Compare commits
	
		
			2091 Commits
		
	
	
		
			master-pos
			...
			OpenSSL_0_
		
	
	| Author | SHA1 | Date | |
|---|---|---|---|
| 
						 | 
					0823ddc56e | ||
| 
						 | 
					ad6567965d | ||
| 
						 | 
					582f1f41d4 | ||
| 
						 | 
					fa57f74a39 | ||
| 
						 | 
					92f9a8bf38 | ||
| 
						 | 
					39bcfb129e | ||
| 
						 | 
					50d3049930 | ||
| 
						 | 
					8b4fd12b0d | ||
| 
						 | 
					17689e7dc6 | ||
| 
						 | 
					f803a417f7 | ||
| 
						 | 
					9759ff0cd9 | ||
| 
						 | 
					f9603f2673 | ||
| 
						 | 
					467daf6b6e | ||
| 
						 | 
					113d36a3fb | ||
| 
						 | 
					f16093d2d6 | ||
| 
						 | 
					aeff907218 | ||
| 
						 | 
					f3b555a601 | ||
| 
						 | 
					c0de854c9d | ||
| 
						 | 
					155ca14ea9 | ||
| 
						 | 
					303845a3b5 | ||
| 
						 | 
					1a38987de0 | ||
| 
						 | 
					5d28381ae4 | ||
| 
						 | 
					eeda966123 | ||
| 
						 | 
					c5b0f5c463 | ||
| 
						 | 
					32fbe9149e | ||
| 
						 | 
					246b35a96e | ||
| 
						 | 
					79cc5417a4 | ||
| 
						 | 
					db8334be06 | ||
| 
						 | 
					fcc5e899aa | ||
| 
						 | 
					b78c9e4a2b | ||
| 
						 | 
					c380bff888 | ||
| 
						 | 
					6655ac4e45 | ||
| 
						 | 
					c7395fb999 | ||
| 
						 | 
					d53f920365 | ||
| 
						 | 
					65c588c140 | ||
| 
						 | 
					544e3e3b69 | ||
| 
						 | 
					497d0b00dc | ||
| 
						 | 
					674341f1b0 | ||
| 
						 | 
					c58f4f73bd | ||
| 
						 | 
					c85c1e08ce | ||
| 
						 | 
					c2f5de13cd | ||
| 
						 | 
					01320ad3b9 | ||
| 
						 | 
					a065737afb | ||
| 
						 | 
					241cff623e | ||
| 
						 | 
					8a8ba07167 | ||
| 
						 | 
					1b4a8df38f | ||
| 
						 | 
					6d4655c27e | ||
| 
						 | 
					9eca2cbc16 | ||
| 
						 | 
					d7efe7ea18 | ||
| 
						 | 
					49fa6b6c2d | ||
| 
						 | 
					d64a227f1f | ||
| 
						 | 
					6844c12968 | ||
| 
						 | 
					ead95e760c | ||
| 
						 | 
					02f0c26cea | ||
| 
						 | 
					6f1f3c6653 | ||
| 
						 | 
					40720ce3ca | ||
| 
						 | 
					9d03aabea3 | ||
| 
						 | 
					117e79dd88 | ||
| 
						 | 
					bc91221636 | ||
| 
						 | 
					b9006da5d7 | ||
| 
						 | 
					d26667b28f | ||
| 
						 | 
					13270477f4 | ||
| 
						 | 
					3600d5a744 | ||
| 
						 | 
					2b2f5ac045 | ||
| 
						 | 
					7d3081c5ae | ||
| 
						 | 
					9a5d775320 | ||
| 
						 | 
					e29126f99a | ||
| 
						 | 
					175af9de89 | ||
| 
						 | 
					53d6e678dc | ||
| 
						 | 
					4191a11f36 | ||
| 
						 | 
					f6e4701f2a | ||
| 
						 | 
					86183798f3 | ||
| 
						 | 
					b527959318 | ||
| 
						 | 
					25ca15e9a3 | ||
| 
						 | 
					d1d4b4f398 | ||
| 
						 | 
					2a3e745a17 | ||
| 
						 | 
					c7c7a432df | ||
| 
						 | 
					5ba9d5bb3b | ||
| 
						 | 
					883a4d55c2 | ||
| 
						 | 
					b4f1dbdc4b | ||
| 
						 | 
					5741067dea | ||
| 
						 | 
					dd7ad2c53d | ||
| 
						 | 
					366b193f89 | ||
| 
						 | 
					402eec1ae5 | ||
| 
						 | 
					44759a0d9e | ||
| 
						 | 
					9b8089bfea | ||
| 
						 | 
					4fd2e6b032 | ||
| 
						 | 
					a2a2bbafde | ||
| 
						 | 
					b0727cd549 | ||
| 
						 | 
					d808ebd379 | ||
| 
						 | 
					23f5f5b9bb | ||
| 
						 | 
					5e121092ab | ||
| 
						 | 
					7ef6c2b9d2 | ||
| 
						 | 
					00ea17f9d7 | ||
| 
						 | 
					3e8042c38f | ||
| 
						 | 
					564ccc55d6 | ||
| 
						 | 
					b558c8d597 | ||
| 
						 | 
					ba442a7e1b | ||
| 
						 | 
					e8ccaee31c | ||
| 
						 | 
					60431d0db3 | ||
| 
						 | 
					346a46f074 | ||
| 
						 | 
					56abaa14e0 | ||
| 
						 | 
					8b8a48d099 | ||
| 
						 | 
					09caf4ffcd | ||
| 
						 | 
					9793a0713f | ||
| 
						 | 
					aa9296e331 | ||
| 
						 | 
					bc253b0902 | ||
| 
						 | 
					b873409efe | ||
| 
						 | 
					f89250f2f2 | ||
| 
						 | 
					1dc6a5441a | ||
| 
						 | 
					a4aa188799 | ||
| 
						 | 
					50befdb659 | ||
| 
						 | 
					46bf0ba876 | ||
| 
						 | 
					4b4c0a1921 | ||
| 
						 | 
					df70302441 | ||
| 
						 | 
					9c6c664041 | ||
| 
						 | 
					11f719da38 | ||
| 
						 | 
					72f1815391 | ||
| 
						 | 
					e42a2abadc | ||
| 
						 | 
					ec2fede946 | ||
| 
						 | 
					63f3c9e715 | ||
| 
						 | 
					c22e2dd6e5 | ||
| 
						 | 
					7fae32f6d6 | ||
| 
						 | 
					5260f1a483 | ||
| 
						 | 
					1cb10d9c7d | ||
| 
						 | 
					62abc80540 | ||
| 
						 | 
					722fa14271 | ||
| 
						 | 
					a2ca66f37c | ||
| 
						 | 
					6a04b0d5a4 | ||
| 
						 | 
					1acca28263 | ||
| 
						 | 
					d510c6489e | ||
| 
						 | 
					b82924741b | ||
| 
						 | 
					cbb6ccabb0 | ||
| 
						 | 
					e369af3600 | ||
| 
						 | 
					15b7f5bf88 | ||
| 
						 | 
					9880f63038 | ||
| 
						 | 
					af32df0a8e | ||
| 
						 | 
					bfb7bf1a28 | ||
| 
						 | 
					f33636faf7 | ||
| 
						 | 
					94f735cade | ||
| 
						 | 
					36216218ca | ||
| 
						 | 
					115eaf4886 | ||
| 
						 | 
					53ce5647d4 | ||
| 
						 | 
					4d2efa29f6 | ||
| 
						 | 
					cd332a0750 | ||
| 
						 | 
					2ed80d14d7 | ||
| 
						 | 
					d286606301 | ||
| 
						 | 
					3f4d81e88b | ||
| 
						 | 
					dc5dfe431c | ||
| 
						 | 
					c6a876473c | ||
| 
						 | 
					5a7fc89394 | ||
| 
						 | 
					116fd3732a | ||
| 
						 | 
					1bb01b1b5f | ||
| 
						 | 
					699d78ce98 | ||
| 
						 | 
					43d613ec18 | ||
| 
						 | 
					96e1015eec | ||
| 
						 | 
					cf4b01a766 | ||
| 
						 | 
					45d129511f | ||
| 
						 | 
					0976adac8f | ||
| 
						 | 
					db5b0d9309 | ||
| 
						 | 
					aeeedc8acc | ||
| 
						 | 
					c903866420 | ||
| 
						 | 
					9b208659aa | ||
| 
						 | 
					f54fab0fef | ||
| 
						 | 
					b30aaafbe5 | ||
| 
						 | 
					fee8d86d7a | ||
| 
						 | 
					bf3e53a7fa | ||
| 
						 | 
					44a8fced97 | ||
| 
						 | 
					4ff07f4c71 | ||
| 
						 | 
					1c5f396d36 | ||
| 
						 | 
					9fcaaef34f | ||
| 
						 | 
					b9a73f5481 | ||
| 
						 | 
					bff5319d90 | ||
| 
						 | 
					fc4bd2f287 | ||
| 
						 | 
					4c836c96c4 | ||
| 
						 | 
					6e14e7fc19 | ||
| 
						 | 
					fc15c44049 | ||
| 
						 | 
					445598b35e | ||
| 
						 | 
					338a5e7e54 | ||
| 
						 | 
					6a431cd293 | ||
| 
						 | 
					1b7024fb69 | ||
| 
						 | 
					5021f6314e | ||
| 
						 | 
					21d24dd38a | ||
| 
						 | 
					681d11b6fd | ||
| 
						 | 
					8c387e62b2 | ||
| 
						 | 
					a117329c5a | ||
| 
						 | 
					f39dbff498 | ||
| 
						 | 
					f6fefb0cb6 | ||
| 
						 | 
					febfaa53f4 | ||
| 
						 | 
					cfed221c2d | ||
| 
						 | 
					c2014ae252 | ||
| 
						 | 
					c3d317b4de | ||
| 
						 | 
					a214feb26b | ||
| 
						 | 
					7a3a82dbbd | ||
| 
						 | 
					02fef91630 | ||
| 
						 | 
					0b8cd5acd6 | ||
| 
						 | 
					97f4e235a1 | ||
| 
						 | 
					cfd2aeeb7c | ||
| 
						 | 
					a0fdc4c6d6 | ||
| 
						 | 
					b5def0243e | ||
| 
						 | 
					357f6d8add | ||
| 
						 | 
					19a71e8c16 | ||
| 
						 | 
					7faa66433f | ||
| 
						 | 
					1a0498769f | ||
| 
						 | 
					a4dde82423 | ||
| 
						 | 
					eba0aa995d | ||
| 
						 | 
					c9e6fffa53 | ||
| 
						 | 
					85dcce7c63 | ||
| 
						 | 
					2ed29615cb | ||
| 
						 | 
					d7080d624b | ||
| 
						 | 
					5d7c8a48db | ||
| 
						 | 
					00e86a74bd | ||
| 
						 | 
					9e6857a358 | ||
| 
						 | 
					715258486c | ||
| 
						 | 
					2daec41e25 | ||
| 
						 | 
					8519635923 | ||
| 
						 | 
					d0bdfdd830 | ||
| 
						 | 
					4b98488eb0 | ||
| 
						 | 
					0e2458e187 | ||
| 
						 | 
					326de18955 | ||
| 
						 | 
					1fcfd61ee7 | ||
| 
						 | 
					121f386ec7 | ||
| 
						 | 
					9fb10cfe6b | ||
| 
						 | 
					a20a6366c8 | ||
| 
						 | 
					54985b5061 | ||
| 
						 | 
					b09db677d5 | ||
| 
						 | 
					cdc596567d | ||
| 
						 | 
					70d923fb03 | ||
| 
						 | 
					def1490717 | ||
| 
						 | 
					7697d9b587 | ||
| 
						 | 
					0345354fe0 | ||
| 
						 | 
					90aef4431b | ||
| 
						 | 
					602689074a | ||
| 
						 | 
					810d2c7f6e | ||
| 
						 | 
					0a9b8dd1b4 | ||
| 
						 | 
					bfce4e5d6e | ||
| 
						 | 
					4a1190beca | ||
| 
						 | 
					047ec5d196 | ||
| 
						 | 
					bb59889305 | ||
| 
						 | 
					141a5482fd | ||
| 
						 | 
					de2422affb | ||
| 
						 | 
					897169fdf0 | ||
| 
						 | 
					410a49a4fa | ||
| 
						 | 
					82ba68c42d | ||
| 
						 | 
					4b258e73ae | ||
| 
						 | 
					6ac2f67882 | ||
| 
						 | 
					bea1d1cbd8 | ||
| 
						 | 
					61e6e80fe5 | ||
| 
						 | 
					2ce540743e | ||
| 
						 | 
					8e928aab02 | ||
| 
						 | 
					105e52bf23 | ||
| 
						 | 
					492a5010a4 | ||
| 
						 | 
					53b0b0a330 | ||
| 
						 | 
					677c117419 | ||
| 
						 | 
					bb50d30f35 | ||
| 
						 | 
					8323996d99 | ||
| 
						 | 
					ee14e33c35 | ||
| 
						 | 
					1bcb94a721 | ||
| 
						 | 
					9658c634a2 | ||
| 
						 | 
					7ee8b27267 | ||
| 
						 | 
					e4ea6f0c76 | ||
| 
						 | 
					a2c00fb210 | ||
| 
						 | 
					d06ae0fff7 | ||
| 
						 | 
					afa2ea204e | ||
| 
						 | 
					0b6394c738 | ||
| 
						 | 
					70ddf8ecca | ||
| 
						 | 
					9febee0272 | ||
| 
						 | 
					a721216f0f | ||
| 
						 | 
					47f689ac09 | ||
| 
						 | 
					f51f374199 | ||
| 
						 | 
					3c1128f43f | ||
| 
						 | 
					8185c9457e | ||
| 
						 | 
					c61f0cbffb | ||
| 
						 | 
					d90605dd00 | ||
| 
						 | 
					e56334998c | ||
| 
						 | 
					9ad5c5e4f9 | ||
| 
						 | 
					4bc24cf01d | ||
| 
						 | 
					79f57768ff | ||
| 
						 | 
					d79eb9299a | ||
| 
						 | 
					fff69a7d8c | ||
| 
						 | 
					a375025e4d | ||
| 
						 | 
					d471adf351 | ||
| 
						 | 
					2fb8642eea | ||
| 
						 | 
					c44d95c1a7 | ||
| 
						 | 
					0da40f0ffc | ||
| 
						 | 
					7f722c95f8 | ||
| 
						 | 
					4268216005 | ||
| 
						 | 
					17540b77e0 | ||
| 
						 | 
					b70e4d3e90 | ||
| 
						 | 
					d9519a4032 | ||
| 
						 | 
					5ac9786807 | ||
| 
						 | 
					0b05204c4e | ||
| 
						 | 
					a4bfeff254 | ||
| 
						 | 
					43433b3852 | ||
| 
						 | 
					020a4782bd | ||
| 
						 | 
					cadbbd51c8 | ||
| 
						 | 
					ff7b021040 | ||
| 
						 | 
					e7e4d506d6 | ||
| 
						 | 
					9204e7ef0d | ||
| 
						 | 
					257df40f00 | ||
| 
						 | 
					a44c9b9c33 | ||
| 
						 | 
					1cbd7456aa | ||
| 
						 | 
					e1e39a2451 | ||
| 
						 | 
					01de6e21cc | ||
| 
						 | 
					05689a132c | ||
| 
						 | 
					1643edc63c | ||
| 
						 | 
					1546fb780b | ||
| 
						 | 
					b7d222c519 | ||
| 
						 | 
					a93cc7c573 | ||
| 
						 | 
					8988407a0b | ||
| 
						 | 
					b2afc0a9dc | ||
| 
						 | 
					a8655eb21a | ||
| 
						 | 
					f751dc4759 | ||
| 
						 | 
					fbe621d08f | ||
| 
						 | 
					2e9fd4301f | ||
| 
						 | 
					1638ce7212 | ||
| 
						 | 
					7ecd974f5f | ||
| 
						 | 
					db731da802 | ||
| 
						 | 
					5864fd2061 | ||
| 
						 | 
					ff58eaa4b6 | ||
| 
						 | 
					76c61a5d1a | ||
| 
						 | 
					4ea7019165 | ||
| 
						 | 
					59b1129e0a | ||
| 
						 | 
					fb092ef4fc | ||
| 
						 | 
					6351adecb4 | ||
| 
						 | 
					8964efc413 | ||
| 
						 | 
					430b637bd5 | ||
| 
						 | 
					ca3b81c858 | ||
| 
						 | 
					031cbecf86 | ||
| 
						 | 
					1213e6c3c2 | ||
| 
						 | 
					32619893b4 | ||
| 
						 | 
					40e0de0395 | ||
| 
						 | 
					5f9345a2f0 | ||
| 
						 | 
					33ccde59a1 | ||
| 
						 | 
					1909df070f | ||
| 
						 | 
					c23a745820 | ||
| 
						 | 
					924b117422 | ||
| 
						 | 
					24b2806097 | ||
| 
						 | 
					99f5093347 | ||
| 
						 | 
					be88529753 | ||
| 
						 | 
					b3a959a337 | ||
| 
						 | 
					2928cb4c82 | ||
| 
						 | 
					a33e6702a0 | ||
| 
						 | 
					35a65e814b | ||
| 
						 | 
					7ad132b133 | ||
| 
						 | 
					2708813166 | ||
| 
						 | 
					affe98998a | ||
| 
						 | 
					66e8211c0b | ||
| 
						 | 
					dd2dee60f3 | ||
| 
						 | 
					6495179af6 | ||
| 
						 | 
					61b8c79d15 | ||
| 
						 | 
					42aa3ec4f2 | ||
| 
						 | 
					bb152dae8f | ||
| 
						 | 
					c42ab44087 | ||
| 
						 | 
					42e10c3fd6 | ||
| 
						 | 
					c571a3e984 | ||
| 
						 | 
					e55988bb60 | ||
| 
						 | 
					34b5ba3b60 | ||
| 
						 | 
					629ac4b4ca | ||
| 
						 | 
					75f0bc4f44 | ||
| 
						 | 
					71a2440ee5 | ||
| 
						 | 
					04e40739f7 | ||
| 
						 | 
					48bcdad0d5 | ||
| 
						 | 
					f7d2402cab | ||
| 
						 | 
					808f55351a | ||
| 
						 | 
					c06271bc35 | ||
| 
						 | 
					92e5882aca | ||
| 
						 | 
					afa0580cd5 | ||
| 
						 | 
					4baee3031c | ||
| 
						 | 
					db7a72b224 | ||
| 
						 | 
					b71e69ad8e | ||
| 
						 | 
					f856173c43 | ||
| 
						 | 
					d742f9ebbd | ||
| 
						 | 
					36dd4cba3d | ||
| 
						 | 
					3978429ad5 | ||
| 
						 | 
					885945d6e1 | ||
| 
						 | 
					e22e770147 | ||
| 
						 | 
					e0c0203341 | ||
| 
						 | 
					e1eec61e26 | ||
| 
						 | 
					296fa128c9 | ||
| 
						 | 
					6dde222aae | ||
| 
						 | 
					391ac37018 | ||
| 
						 | 
					8d038a08fb | ||
| 
						 | 
					747c6ffda4 | ||
| 
						 | 
					d4cddc54f0 | ||
| 
						 | 
					eb7112c18e | ||
| 
						 | 
					fef9e07930 | ||
| 
						 | 
					8ab27e6ef7 | ||
| 
						 | 
					6415055590 | ||
| 
						 | 
					556e27b14f | ||
| 
						 | 
					af0c009d70 | ||
| 
						 | 
					0b1cf4a139 | ||
| 
						 | 
					a9101cdcaa | ||
| 
						 | 
					e351e2a7cf | ||
| 
						 | 
					215276243d | ||
| 
						 | 
					ddb7832852 | ||
| 
						 | 
					2fad41d155 | ||
| 
						 | 
					b9c3d9168f | ||
| 
						 | 
					4f2fc3c2dd | ||
| 
						 | 
					48819f4d54 | ||
| 
						 | 
					b0cbdd3eba | ||
| 
						 | 
					5016107550 | ||
| 
						 | 
					25d5d15fd5 | ||
| 
						 | 
					725713f74a | ||
| 
						 | 
					73eb0972cf | ||
| 
						 | 
					6720779c7e | ||
| 
						 | 
					b2a2c6af2a | ||
| 
						 | 
					272993bac4 | ||
| 
						 | 
					58532ae047 | ||
| 
						 | 
					4e7f6d380d | ||
| 
						 | 
					f0be325f88 | ||
| 
						 | 
					b66af23aa9 | ||
| 
						 | 
					29d0c13e97 | ||
| 
						 | 
					8a4e81a269 | ||
| 
						 | 
					843fc7b681 | ||
| 
						 | 
					6dcb6bf1c1 | ||
| 
						 | 
					1061c3cb3c | ||
| 
						 | 
					0d0f15d8d1 | ||
| 
						 | 
					a72ce94213 | ||
| 
						 | 
					f71d59c70e | ||
| 
						 | 
					3309f8313c | ||
| 
						 | 
					6cc5f194a7 | ||
| 
						 | 
					096327a99a | ||
| 
						 | 
					cc10bcf25e | ||
| 
						 | 
					875ac0ec00 | ||
| 
						 | 
					bf240f063a | ||
| 
						 | 
					dd016b0570 | ||
| 
						 | 
					244788464a | ||
| 
						 | 
					a95808334e | ||
| 
						 | 
					b3cebd5acf | ||
| 
						 | 
					7b775145e4 | ||
| 
						 | 
					7183aa6b9d | ||
| 
						 | 
					eebefe35e7 | ||
| 
						 | 
					1db0bbdc76 | ||
| 
						 | 
					e643112dd8 | ||
| 
						 | 
					21c4b25959 | ||
| 
						 | 
					41cf2c3aef | ||
| 
						 | 
					0e3a930fb4 | ||
| 
						 | 
					0c214e0153 | ||
| 
						 | 
					6c61cfbe03 | ||
| 
						 | 
					2ee77d36a0 | ||
| 
						 | 
					24f441e0bb | ||
| 
						 | 
					740da44f20 | ||
| 
						 | 
					72033fde7b | ||
| 
						 | 
					9adf3fcf9a | ||
| 
						 | 
					65f7456652 | ||
| 
						 | 
					8794569a08 | ||
| 
						 | 
					f8731bc2fd | ||
| 
						 | 
					195d6bf760 | ||
| 
						 | 
					dacd94b9c8 | ||
| 
						 | 
					8070cb5f87 | ||
| 
						 | 
					f7d514f449 | ||
| 
						 | 
					6d50bce79f | ||
| 
						 | 
					3cf0a38b3e | ||
| 
						 | 
					91a1d08a4c | ||
| 
						 | 
					85e776885b | ||
| 
						 | 
					fc4015329f | ||
| 
						 | 
					6ec9ff83f3 | ||
| 
						 | 
					db45308477 | ||
| 
						 | 
					1c7c69a8a5 | ||
| 
						 | 
					24ad061037 | ||
| 
						 | 
					92f96fa721 | ||
| 
						 | 
					0d1e362363 | ||
| 
						 | 
					a0bf2c86ab | ||
| 
						 | 
					6a662a45f3 | ||
| 
						 | 
					24d0524f31 | ||
| 
						 | 
					c081817c95 | ||
| 
						 | 
					46a1f2487e | ||
| 
						 | 
					ac02a4b68a | ||
| 
						 | 
					4ba063d3c5 | ||
| 
						 | 
					e0e0818e4b | ||
| 
						 | 
					82a5049f6a | ||
| 
						 | 
					d027b75b73 | ||
| 
						 | 
					87421d3fc5 | ||
| 
						 | 
					87d14a3625 | ||
| 
						 | 
					cc0931e36b | ||
| 
						 | 
					22152d6885 | ||
| 
						 | 
					102bcbce8d | ||
| 
						 | 
					8655de423d | ||
| 
						 | 
					c4b2eb24b3 | ||
| 
						 | 
					03e3fbb702 | ||
| 
						 | 
					bc7ee385f5 | ||
| 
						 | 
					1e368ab08f | ||
| 
						 | 
					2c77c5c8db | ||
| 
						 | 
					1eb38c563f | ||
| 
						 | 
					fa657871ed | ||
| 
						 | 
					09dac71a45 | ||
| 
						 | 
					be70b3adce | ||
| 
						 | 
					6d12b1f82b | ||
| 
						 | 
					7116a41129 | ||
| 
						 | 
					7143acab25 | ||
| 
						 | 
					11d4086d8e | ||
| 
						 | 
					32cd1da62e | ||
| 
						 | 
					d430f56de6 | ||
| 
						 | 
					957ebe98fb | ||
| 
						 | 
					9d09fc8485 | ||
| 
						 | 
					8ea4531718 | ||
| 
						 | 
					881611678e | ||
| 
						 | 
					a3dc628d86 | ||
| 
						 | 
					3c159fc1a5 | ||
| 
						 | 
					6056afd223 | ||
| 
						 | 
					54db796991 | ||
| 
						 | 
					119e912a83 | ||
| 
						 | 
					f4a4a0fdc7 | ||
| 
						 | 
					9ad765173f | ||
| 
						 | 
					c8e3c1a9b5 | ||
| 
						 | 
					ae378b769a | ||
| 
						 | 
					4de4e35459 | ||
| 
						 | 
					5537a83e56 | ||
| 
						 | 
					c850d322a6 | ||
| 
						 | 
					b8be571868 | ||
| 
						 | 
					acd43bf38c | ||
| 
						 | 
					5eaf173647 | ||
| 
						 | 
					7890b562bc | ||
| 
						 | 
					7258d33794 | ||
| 
						 | 
					263979a2a3 | ||
| 
						 | 
					2c6d83354d | ||
| 
						 | 
					a188fc01fe | ||
| 
						 | 
					1948f9e042 | ||
| 
						 | 
					f7ffc3a6c9 | ||
| 
						 | 
					4d6af5c5d2 | ||
| 
						 | 
					efed63d783 | ||
| 
						 | 
					7e351bb560 | ||
| 
						 | 
					0067580321 | ||
| 
						 | 
					82e0073624 | ||
| 
						 | 
					7e541b1a7f | ||
| 
						 | 
					2ae47ddbc2 | ||
| 
						 | 
					3e8b8b8990 | ||
| 
						 | 
					05bbbe9204 | ||
| 
						 | 
					a073129293 | ||
| 
						 | 
					93fc0e0e40 | ||
| 
						 | 
					84f1c14396 | ||
| 
						 | 
					f10986bab4 | ||
| 
						 | 
					6cb5746b65 | ||
| 
						 | 
					0061aa9f32 | ||
| 
						 | 
					3926bbcf6d | ||
| 
						 | 
					b5cee977c2 | ||
| 
						 | 
					ae3b60ba99 | ||
| 
						 | 
					d4ba6424a1 | ||
| 
						 | 
					92a97e52a0 | ||
| 
						 | 
					78dcaa0609 | ||
| 
						 | 
					65b4c34d86 | ||
| 
						 | 
					d8486c312c | ||
| 
						 | 
					8d4baaf2f0 | ||
| 
						 | 
					50fb940f05 | ||
| 
						 | 
					63e3676e68 | ||
| 
						 | 
					1dac2cae68 | ||
| 
						 | 
					d886975835 | ||
| 
						 | 
					22872a5363 | ||
| 
						 | 
					82b6b541b1 | ||
| 
						 | 
					60a989a76e | ||
| 
						 | 
					18394ed50f | ||
| 
						 | 
					3416d11926 | ||
| 
						 | 
					c1f1a03d0c | ||
| 
						 | 
					278a447ee8 | ||
| 
						 | 
					8ceee689c7 | ||
| 
						 | 
					356f164f52 | ||
| 
						 | 
					203ef9988c | ||
| 
						 | 
					9f51bdae00 | ||
| 
						 | 
					59c4f46f0f | ||
| 
						 | 
					f9ab6255e7 | ||
| 
						 | 
					a89b665b9b | ||
| 
						 | 
					a7949b8da3 | ||
| 
						 | 
					b0b4adc3af | ||
| 
						 | 
					6e19895972 | ||
| 
						 | 
					d24f1cbf35 | ||
| 
						 | 
					b8febed96a | ||
| 
						 | 
					82687bb4c3 | ||
| 
						 | 
					6506b7754a | ||
| 
						 | 
					2eb8e5e62a | ||
| 
						 | 
					c713a4c04d | ||
| 
						 | 
					0cefa0f942 | ||
| 
						 | 
					834c85ef0c | ||
| 
						 | 
					0c8c8eab58 | ||
| 
						 | 
					bc06baca76 | ||
| 
						 | 
					9eeb779e8f | ||
| 
						 | 
					fe171f9c3e | ||
| 
						 | 
					5e613d5411 | ||
| 
						 | 
					56e930eb03 | ||
| 
						 | 
					4a052f0bb9 | ||
| 
						 | 
					f34e79f27b | ||
| 
						 | 
					ef1fe9094c | ||
| 
						 | 
					c25e8ee9b3 | ||
| 
						 | 
					4525a048ec | ||
| 
						 | 
					f421a52f56 | ||
| 
						 | 
					17a79eec0c | ||
| 
						 | 
					1eda14b44f | ||
| 
						 | 
					aa9b502619 | ||
| 
						 | 
					aaf45e6464 | ||
| 
						 | 
					be83c31cdd | ||
| 
						 | 
					76a41eec2b | ||
| 
						 | 
					ab9c0ec9fc | ||
| 
						 | 
					cf6a1dea19 | ||
| 
						 | 
					ea5b3f5e62 | ||
| 
						 | 
					c3c658e1c0 | ||
| 
						 | 
					5d013b6b32 | ||
| 
						 | 
					ee91323f52 | ||
| 
						 | 
					4fae868811 | ||
| 
						 | 
					354f92d66a | ||
| 
						 | 
					c3484e0268 | ||
| 
						 | 
					6b0be9c73d | ||
| 
						 | 
					02312a91ca | ||
| 
						 | 
					744f6b648e | ||
| 
						 | 
					f1502a491e | ||
| 
						 | 
					b70871b675 | ||
| 
						 | 
					9de450b545 | ||
| 
						 | 
					cc53036744 | ||
| 
						 | 
					4610d8dc00 | ||
| 
						 | 
					5d7dfefe82 | ||
| 
						 | 
					5e8e7054f7 | ||
| 
						 | 
					9a542ea01d | ||
| 
						 | 
					1939f83709 | ||
| 
						 | 
					b7c114f044 | ||
| 
						 | 
					ede1351997 | ||
| 
						 | 
					7786ed6a64 | ||
| 
						 | 
					bdd08277b8 | ||
| 
						 | 
					2bf4faa7e4 | ||
| 
						 | 
					2e5e604b0c | ||
| 
						 | 
					ed4cd027f3 | ||
| 
						 | 
					bab19a2ac2 | ||
| 
						 | 
					582eb96d15 | ||
| 
						 | 
					2649ce1ebc | ||
| 
						 | 
					7070cdba4e | ||
| 
						 | 
					e885de28b1 | ||
| 
						 | 
					3038649ab2 | ||
| 
						 | 
					3e4da3f7cb | ||
| 
						 | 
					53b5d04715 | ||
| 
						 | 
					defede6080 | ||
| 
						 | 
					1472f1427e | ||
| 
						 | 
					00d1ecb1da | ||
| 
						 | 
					739e0e934a | ||
| 
						 | 
					6ae9770d34 | ||
| 
						 | 
					bec7184768 | ||
| 
						 | 
					442ac8d259 | ||
| 
						 | 
					657b02d0cf | ||
| 
						 | 
					b50ef8b216 | ||
| 
						 | 
					1b690c1a8b | ||
| 
						 | 
					2873a53f5f | ||
| 
						 | 
					04a781e844 | ||
| 
						 | 
					68be98d1a6 | ||
| 
						 | 
					0bbbadf3f5 | ||
| 
						 | 
					c0c1ce125a | ||
| 
						 | 
					105861186f | ||
| 
						 | 
					4a9d335bb4 | ||
| 
						 | 
					162f1e08f8 | ||
| 
						 | 
					0484ff5ec1 | ||
| 
						 | 
					4acc2fed6c | ||
| 
						 | 
					0369804ffa | ||
| 
						 | 
					33d7b5ec07 | ||
| 
						 | 
					4b38f35e72 | ||
| 
						 | 
					82c2773423 | ||
| 
						 | 
					ded27f709c | ||
| 
						 | 
					30dc3e112b | ||
| 
						 | 
					371b262f96 | ||
| 
						 | 
					b3fb2492d5 | ||
| 
						 | 
					93b810637b | ||
| 
						 | 
					cc62974182 | ||
| 
						 | 
					9413788571 | ||
| 
						 | 
					e8387db0c4 | ||
| 
						 | 
					81f28ca567 | ||
| 
						 | 
					1b32943215 | ||
| 
						 | 
					a231d99d4c | ||
| 
						 | 
					714044cc03 | ||
| 
						 | 
					5598b99fb3 | ||
| 
						 | 
					6899d9bbf6 | ||
| 
						 | 
					cf876a9893 | ||
| 
						 | 
					8b8a2928af | ||
| 
						 | 
					031774468c | ||
| 
						 | 
					dd28d12add | ||
| 
						 | 
					6c61ee8fe3 | ||
| 
						 | 
					b86ebb55ff | ||
| 
						 | 
					66956eaba3 | ||
| 
						 | 
					444ff35029 | ||
| 
						 | 
					ff2549be1d | ||
| 
						 | 
					2557c6a812 | ||
| 
						 | 
					aae48de0f7 | ||
| 
						 | 
					766708f24b | ||
| 
						 | 
					fbeb4a9d15 | ||
| 
						 | 
					24fc4f656c | ||
| 
						 | 
					c3c3b28818 | ||
| 
						 | 
					06e2670a57 | ||
| 
						 | 
					3798a4d059 | ||
| 
						 | 
					5b8246d6eb | ||
| 
						 | 
					2e24bc421d | ||
| 
						 | 
					f244ed3ed2 | ||
| 
						 | 
					50a095ed16 | ||
| 
						 | 
					37aff2199e | ||
| 
						 | 
					309aa5fbf3 | ||
| 
						 | 
					5f40948714 | ||
| 
						 | 
					c22050be29 | ||
| 
						 | 
					54ca55fd81 | ||
| 
						 | 
					d0e79d7e2c | ||
| 
						 | 
					c1003dfd15 | ||
| 
						 | 
					98809a1458 | ||
| 
						 | 
					ccc3df8c33 | ||
| 
						 | 
					593a6dbe19 | ||
| 
						 | 
					efbe446f1a | ||
| 
						 | 
					725745d105 | ||
| 
						 | 
					c0e94f8292 | ||
| 
						 | 
					ef4bd0167c | ||
| 
						 | 
					7a8a3ef4f6 | ||
| 
						 | 
					98c7b0367d | ||
| 
						 | 
					9e5dea0ffd | ||
| 
						 | 
					cb4823fdd6 | ||
| 
						 | 
					17bb051628 | ||
| 
						 | 
					59f44e810b | ||
| 
						 | 
					7a014dceb6 | ||
| 
						 | 
					1ff44a99a4 | ||
| 
						 | 
					6cf61614e4 | ||
| 
						 | 
					82e448b92b | ||
| 
						 | 
					b172352b52 | ||
| 
						 | 
					95b14fd803 | ||
| 
						 | 
					553d2e3280 | ||
| 
						 | 
					82fb4ee89d | ||
| 
						 | 
					389fef6c9c | ||
| 
						 | 
					b6622f9623 | ||
| 
						 | 
					7f5448e3a8 | ||
| 
						 | 
					5d965f0783 | ||
| 
						 | 
					b14713c231 | ||
| 
						 | 
					637e0ba420 | ||
| 
						 | 
					9ac37cb018 | ||
| 
						 | 
					fb7751b44f | ||
| 
						 | 
					e333a8d673 | ||
| 
						 | 
					89a6daac00 | ||
| 
						 | 
					7e42945918 | ||
| 
						 | 
					b61a87b26c | ||
| 
						 | 
					2c6b141931 | ||
| 
						 | 
					af13c50d51 | ||
| 
						 | 
					65c2397fce | ||
| 
						 | 
					16e7efe3c8 | ||
| 
						 | 
					c2b78c31d6 | ||
| 
						 | 
					a1dc0336dd | ||
| 
						 | 
					d99a35f275 | ||
| 
						 | 
					949fbf073a | ||
| 
						 | 
					6156be4da3 | ||
| 
						 | 
					d7d4325655 | ||
| 
						 | 
					9f81ffe433 | ||
| 
						 | 
					8164930816 | ||
| 
						 | 
					2a8834cf89 | ||
| 
						 | 
					e6e11f4ec3 | ||
| 
						 | 
					452e41562c | ||
| 
						 | 
					8c6dd96aed | ||
| 
						 | 
					23a4ccd178 | ||
| 
						 | 
					2b4d877a27 | ||
| 
						 | 
					d916f92d6f | ||
| 
						 | 
					b9b5134e19 | ||
| 
						 | 
					9ef6fdab63 | ||
| 
						 | 
					3a0b6de4d0 | ||
| 
						 | 
					08896dc0bd | ||
| 
						 | 
					ef62799783 | ||
| 
						 | 
					8196257f00 | ||
| 
						 | 
					ac923d3377 | ||
| 
						 | 
					0ec529ac82 | ||
| 
						 | 
					d5b0c872d8 | ||
| 
						 | 
					2e8026b65a | ||
| 
						 | 
					381a9f04a0 | ||
| 
						 | 
					d7050b4424 | ||
| 
						 | 
					91ca332058 | ||
| 
						 | 
					ff095a8ac8 | ||
| 
						 | 
					ae37f9f3a2 | ||
| 
						 | 
					95d66bd867 | ||
| 
						 | 
					6d73e9d8e8 | ||
| 
						 | 
					fb5a4bbaa7 | ||
| 
						 | 
					d402f6b66f | ||
| 
						 | 
					36a38a7a27 | ||
| 
						 | 
					2a4dc7e505 | ||
| 
						 | 
					4e92353d23 | ||
| 
						 | 
					0badc909ae | ||
| 
						 | 
					3cc52ee97a | ||
| 
						 | 
					822da9ccc3 | ||
| 
						 | 
					96e20179e4 | ||
| 
						 | 
					1dfa26bd84 | ||
| 
						 | 
					9e6c97703c | ||
| 
						 | 
					a0f6e0c1e7 | ||
| 
						 | 
					edaa7a599a | ||
| 
						 | 
					3b95629db1 | ||
| 
						 | 
					afff063a14 | ||
| 
						 | 
					e1246e1ad7 | ||
| 
						 | 
					df0b451d91 | ||
| 
						 | 
					07cb0a82d1 | ||
| 
						 | 
					f2671f8ac4 | ||
| 
						 | 
					43e9e1a160 | ||
| 
						 | 
					d0969d24cf | ||
| 
						 | 
					cf51a0dccb | ||
| 
						 | 
					48b30bf0e2 | ||
| 
						 | 
					17b08b6a64 | ||
| 
						 | 
					197ab47bdd | ||
| 
						 | 
					e8cce0babe | ||
| 
						 | 
					11d655ef40 | ||
| 
						 | 
					1da61e8051 | ||
| 
						 | 
					da6ce18279 | ||
| 
						 | 
					98f43a173b | ||
| 
						 | 
					c202eda634 | ||
| 
						 | 
					f78bcb8945 | ||
| 
						 | 
					2a918d4cc0 | ||
| 
						 | 
					2c83b24cad | ||
| 
						 | 
					e75445f688 | ||
| 
						 | 
					df51d79ec4 | ||
| 
						 | 
					c21a427a14 | ||
| 
						 | 
					c6e4ef2c6e | ||
| 
						 | 
					6450908a35 | ||
| 
						 | 
					a91cb2103d | ||
| 
						 | 
					3acd3158e9 | ||
| 
						 | 
					8a04c6f894 | ||
| 
						 | 
					745565c69f | ||
| 
						 | 
					fbc4a24633 | ||
| 
						 | 
					4775a89760 | ||
| 
						 | 
					3008a7d819 | ||
| 
						 | 
					233f758523 | ||
| 
						 | 
					3af16cf694 | ||
| 
						 | 
					985b5ee735 | ||
| 
						 | 
					4df7ade829 | ||
| 
						 | 
					932858d5f9 | ||
| 
						 | 
					c4b3503b4b | ||
| 
						 | 
					f871545f7f | ||
| 
						 | 
					136b5dc7c7 | ||
| 
						 | 
					759b287f15 | ||
| 
						 | 
					5fffb5b3d9 | ||
| 
						 | 
					17620eec4c | ||
| 
						 | 
					059230b320 | ||
| 
						 | 
					19dac35e5f | ||
| 
						 | 
					f5fe2a9f6c | ||
| 
						 | 
					d36e9d160b | ||
| 
						 | 
					e58e78cab2 | ||
| 
						 | 
					b0080e3817 | ||
| 
						 | 
					4d67d79273 | ||
| 
						 | 
					83ece9f028 | ||
| 
						 | 
					cec136c30d | ||
| 
						 | 
					ded8aff2c8 | ||
| 
						 | 
					76a268a43f | ||
| 
						 | 
					6563b02980 | ||
| 
						 | 
					32d4496c1e | ||
| 
						 | 
					0b26e53c59 | ||
| 
						 | 
					7cf69ed544 | ||
| 
						 | 
					8b634ba029 | ||
| 
						 | 
					526228b78e | ||
| 
						 | 
					34d01a3b20 | ||
| 
						 | 
					856f3005de | ||
| 
						 | 
					6e2a14002e | ||
| 
						 | 
					7852c6b075 | ||
| 
						 | 
					2c5f3606d1 | ||
| 
						 | 
					1649489834 | ||
| 
						 | 
					b51291cba8 | ||
| 
						 | 
					b29b576957 | ||
| 
						 | 
					abe389fd28 | ||
| 
						 | 
					e7e7f5de4b | ||
| 
						 | 
					3dfa7416cd | ||
| 
						 | 
					d733ef7a69 | ||
| 
						 | 
					17e01d24bb | ||
| 
						 | 
					f67f815624 | ||
| 
						 | 
					ab8fe43fa2 | ||
| 
						 | 
					5e4c2225ed | ||
| 
						 | 
					167d2a1411 | ||
| 
						 | 
					3f4802a14e | ||
| 
						 | 
					9aecc3e5ff | ||
| 
						 | 
					b8a4a5bcba | ||
| 
						 | 
					6daac534d7 | ||
| 
						 | 
					79649d380e | ||
| 
						 | 
					51ebaa9f82 | ||
| 
						 | 
					efaa569c3b | ||
| 
						 | 
					15684f58c2 | ||
| 
						 | 
					0e6c24ae4b | ||
| 
						 | 
					0dc1b3c1fb | ||
| 
						 | 
					1e53b797f6 | ||
| 
						 | 
					1ddf691244 | ||
| 
						 | 
					78074baadd | ||
| 
						 | 
					7457642b8c | ||
| 
						 | 
					d1e107702b | ||
| 
						 | 
					19503ca653 | ||
| 
						 | 
					14089b1d0f | ||
| 
						 | 
					0b8eca58b9 | ||
| 
						 | 
					c2f425a06a | ||
| 
						 | 
					4930f8bbd9 | ||
| 
						 | 
					a5668db68b | ||
| 
						 | 
					996b80f990 | ||
| 
						 | 
					1998f60546 | ||
| 
						 | 
					13a4808ca4 | ||
| 
						 | 
					a176be48a2 | ||
| 
						 | 
					f47bce27e3 | ||
| 
						 | 
					f86d65110d | ||
| 
						 | 
					4730ea8a38 | ||
| 
						 | 
					3e82dfdf2d | ||
| 
						 | 
					b7d0d35a13 | ||
| 
						 | 
					e12ceb2c92 | ||
| 
						 | 
					e8d23950a0 | ||
| 
						 | 
					d7c86198d9 | ||
| 
						 | 
					76428da729 | ||
| 
						 | 
					6bf4ca0840 | ||
| 
						 | 
					efa59b8d59 | ||
| 
						 | 
					e1a2bfaaa6 | ||
| 
						 | 
					48f48d96ce | ||
| 
						 | 
					085cb7cac0 | ||
| 
						 | 
					9874ff33c3 | ||
| 
						 | 
					73cfd9cce9 | ||
| 
						 | 
					3166d16f06 | ||
| 
						 | 
					26b82246b1 | ||
| 
						 | 
					277ba3ebd2 | ||
| 
						 | 
					3e9b2042d9 | ||
| 
						 | 
					5d577d7eb0 | ||
| 
						 | 
					05ee0523c1 | ||
| 
						 | 
					43f392c9a1 | ||
| 
						 | 
					01cb2049e3 | ||
| 
						 | 
					a224fe14e9 | ||
| 
						 | 
					00d5a5ff55 | ||
| 
						 | 
					420312cec5 | ||
| 
						 | 
					3c17fa3325 | ||
| 
						 | 
					e3424084a0 | ||
| 
						 | 
					d9a55422c7 | ||
| 
						 | 
					374941f727 | ||
| 
						 | 
					caeb429055 | ||
| 
						 | 
					b00c36e366 | ||
| 
						 | 
					1f9a128519 | ||
| 
						 | 
					18df6b30b1 | ||
| 
						 | 
					0d399f97dd | ||
| 
						 | 
					3fdc2c906d | ||
| 
						 | 
					a78ded0b61 | ||
| 
						 | 
					0a629ddbd6 | ||
| 
						 | 
					353cb367e4 | ||
| 
						 | 
					6252f3bc7c | ||
| 
						 | 
					4e319926d7 | ||
| 
						 | 
					e4f456918f | ||
| 
						 | 
					c342341ea1 | ||
| 
						 | 
					9d396bee8e | ||
| 
						 | 
					a9427c2536 | ||
| 
						 | 
					7a746ecf3e | ||
| 
						 | 
					aca8bf43ce | ||
| 
						 | 
					7de0df694f | ||
| 
						 | 
					15d3cd4680 | ||
| 
						 | 
					da4fb3cb39 | ||
| 
						 | 
					e10051ef3f | ||
| 
						 | 
					c60dca1f95 | ||
| 
						 | 
					188abf7e2a | ||
| 
						 | 
					f021b7cca6 | ||
| 
						 | 
					c126b73a4a | ||
| 
						 | 
					3f03b3569d | ||
| 
						 | 
					07dd3bfcd4 | ||
| 
						 | 
					37afdc953e | ||
| 
						 | 
					044855e146 | ||
| 
						 | 
					12379c82ba | ||
| 
						 | 
					be98d6b9ad | ||
| 
						 | 
					910b484975 | ||
| 
						 | 
					1fde5b65c6 | ||
| 
						 | 
					c40bc0b11f | ||
| 
						 | 
					7a0c01b41a | ||
| 
						 | 
					6fe9c925d2 | ||
| 
						 | 
					1ebdc48d5a | ||
| 
						 | 
					395a6c69bd | ||
| 
						 | 
					0d658ddf25 | ||
| 
						 | 
					cefa7ce284 | ||
| 
						 | 
					ee4041b8bd | ||
| 
						 | 
					a17f351b56 | ||
| 
						 | 
					4fcf8d8b07 | ||
| 
						 | 
					b7650eb21e | ||
| 
						 | 
					69120ad199 | ||
| 
						 | 
					1eee8a4226 | ||
| 
						 | 
					98448a53c8 | ||
| 
						 | 
					241d088156 | ||
| 
						 | 
					a22a8dd7dd | ||
| 
						 | 
					e26ad0c4fd | ||
| 
						 | 
					6e7559ac7f | ||
| 
						 | 
					9feda63955 | ||
| 
						 | 
					1ed81ff731 | ||
| 
						 | 
					b2dc2e6dac | ||
| 
						 | 
					1b787fc04c | ||
| 
						 | 
					9a6401acdf | ||
| 
						 | 
					c40fcc1e40 | ||
| 
						 | 
					f908ca4db4 | ||
| 
						 | 
					72f6453c48 | ||
| 
						 | 
					eca7b90771 | ||
| 
						 | 
					7eb90ccefb | ||
| 
						 | 
					6ed534782f | ||
| 
						 | 
					1ee27238f7 | ||
| 
						 | 
					59689735a6 | ||
| 
						 | 
					1be16287ee | ||
| 
						 | 
					9fe4b73d97 | ||
| 
						 | 
					73cb37295d | ||
| 
						 | 
					1f35508ae6 | ||
| 
						 | 
					3e2a74c294 | ||
| 
						 | 
					a34922c476 | ||
| 
						 | 
					84be7091fd | ||
| 
						 | 
					f82c1f0dd8 | ||
| 
						 | 
					dc0cb7e74f | ||
| 
						 | 
					ab31dbc482 | ||
| 
						 | 
					36e9d3ee91 | ||
| 
						 | 
					cc8c0f6b46 | ||
| 
						 | 
					3eac70a356 | ||
| 
						 | 
					5f3ad8f82c | ||
| 
						 | 
					367316c723 | ||
| 
						 | 
					d34353cc91 | ||
| 
						 | 
					6287fa5396 | ||
| 
						 | 
					a00c3c4019 | ||
| 
						 | 
					f4677b7960 | ||
| 
						 | 
					92308905dd | ||
| 
						 | 
					6f32fc5c4e | ||
| 
						 | 
					e607e731eb | ||
| 
						 | 
					f17c45611e | ||
| 
						 | 
					1ff7b6492b | ||
| 
						 | 
					20900d6801 | ||
| 
						 | 
					4b253d904d | ||
| 
						 | 
					a51c8c64e0 | ||
| 
						 | 
					c153422388 | ||
| 
						 | 
					7f065cfdbd | ||
| 
						 | 
					667fbc0847 | ||
| 
						 | 
					6ba7bd5697 | ||
| 
						 | 
					2cad035c01 | ||
| 
						 | 
					2a76c68842 | ||
| 
						 | 
					1b00f4bc37 | ||
| 
						 | 
					be62eb6d93 | ||
| 
						 | 
					5f3878f1e3 | ||
| 
						 | 
					a523e997d3 | ||
| 
						 | 
					fe43caa4a4 | ||
| 
						 | 
					792e614144 | ||
| 
						 | 
					ce2b87d88a | ||
| 
						 | 
					f092a073a7 | ||
| 
						 | 
					6fa4cd7136 | ||
| 
						 | 
					505ed2b076 | ||
| 
						 | 
					cef3e62d2b | ||
| 
						 | 
					40ea9ff9e8 | ||
| 
						 | 
					a97a6b03bc | ||
| 
						 | 
					516f76fd2c | ||
| 
						 | 
					5a02ac6e5b | ||
| 
						 | 
					14d4074ee1 | ||
| 
						 | 
					d9f16c405c | ||
| 
						 | 
					bfc6482a7a | ||
| 
						 | 
					5aa032033e | ||
| 
						 | 
					2d59f9938f | ||
| 
						 | 
					c0ce8fe755 | ||
| 
						 | 
					55eff40084 | ||
| 
						 | 
					e5a251843d | ||
| 
						 | 
					fe46b0de29 | ||
| 
						 | 
					a581439bb1 | ||
| 
						 | 
					a43337e8c4 | ||
| 
						 | 
					33c51ec143 | ||
| 
						 | 
					448da15fbf | ||
| 
						 | 
					a1bb2d6c2f | ||
| 
						 | 
					81dde5e8fe | ||
| 
						 | 
					b84e441861 | ||
| 
						 | 
					08e012bbec | ||
| 
						 | 
					b46acc392b | ||
| 
						 | 
					28af6367b8 | ||
| 
						 | 
					2c17b493b1 | ||
| 
						 | 
					ea725a66c9 | ||
| 
						 | 
					1532493dab | ||
| 
						 | 
					3795297af8 | ||
| 
						 | 
					33fd33d423 | ||
| 
						 | 
					4e98f8863f | ||
| 
						 | 
					582ef3dbdb | ||
| 
						 | 
					6a933782fa | ||
| 
						 | 
					d1c2778e93 | ||
| 
						 | 
					8d64abacc6 | ||
| 
						 | 
					9af6802943 | ||
| 
						 | 
					c10f53a897 | ||
| 
						 | 
					2124e869a8 | ||
| 
						 | 
					3b668eedda | ||
| 
						 | 
					7471431322 | ||
| 
						 | 
					1542de4eed | ||
| 
						 | 
					b6c2bffbdf | ||
| 
						 | 
					ff09931e22 | ||
| 
						 | 
					155c70b882 | ||
| 
						 | 
					7c49452973 | ||
| 
						 | 
					312539ae9f | ||
| 
						 | 
					cc40dcce58 | ||
| 
						 | 
					5790921aea | ||
| 
						 | 
					df84c11407 | ||
| 
						 | 
					b76306c983 | ||
| 
						 | 
					cdffc716c9 | ||
| 
						 | 
					5dffc13f55 | ||
| 
						 | 
					a5873a8d3d | ||
| 
						 | 
					4db3e88459 | ||
| 
						 | 
					ab073bad4f | ||
| 
						 | 
					cfe04f607d | ||
| 
						 | 
					c0e9f540e0 | ||
| 
						 | 
					7c97aacbe8 | ||
| 
						 | 
					36b8f87566 | ||
| 
						 | 
					d875413a0b | ||
| 
						 | 
					155ad6d219 | ||
| 
						 | 
					138f20433e | ||
| 
						 | 
					7747c67861 | ||
| 
						 | 
					237a6f06b6 | ||
| 
						 | 
					fe99beb82a | ||
| 
						 | 
					736a77f275 | ||
| 
						 | 
					94539213a1 | ||
| 
						 | 
					c5c4246319 | ||
| 
						 | 
					2e6d8a8991 | ||
| 
						 | 
					e852835da6 | ||
| 
						 | 
					d245c32529 | ||
| 
						 | 
					964d58bcb0 | ||
| 
						 | 
					52702f6f92 | ||
| 
						 | 
					05794d983f | ||
| 
						 | 
					364f36f851 | ||
| 
						 | 
					9b809d6278 | ||
| 
						 | 
					bbefea3387 | ||
| 
						 | 
					d83dde6180 | ||
| 
						 | 
					63e1319d0f | ||
| 
						 | 
					8067d34b3a | ||
| 
						 | 
					e3f2860e73 | ||
| 
						 | 
					92eb44d238 | ||
| 
						 | 
					f4179bead4 | ||
| 
						 | 
					fced277486 | ||
| 
						 | 
					3d1be455ce | ||
| 
						 | 
					dee4d129cb | ||
| 
						 | 
					0067bd77a8 | ||
| 
						 | 
					d98904e5a7 | ||
| 
						 | 
					96a259e81e | ||
| 
						 | 
					59f3477b82 | ||
| 
						 | 
					f947b818bf | ||
| 
						 | 
					3fa1a444ce | ||
| 
						 | 
					a2dc9b6be2 | ||
| 
						 | 
					16349eeceb | ||
| 
						 | 
					aecf1c1f96 | ||
| 
						 | 
					4ea574fdf3 | ||
| 
						 | 
					cf8115deb0 | ||
| 
						 | 
					d25cbda074 | ||
| 
						 | 
					5d582fd516 | ||
| 
						 | 
					8ec86dcf04 | ||
| 
						 | 
					6d3b70c8da | ||
| 
						 | 
					0a4fda742b | ||
| 
						 | 
					3745e57bf9 | ||
| 
						 | 
					b7e7aa00de | ||
| 
						 | 
					1098fd48ce | ||
| 
						 | 
					393906d9be | ||
| 
						 | 
					446881468c | ||
| 
						 | 
					cfb95ba9f6 | ||
| 
						 | 
					c198c26226 | ||
| 
						 | 
					54d6ddba69 | ||
| 
						 | 
					1af12ff1d1 | ||
| 
						 | 
					bd72b8eca6 | ||
| 
						 | 
					200d00c854 | ||
| 
						 | 
					669b912dea | ||
| 
						 | 
					36a4a67b2b | ||
| 
						 | 
					3413424f01 | ||
| 
						 | 
					80fc840d89 | ||
| 
						 | 
					6455100f7a | ||
| 
						 | 
					b7c8b4fc95 | ||
| 
						 | 
					f58d0f70b6 | ||
| 
						 | 
					8f59c61d1d | ||
| 
						 | 
					fd43ae3fe4 | ||
| 
						 | 
					cdd0f3b328 | ||
| 
						 | 
					f9f6f0e9f0 | ||
| 
						 | 
					405f382144 | ||
| 
						 | 
					a750273546 | ||
| 
						 | 
					ddc5f6f328 | ||
| 
						 | 
					4231b356aa | ||
| 
						 | 
					df1f7b4b02 | ||
| 
						 | 
					0b7545b239 | ||
| 
						 | 
					3a72137211 | ||
| 
						 | 
					e5d289cc03 | ||
| 
						 | 
					0ff3766b0e | ||
| 
						 | 
					3562202306 | ||
| 
						 | 
					2bf4b96aef | ||
| 
						 | 
					811e08a2c5 | ||
| 
						 | 
					dd6e90465d | ||
| 
						 | 
					a86c626802 | ||
| 
						 | 
					705c3dec2c | ||
| 
						 | 
					4afcee8b4b | ||
| 
						 | 
					9627017f9c | ||
| 
						 | 
					e0f6c15418 | ||
| 
						 | 
					ecc20b75f8 | ||
| 
						 | 
					540e455e3a | ||
| 
						 | 
					14748adb09 | ||
| 
						 | 
					ff2ab9e6bb | ||
| 
						 | 
					cc5cc3bb8f | ||
| 
						 | 
					1f3206216b | ||
| 
						 | 
					f113bb9f4e | ||
| 
						 | 
					4681147bb3 | ||
| 
						 | 
					52c3f232e4 | ||
| 
						 | 
					3dc466424e | ||
| 
						 | 
					353415cc81 | ||
| 
						 | 
					1a12ce8ea5 | ||
| 
						 | 
					0278e15fa3 | ||
| 
						 | 
					f01f085cb9 | ||
| 
						 | 
					bca68e90cc | ||
| 
						 | 
					a3f67ec18d | ||
| 
						 | 
					56ef1cbc40 | ||
| 
						 | 
					a1411093f0 | ||
| 
						 | 
					f35f7d9fbb | ||
| 
						 | 
					dfbf646ac4 | ||
| 
						 | 
					591371566e | ||
| 
						 | 
					5799b72178 | ||
| 
						 | 
					1cfe6842d5 | ||
| 
						 | 
					f4c98a6a3d | ||
| 
						 | 
					4aefb1dd98 | ||
| 
						 | 
					aa03989791 | ||
| 
						 | 
					a865b2c320 | ||
| 
						 | 
					694ce314a8 | ||
| 
						 | 
					94299a36a6 | ||
| 
						 | 
					3aaeb5c1e5 | ||
| 
						 | 
					80ec6cc806 | ||
| 
						 | 
					3d83320279 | ||
| 
						 | 
					4ab252d198 | ||
| 
						 | 
					058ffd7623 | ||
| 
						 | 
					0330a13aea | ||
| 
						 | 
					467325b81d | ||
| 
						 | 
					00f716bbe6 | ||
| 
						 | 
					2f2f032497 | ||
| 
						 | 
					feb200bbb3 | ||
| 
						 | 
					3894667036 | ||
| 
						 | 
					203ac694e3 | ||
| 
						 | 
					bb592c75e7 | ||
| 
						 | 
					777d717c40 | ||
| 
						 | 
					143d84590f | ||
| 
						 | 
					a29669d78d | ||
| 
						 | 
					e5be1e1696 | ||
| 
						 | 
					9e47c34729 | ||
| 
						 | 
					cb896f8923 | ||
| 
						 | 
					cec9bce126 | ||
| 
						 | 
					3f79793b7e | ||
| 
						 | 
					0d01d8a735 | ||
| 
						 | 
					2c0fa03dc6 | ||
| 
						 | 
					d3b3a6d389 | ||
| 
						 | 
					fc260b09a1 | ||
| 
						 | 
					b3c79a8a27 | ||
| 
						 | 
					f0ecefc0c0 | ||
| 
						 | 
					b0118409a9 | ||
| 
						 | 
					5f23288692 | ||
| 
						 | 
					45c58c7d10 | ||
| 
						 | 
					112591be76 | ||
| 
						 | 
					1b8daa3693 | ||
| 
						 | 
					1cdbc755ee | ||
| 
						 | 
					aa9c7e4b8c | ||
| 
						 | 
					6be69a168f | ||
| 
						 | 
					eaf76feeb6 | ||
| 
						 | 
					03e79ed05e | ||
| 
						 | 
					56bef2df4f | ||
| 
						 | 
					10d3886c51 | ||
| 
						 | 
					f1c0cf5b70 | ||
| 
						 | 
					2a7ac69ee4 | ||
| 
						 | 
					d13ea8e184 | ||
| 
						 | 
					1820b04bb2 | ||
| 
						 | 
					439b7ef463 | ||
| 
						 | 
					a25fb95bd6 | ||
| 
						 | 
					6168067160 | ||
| 
						 | 
					c3031a4610 | ||
| 
						 | 
					1099a94063 | ||
| 
						 | 
					812d8a176c | ||
| 
						 | 
					db533c96e3 | ||
| 
						 | 
					8831eb7624 | ||
| 
						 | 
					3c8f315021 | ||
| 
						 | 
					0f2e636602 | ||
| 
						 | 
					98bd148b1a | ||
| 
						 | 
					292248b8c2 | ||
| 
						 | 
					d3eef3e5af | ||
| 
						 | 
					c5fbf8c1ba | ||
| 
						 | 
					1ed2d8f512 | ||
| 
						 | 
					d140890259 | ||
| 
						 | 
					eb492df2bb | ||
| 
						 | 
					2c16e78400 | ||
| 
						 | 
					bf2b87aea3 | ||
| 
						 | 
					1dff425999 | ||
| 
						 | 
					501af5ba89 | ||
| 
						 | 
					31d6e7b7ba | ||
| 
						 | 
					b983322bfb | ||
| 
						 | 
					339654e163 | ||
| 
						 | 
					5ca48cc853 | ||
| 
						 | 
					79996e3335 | ||
| 
						 | 
					173acc185c | ||
| 
						 | 
					a985ecdd17 | ||
| 
						 | 
					fb4c24b6e7 | ||
| 
						 | 
					1366f6b9bd | ||
| 
						 | 
					e13546f739 | ||
| 
						 | 
					d6c813daff | ||
| 
						 | 
					e3818a4c4b | ||
| 
						 | 
					415fe2abe9 | ||
| 
						 | 
					5bbdaaf4b7 | ||
| 
						 | 
					bf1f1a5759 | ||
| 
						 | 
					8e42429c9d | ||
| 
						 | 
					c43c2285f6 | ||
| 
						 | 
					94b2c29f9d | ||
| 
						 | 
					090f931a35 | ||
| 
						 | 
					6b8be6da76 | ||
| 
						 | 
					7ec2d392e7 | ||
| 
						 | 
					e88f66bb49 | ||
| 
						 | 
					28a2759ab8 | ||
| 
						 | 
					3edad44d6e | ||
| 
						 | 
					9e7459fc5d | ||
| 
						 | 
					b98f5ef42b | ||
| 
						 | 
					a6d4f79f24 | ||
| 
						 | 
					efcb7a75fc | ||
| 
						 | 
					30aa23fea2 | ||
| 
						 | 
					c9e045041e | ||
| 
						 | 
					fd6fa9c0b2 | ||
| 
						 | 
					9f70d09275 | ||
| 
						 | 
					3fb0f01001 | ||
| 
						 | 
					216ac24bd3 | ||
| 
						 | 
					2035af2091 | ||
| 
						 | 
					19398a175a | ||
| 
						 | 
					fa369ddbe7 | ||
| 
						 | 
					294ba3c282 | ||
| 
						 | 
					2923e91a98 | ||
| 
						 | 
					7c52b7706f | ||
| 
						 | 
					ddec587581 | ||
| 
						 | 
					4f466f8e81 | ||
| 
						 | 
					1502cda142 | ||
| 
						 | 
					ce2b5d7574 | ||
| 
						 | 
					f1c65db80b | ||
| 
						 | 
					496970b233 | ||
| 
						 | 
					3b0e61a812 | ||
| 
						 | 
					e84b0d709b | ||
| 
						 | 
					16241f0ea4 | ||
| 
						 | 
					518af4e3ae | ||
| 
						 | 
					fe01f90a1c | ||
| 
						 | 
					99a376df16 | ||
| 
						 | 
					831ffcb705 | ||
| 
						 | 
					5f297c4504 | ||
| 
						 | 
					d7623ff9f3 | ||
| 
						 | 
					df9b5405e8 | ||
| 
						 | 
					180eb5b3c2 | ||
| 
						 | 
					af7d49aaff | ||
| 
						 | 
					187b655bc2 | ||
| 
						 | 
					8612cb9239 | ||
| 
						 | 
					b2f3fafa6a | ||
| 
						 | 
					483dab147d | ||
| 
						 | 
					f39b8e697c | ||
| 
						 | 
					7d610299c9 | ||
| 
						 | 
					25550b2dd4 | ||
| 
						 | 
					5c676c47cd | ||
| 
						 | 
					e77f9d5e78 | ||
| 
						 | 
					9c04747623 | ||
| 
						 | 
					e66deb6817 | ||
| 
						 | 
					cc9a645a02 | ||
| 
						 | 
					18fb9d807e | ||
| 
						 | 
					a1cc568288 | ||
| 
						 | 
					2ea3cd8abc | ||
| 
						 | 
					095db72024 | ||
| 
						 | 
					11eb172b6e | ||
| 
						 | 
					4b60f4b175 | ||
| 
						 | 
					0794f3a798 | ||
| 
						 | 
					2b8e7b5061 | ||
| 
						 | 
					6f57311da0 | ||
| 
						 | 
					98b09d3949 | ||
| 
						 | 
					231a737a82 | ||
| 
						 | 
					236860735e | ||
| 
						 | 
					ac1ef7ec72 | ||
| 
						 | 
					5f761514e1 | ||
| 
						 | 
					32f1f622f6 | ||
| 
						 | 
					5f95651316 | ||
| 
						 | 
					ccac657556 | ||
| 
						 | 
					a9c23ea079 | ||
| 
						 | 
					33ffe2a7f7 | ||
| 
						 | 
					7c717aafc6 | ||
| 
						 | 
					225aeb171e | ||
| 
						 | 
					ffe181c366 | ||
| 
						 | 
					fd4e79a9ed | ||
| 
						 | 
					299e174d2d | ||
| 
						 | 
					ce62fc6eae | ||
| 
						 | 
					43490dfb89 | ||
| 
						 | 
					a523276786 | ||
| 
						 | 
					074471ab0c | ||
| 
						 | 
					d761421e1d | ||
| 
						 | 
					2339c5d722 | ||
| 
						 | 
					dd00266757 | ||
| 
						 | 
					bb99ce5f80 | ||
| 
						 | 
					49f42ec0f6 | ||
| 
						 | 
					91d509f0d9 | ||
| 
						 | 
					d5e858c55f | ||
| 
						 | 
					fb8fcce2ac | ||
| 
						 | 
					d4736ae701 | ||
| 
						 | 
					3e1158522a | ||
| 
						 | 
					57191f86d9 | ||
| 
						 | 
					0a89c575de | ||
| 
						 | 
					4c860910df | ||
| 
						 | 
					0fc3d51b7d | ||
| 
						 | 
					c4b0d7879e | ||
| 
						 | 
					aab1ec3f36 | ||
| 
						 | 
					fbfa11fb29 | ||
| 
						 | 
					284498fcef | ||
| 
						 | 
					07d9808496 | ||
| 
						 | 
					4ab0088bfe | ||
| 
						 | 
					3bd1690bfb | ||
| 
						 | 
					29f4b05954 | ||
| 
						 | 
					48ca0c99b2 | ||
| 
						 | 
					015052cf7b | ||
| 
						 | 
					9ce3ee47ba | ||
| 
						 | 
					2e3fd54337 | ||
| 
						 | 
					625782f7ee | ||
| 
						 | 
					1c90899eef | ||
| 
						 | 
					4f2b7d48b1 | ||
| 
						 | 
					458c3900e1 | ||
| 
						 | 
					ba75b4e750 | ||
| 
						 | 
					ab011d51be | ||
| 
						 | 
					898d9b1a87 | ||
| 
						 | 
					4f9a9d2b79 | ||
| 
						 | 
					346f2f93e1 | ||
| 
						 | 
					25b0e072dd | ||
| 
						 | 
					dc13c882fb | ||
| 
						 | 
					12a52467c8 | ||
| 
						 | 
					22e6c73dcc | ||
| 
						 | 
					53b9696f3f | ||
| 
						 | 
					7e4fe4662b | ||
| 
						 | 
					18fd413f37 | ||
| 
						 | 
					80ed5f84de | ||
| 
						 | 
					b48111df7c | ||
| 
						 | 
					73e3edd70d | ||
| 
						 | 
					d4cfbdf2c0 | ||
| 
						 | 
					294f03a812 | ||
| 
						 | 
					272f9f3d27 | ||
| 
						 | 
					927a28ba3b | ||
| 
						 | 
					a938c4284e | ||
| 
						 | 
					7a44a0cee7 | ||
| 
						 | 
					82430309ac | ||
| 
						 | 
					c2079de880 | ||
| 
						 | 
					967ead7269 | ||
| 
						 | 
					c9255df519 | ||
| 
						 | 
					27c824a1c9 | ||
| 
						 | 
					5b96d1ccf9 | ||
| 
						 | 
					29c0866b38 | ||
| 
						 | 
					0214ea0dfe | ||
| 
						 | 
					80355002a1 | ||
| 
						 | 
					0e36825228 | ||
| 
						 | 
					95a8f1469f | ||
| 
						 | 
					afdbadc704 | ||
| 
						 | 
					004cc26abf | ||
| 
						 | 
					35a924c576 | ||
| 
						 | 
					99279ac97a | ||
| 
						 | 
					87605ca1e2 | ||
| 
						 | 
					7cc586f117 | ||
| 
						 | 
					c263a6092c | ||
| 
						 | 
					f92fd85400 | ||
| 
						 | 
					e71520ddd6 | ||
| 
						 | 
					275f34b5d2 | ||
| 
						 | 
					50fbb6ed36 | ||
| 
						 | 
					34fdacbd35 | ||
| 
						 | 
					77f2d20dbc | ||
| 
						 | 
					0dbfbf26cb | ||
| 
						 | 
					2863a6878f | ||
| 
						 | 
					ae46e91e4d | ||
| 
						 | 
					865a90eb4f | ||
| 
						 | 
					0269c4507c | ||
| 
						 | 
					a5d3574984 | ||
| 
						 | 
					1040deb0c5 | ||
| 
						 | 
					05ea800faf | ||
| 
						 | 
					341f87862c | ||
| 
						 | 
					f805d30769 | ||
| 
						 | 
					4fb9472cc2 | ||
| 
						 | 
					a8098740c6 | ||
| 
						 | 
					e3af0d041e | ||
| 
						 | 
					28cfda9f30 | ||
| 
						 | 
					a313e23fff | ||
| 
						 | 
					4d2a292e8a | ||
| 
						 | 
					5a84b7fc2d | ||
| 
						 | 
					d8e660a6dc | ||
| 
						 | 
					761f3b403b | ||
| 
						 | 
					4570d29404 | ||
| 
						 | 
					14346b3456 | ||
| 
						 | 
					769f58aaaa | ||
| 
						 | 
					a166e96d16 | ||
| 
						 | 
					8dd8ce1dc3 | ||
| 
						 | 
					4c5979a107 | ||
| 
						 | 
					649ab2dcfa | ||
| 
						 | 
					71fc9b37ae | ||
| 
						 | 
					283aedf498 | ||
| 
						 | 
					1a56614af2 | ||
| 
						 | 
					693c33e407 | ||
| 
						 | 
					d9a9aa027d | ||
| 
						 | 
					b22250bb67 | ||
| 
						 | 
					d446120527 | ||
| 
						 | 
					bb9d68489c | ||
| 
						 | 
					affaea59fe | ||
| 
						 | 
					81fc4c93ef | ||
| 
						 | 
					8957121c14 | ||
| 
						 | 
					50241bc84e | ||
| 
						 | 
					e7f077f1ba | ||
| 
						 | 
					c3b82c7610 | ||
| 
						 | 
					2c12e7f6f5 | ||
| 
						 | 
					8db10d9ac4 | ||
| 
						 | 
					c3cc4662af | ||
| 
						 | 
					22892f9803 | ||
| 
						 | 
					27eb115fb6 | ||
| 
						 | 
					51a596ef4f | ||
| 
						 | 
					97de8bd1e0 | ||
| 
						 | 
					1cb7e5be5b | ||
| 
						 | 
					84dd04e761 | ||
| 
						 | 
					2ac061e487 | ||
| 
						 | 
					7cdb81582c | ||
| 
						 | 
					8f33b40302 | ||
| 
						 | 
					e600614ef5 | ||
| 
						 | 
					02581dea1f | ||
| 
						 | 
					40ad08bcc2 | ||
| 
						 | 
					9c4456a13f | ||
| 
						 | 
					f4d0392faa | ||
| 
						 | 
					45ba6cfe03 | ||
| 
						 | 
					4f23a0c797 | ||
| 
						 | 
					f6c32bbf2b | ||
| 
						 | 
					d040c951f0 | ||
| 
						 | 
					69abfb0e33 | ||
| 
						 | 
					9a1daf8482 | ||
| 
						 | 
					9de6dc3af3 | ||
| 
						 | 
					248834dcaa | ||
| 
						 | 
					11a7da7c9f | ||
| 
						 | 
					9fea0b9937 | ||
| 
						 | 
					6fd3f3260d | ||
| 
						 | 
					d9e262443c | ||
| 
						 | 
					51c3bb3b98 | ||
| 
						 | 
					7d608f9e32 | ||
| 
						 | 
					295de18c8a | ||
| 
						 | 
					3370b694b9 | ||
| 
						 | 
					3380c52f15 | ||
| 
						 | 
					1364e6f1ac | ||
| 
						 | 
					c5ac2aa62c | ||
| 
						 | 
					392a0345de | ||
| 
						 | 
					5c2fc73e7b | ||
| 
						 | 
					402b951804 | ||
| 
						 | 
					5848d13fed | ||
| 
						 | 
					5dd24ead57 | ||
| 
						 | 
					d2cb94952a | ||
| 
						 | 
					0615396d2d | ||
| 
						 | 
					82877ea449 | ||
| 
						 | 
					81fae49db9 | ||
| 
						 | 
					74ff8dc975 | ||
| 
						 | 
					ac319217d0 | ||
| 
						 | 
					cdb13ae8d0 | ||
| 
						 | 
					ab700807d9 | ||
| 
						 | 
					744b91bb9f | ||
| 
						 | 
					d69f85bf15 | ||
| 
						 | 
					52ee969e29 | ||
| 
						 | 
					55f0501201 | ||
| 
						 | 
					b2710ee19a | ||
| 
						 | 
					bbfcc4724d | ||
| 
						 | 
					c31cc72d79 | ||
| 
						 | 
					d1049ad93e | ||
| 
						 | 
					5f4cc234fb | ||
| 
						 | 
					d31a13953c | ||
| 
						 | 
					28f5873179 | ||
| 
						 | 
					8f813338f1 | ||
| 
						 | 
					6555dfa486 | ||
| 
						 | 
					5eee0253e5 | ||
| 
						 | 
					594c723f98 | ||
| 
						 | 
					f418265865 | ||
| 
						 | 
					53707e2eec | ||
| 
						 | 
					fde794e898 | ||
| 
						 | 
					082f19b42d | ||
| 
						 | 
					e31c620686 | ||
| 
						 | 
					570253315f | ||
| 
						 | 
					5dcdac6e4e | ||
| 
						 | 
					eea3fce854 | ||
| 
						 | 
					215c49d032 | ||
| 
						 | 
					923df53e25 | ||
| 
						 | 
					1a684d0020 | ||
| 
						 | 
					dc3b721fa0 | ||
| 
						 | 
					4479ce9c1c | ||
| 
						 | 
					4a0d3530e0 | ||
| 
						 | 
					9907d2992d | ||
| 
						 | 
					9d9224f184 | ||
| 
						 | 
					78d4d87e39 | ||
| 
						 | 
					6211633273 | ||
| 
						 | 
					3a4cf918bf | ||
| 
						 | 
					e25eb309ec | ||
| 
						 | 
					ffa2b2aa7d | ||
| 
						 | 
					a77a95584d | ||
| 
						 | 
					68bb98159f | ||
| 
						 | 
					8e6905d238 | ||
| 
						 | 
					1a8521ff24 | ||
| 
						 | 
					9d5460d72d | ||
| 
						 | 
					35e59297fc | ||
| 
						 | 
					9b945233b1 | ||
| 
						 | 
					b065dc2eee | ||
| 
						 | 
					66c4bb1a70 | ||
| 
						 | 
					36abe6fe61 | ||
| 
						 | 
					3c786aa6c8 | ||
| 
						 | 
					e5cce6d356 | ||
| 
						 | 
					723b7d81e4 | ||
| 
						 | 
					a3ddd7358b | ||
| 
						 | 
					45c027f31f | ||
| 
						 | 
					3b62e9eb0d | ||
| 
						 | 
					34a8c7ec87 | ||
| 
						 | 
					d4a6240005 | ||
| 
						 | 
					5c6f76da0a | ||
| 
						 | 
					4636341b05 | ||
| 
						 | 
					be3b770d8f | ||
| 
						 | 
					af32387b3f | ||
| 
						 | 
					115fc340cb | ||
| 
						 | 
					900f7a8776 | ||
| 
						 | 
					4877e30504 | ||
| 
						 | 
					4656ec3852 | ||
| 
						 | 
					e336441197 | ||
| 
						 | 
					20d6182f33 | ||
| 
						 | 
					aa145866f9 | ||
| 
						 | 
					fdff41e166 | ||
| 
						 | 
					07b4bc3979 | ||
| 
						 | 
					0c66d3ae37 | ||
| 
						 | 
					bd869183d5 | ||
| 
						 | 
					7e2bf83100 | ||
| 
						 | 
					25e52a78fb | ||
| 
						 | 
					47c4bb2ddf | ||
| 
						 | 
					951dfbb13a | ||
| 
						 | 
					81780a3b62 | ||
| 
						 | 
					c574d0cdf2 | ||
| 
						 | 
					c987c3f999 | ||
| 
						 | 
					1a5e414863 | ||
| 
						 | 
					ec3639385e | ||
| 
						 | 
					f01cfca6a4 | ||
| 
						 | 
					7d5af5e0fa | ||
| 
						 | 
					8fdb296cbd | ||
| 
						 | 
					879b30aaa3 | ||
| 
						 | 
					40ddcb717a | ||
| 
						 | 
					da1841a075 | ||
| 
						 | 
					0a0a10d127 | ||
| 
						 | 
					df20b6e79b | ||
| 
						 | 
					f4f1dc39e0 | ||
| 
						 | 
					340b4dd7df | ||
| 
						 | 
					4b9dcd821f | ||
| 
						 | 
					669c5c9380 | ||
| 
						 | 
					7f9aa6c59b | ||
| 
						 | 
					d9c06b56ca | ||
| 
						 | 
					d045e1d77e | ||
| 
						 | 
					6d14cc7ec1 | ||
| 
						 | 
					eb499b2854 | ||
| 
						 | 
					65a82ef6d7 | ||
| 
						 | 
					616f581650 | ||
| 
						 | 
					57e802656f | ||
| 
						 | 
					5d7f15daf8 | ||
| 
						 | 
					ec67e3b7e4 | ||
| 
						 | 
					0d3ff3c073 | ||
| 
						 | 
					325e48867c | ||
| 
						 | 
					8de95bc05b | ||
| 
						 | 
					5e3003bb52 | ||
| 
						 | 
					e6e3f38bfa | ||
| 
						 | 
					aa17ab7e57 | ||
| 
						 | 
					35908bd040 | ||
| 
						 | 
					4a9cfd763e | ||
| 
						 | 
					0e73294e26 | ||
| 
						 | 
					b610f46bae | ||
| 
						 | 
					1921a1adb2 | ||
| 
						 | 
					6d2cd23f40 | ||
| 
						 | 
					14fb67f28a | ||
| 
						 | 
					c552680473 | ||
| 
						 | 
					edbf9f878d | ||
| 
						 | 
					2745ddfc33 | ||
| 
						 | 
					808606034a | ||
| 
						 | 
					e18eef3d7a | ||
| 
						 | 
					e78fc11a95 | ||
| 
						 | 
					83231cb376 | ||
| 
						 | 
					986ad56124 | ||
| 
						 | 
					b723a7b11b | ||
| 
						 | 
					1b6b67b17e | ||
| 
						 | 
					1ee3236f72 | ||
| 
						 | 
					b03a4917be | ||
| 
						 | 
					84971b39f5 | ||
| 
						 | 
					5ab3e743f3 | ||
| 
						 | 
					1c5dc844e7 | ||
| 
						 | 
					f871949efd | ||
| 
						 | 
					eb2ec6bee9 | ||
| 
						 | 
					df22f59f6e | ||
| 
						 | 
					db0edc3273 | ||
| 
						 | 
					6300c14248 | ||
| 
						 | 
					d4426e79a7 | ||
| 
						 | 
					b095418d20 | ||
| 
						 | 
					d6fd880481 | ||
| 
						 | 
					cbb0b734c7 | ||
| 
						 | 
					f4bcd70f27 | ||
| 
						 | 
					6e16b45d9d | ||
| 
						 | 
					e09e7ab362 | ||
| 
						 | 
					d5cc2f19cd | ||
| 
						 | 
					b7a80146f4 | ||
| 
						 | 
					5586a71a6e | ||
| 
						 | 
					81418b7c77 | ||
| 
						 | 
					8bd0c77ae3 | ||
| 
						 | 
					e2217e7ed5 | ||
| 
						 | 
					51b75ea7ef | ||
| 
						 | 
					41d4d6721c | ||
| 
						 | 
					9d01d50459 | ||
| 
						 | 
					e27c67c5c5 | ||
| 
						 | 
					e7decd5f4d | ||
| 
						 | 
					38a3178185 | ||
| 
						 | 
					58828ae573 | ||
| 
						 | 
					6b5f5e3508 | ||
| 
						 | 
					f0ec771933 | ||
| 
						 | 
					22d1087e16 | ||
| 
						 | 
					9f85fcefdc | ||
| 
						 | 
					269d2575cd | ||
| 
						 | 
					0b8ed5de2d | ||
| 
						 | 
					c22684eac9 | ||
| 
						 | 
					c42cd4b831 | ||
| 
						 | 
					4d018f7067 | ||
| 
						 | 
					46eaf3b0cc | ||
| 
						 | 
					9df2a00b94 | ||
| 
						 | 
					fbcf4bc1f2 | ||
| 
						 | 
					ca08c064bb | ||
| 
						 | 
					02df47d349 | ||
| 
						 | 
					41c39e3366 | ||
| 
						 | 
					45803988ce | ||
| 
						 | 
					28251e7ff9 | ||
| 
						 | 
					217382d584 | ||
| 
						 | 
					82a2cb6f51 | ||
| 
						 | 
					611ed5f312 | ||
| 
						 | 
					27fbb5dbf4 | ||
| 
						 | 
					db8d9b7cf1 | ||
| 
						 | 
					60ec950517 | ||
| 
						 | 
					2cd4ebc01f | ||
| 
						 | 
					5f4dcaf781 | ||
| 
						 | 
					c55d882fab | ||
| 
						 | 
					8dc7450068 | ||
| 
						 | 
					2e885232c2 | ||
| 
						 | 
					970d9b3795 | ||
| 
						 | 
					2f58af0d85 | ||
| 
						 | 
					0ae50f19da | ||
| 
						 | 
					c4ac37361e | ||
| 
						 | 
					3152861e81 | ||
| 
						 | 
					a14afd0804 | ||
| 
						 | 
					25d5d1a60d | ||
| 
						 | 
					6ff58b9240 | ||
| 
						 | 
					99237262d4 | ||
| 
						 | 
					29982dfd15 | ||
| 
						 | 
					6c4da94687 | ||
| 
						 | 
					6986d0e6eb | ||
| 
						 | 
					bc9320452c | ||
| 
						 | 
					23d43aae27 | ||
| 
						 | 
					de71735e7c | ||
| 
						 | 
					05decf3638 | ||
| 
						 | 
					95bffa1a1f | ||
| 
						 | 
					974d52fdb8 | ||
| 
						 | 
					7614f0e55e | ||
| 
						 | 
					0632284f79 | ||
| 
						 | 
					ad4a89f070 | ||
| 
						 | 
					6104c49f31 | ||
| 
						 | 
					07fc760999 | ||
| 
						 | 
					cf6bc84148 | ||
| 
						 | 
					36d51bea93 | ||
| 
						 | 
					fc12885b1b | ||
| 
						 | 
					ec7033745e | ||
| 
						 | 
					9e31e63147 | ||
| 
						 | 
					feef17fd88 | ||
| 
						 | 
					817f011191 | ||
| 
						 | 
					98c045cf3a | ||
| 
						 | 
					8860f3a82a | ||
| 
						 | 
					43e9f4ca2f | ||
| 
						 | 
					586f843c76 | ||
| 
						 | 
					7cfc9e6d8c | ||
| 
						 | 
					4952ed0fa4 | ||
| 
						 | 
					a084185d76 | ||
| 
						 | 
					914b80d276 | ||
| 
						 | 
					282557da52 | ||
| 
						 | 
					5f649d583c | ||
| 
						 | 
					b98225ebf5 | ||
| 
						 | 
					abb0c2bba4 | ||
| 
						 | 
					b3bdb474a9 | ||
| 
						 | 
					d796e6acb7 | ||
| 
						 | 
					d3afc92bc9 | ||
| 
						 | 
					35a97b4b7b | ||
| 
						 | 
					f59463aad3 | ||
| 
						 | 
					ed656499c4 | ||
| 
						 | 
					63533e9a22 | ||
| 
						 | 
					20f7053254 | ||
| 
						 | 
					8b8ef74d39 | ||
| 
						 | 
					3bfe024d8d | ||
| 
						 | 
					063333e03d | ||
| 
						 | 
					0a0918ff38 | ||
| 
						 | 
					802c014656 | ||
| 
						 | 
					860841794d | ||
| 
						 | 
					2a87c31237 | ||
| 
						 | 
					da5f7fdcee | ||
| 
						 | 
					d8b408b1de | ||
| 
						 | 
					64932f9e4a | ||
| 
						 | 
					5a20efcf17 | ||
| 
						 | 
					2a2857bbc8 | ||
| 
						 | 
					1bef284ab1 | ||
| 
						 | 
					d8d0b6434f | ||
| 
						 | 
					416b6fd115 | ||
| 
						 | 
					f685cf920b | ||
| 
						 | 
					54f51116b2 | ||
| 
						 | 
					b0d90958fc | ||
| 
						 | 
					049ced2c2f | ||
| 
						 | 
					844b0e603b | ||
| 
						 | 
					75ef751e23 | ||
| 
						 | 
					c4f6e56fca | ||
| 
						 | 
					ff86d3d894 | ||
| 
						 | 
					85b4c03e33 | ||
| 
						 | 
					efaf159af6 | ||
| 
						 | 
					daa657fb78 | ||
| 
						 | 
					4685663d73 | ||
| 
						 | 
					ed1f716022 | ||
| 
						 | 
					d3205a4898 | ||
| 
						 | 
					86731ce2c6 | ||
| 
						 | 
					1399309624 | ||
| 
						 | 
					cb59297438 | ||
| 
						 | 
					5824f6bc06 | ||
| 
						 | 
					5ce7090d54 | ||
| 
						 | 
					7306ab29bc | ||
| 
						 | 
					3a8b42f291 | ||
| 
						 | 
					e4c25383f2 | ||
| 
						 | 
					e734dcc2c7 | ||
| 
						 | 
					0fce007b8e | ||
| 
						 | 
					5a053a3a07 | ||
| 
						 | 
					3b2ba5f7fb | ||
| 
						 | 
					7f622f6c04 | ||
| 
						 | 
					801136bcc2 | ||
| 
						 | 
					3c0e39c539 | ||
| 
						 | 
					19fddebf0e | ||
| 
						 | 
					9eaf7e14c7 | ||
| 
						 | 
					0e441bc103 | ||
| 
						 | 
					cd9911fdf8 | ||
| 
						 | 
					6086422193 | ||
| 
						 | 
					9ddb11f11c | ||
| 
						 | 
					7a20cabd03 | ||
| 
						 | 
					9dc4ca4507 | ||
| 
						 | 
					62fea98b4f | ||
| 
						 | 
					7ae4eac5b6 | ||
| 
						 | 
					fcf8ae5e2b | ||
| 
						 | 
					55b9a7938b | ||
| 
						 | 
					cf1546a60e | ||
| 
						 | 
					e7eec05af0 | ||
| 
						 | 
					98e986141b | ||
| 
						 | 
					d7e35e0371 | ||
| 
						 | 
					222f224664 | ||
| 
						 | 
					62b6cd007f | ||
| 
						 | 
					1682e8fb12 | ||
| 
						 | 
					984aefe0e8 | ||
| 
						 | 
					2d54cc69c9 | ||
| 
						 | 
					2dd8278de8 | ||
| 
						 | 
					e0d8ac972e | ||
| 
						 | 
					ec03812fb0 | ||
| 
						 | 
					93cf2b17bf | ||
| 
						 | 
					77ef1a989d | ||
| 
						 | 
					423c7ac6c6 | ||
| 
						 | 
					2c368ef148 | ||
| 
						 | 
					b3c7162fd0 | ||
| 
						 | 
					67865069eb | ||
| 
						 | 
					1896a9be60 | ||
| 
						 | 
					b5b2c037c1 | ||
| 
						 | 
					1957924d51 | ||
| 
						 | 
					104a66f256 | ||
| 
						 | 
					3de6d65ea3 | ||
| 
						 | 
					fdb0a6e004 | ||
| 
						 | 
					87b857b6bf | ||
| 
						 | 
					b18165301d | ||
| 
						 | 
					097e65944a | ||
| 
						 | 
					0cdd29ea78 | ||
| 
						 | 
					7dec24688f | ||
| 
						 | 
					e62fa54811 | ||
| 
						 | 
					1614174e79 | ||
| 
						 | 
					f95d097359 | ||
| 
						 | 
					3c6ab9aad9 | ||
| 
						 | 
					4913b88f70 | ||
| 
						 | 
					273157153c | ||
| 
						 | 
					fb5156ff38 | ||
| 
						 | 
					2a824402f3 | ||
| 
						 | 
					86a249fe4f | ||
| 
						 | 
					6cae8221c9 | ||
| 
						 | 
					750cb3d248 | ||
| 
						 | 
					f254b540b8 | ||
| 
						 | 
					11024f252e | ||
| 
						 | 
					9d5cba17ba | ||
| 
						 | 
					1d01c9d43d | ||
| 
						 | 
					e32ea81876 | ||
| 
						 | 
					ef8a18f49b | ||
| 
						 | 
					b914049c53 | ||
| 
						 | 
					dabaea8048 | ||
| 
						 | 
					09c1a425a9 | ||
| 
						 | 
					8c6fed007f | ||
| 
						 | 
					2e39604021 | ||
| 
						 | 
					fbfb947b21 | ||
| 
						 | 
					8b963f4ba4 | ||
| 
						 | 
					9152f07eaf | ||
| 
						 | 
					35f70c09f5 | ||
| 
						 | 
					cc4cba7b5d | ||
| 
						 | 
					6b695fefd0 | ||
| 
						 | 
					910d193029 | ||
| 
						 | 
					f18dd687c8 | ||
| 
						 | 
					50d5376698 | ||
| 
						 | 
					5b9b62a7db | ||
| 
						 | 
					c0e29e5b01 | ||
| 
						 | 
					2f03129d46 | ||
| 
						 | 
					b44e2d3416 | ||
| 
						 | 
					564915681c | ||
| 
						 | 
					a24b7eeb87 | ||
| 
						 | 
					0215c01861 | ||
| 
						 | 
					beae6324e5 | ||
| 
						 | 
					71a61c573e | ||
| 
						 | 
					6b3b632767 | ||
| 
						 | 
					2a2fa04b7b | ||
| 
						 | 
					79b81d194b | ||
| 
						 | 
					ef04c9aff8 | ||
| 
						 | 
					7f85197c10 | ||
| 
						 | 
					ff0bfe64af | ||
| 
						 | 
					44b3a3a5e6 | ||
| 
						 | 
					7e3033aa93 | ||
| 
						 | 
					8bdbf50772 | ||
| 
						 | 
					ec33a76641 | ||
| 
						 | 
					00ce9376c7 | ||
| 
						 | 
					46e7a9797e | ||
| 
						 | 
					7006c4ac88 | ||
| 
						 | 
					a50a2126cf | ||
| 
						 | 
					07f7b4b470 | ||
| 
						 | 
					7e726e42f4 | ||
| 
						 | 
					40ba0257de | ||
| 
						 | 
					3fbd5f9fea | ||
| 
						 | 
					57b2246d35 | ||
| 
						 | 
					2a5b22d6f9 | ||
| 
						 | 
					f247dc7522 | ||
| 
						 | 
					e6531253e2 | ||
| 
						 | 
					c938babf00 | ||
| 
						 | 
					bf3900020f | ||
| 
						 | 
					586df3bb7f | ||
| 
						 | 
					c4b13b0268 | ||
| 
						 | 
					daef72316f | ||
| 
						 | 
					1f93c96e63 | ||
| 
						 | 
					8aa9c79276 | ||
| 
						 | 
					09a7f2e734 | ||
| 
						 | 
					b2d27e376d | ||
| 
						 | 
					644c4af11e | ||
| 
						 | 
					ca3dc3a0a0 | ||
| 
						 | 
					2b975dfd5b | ||
| 
						 | 
					0932892278 | ||
| 
						 | 
					fe0b3d98c2 | ||
| 
						 | 
					8d56c8b51c | ||
| 
						 | 
					d8e6409336 | ||
| 
						 | 
					a4ae746656 | ||
| 
						 | 
					331a0a7b9b | ||
| 
						 | 
					c630a3e8d6 | ||
| 
						 | 
					7435d89edf | ||
| 
						 | 
					14557c8be4 | ||
| 
						 | 
					98b4995bad | ||
| 
						 | 
					3000bdcc3a | ||
| 
						 | 
					cbe77a6753 | ||
| 
						 | 
					c58a1f76f8 | ||
| 
						 | 
					ecf2875ebf | ||
| 
						 | 
					ce2c19e357 | ||
| 
						 | 
					1b1081a3ed | ||
| 
						 | 
					37b200389a | ||
| 
						 | 
					6b5a8f3a22 | ||
| 
						 | 
					0b18d8b0c7 | ||
| 
						 | 
					3d187ede47 | ||
| 
						 | 
					f3b9c34515 | ||
| 
						 | 
					c923394924 | ||
| 
						 | 
					d9dbd24db5 | ||
| 
						 | 
					b135819d71 | ||
| 
						 | 
					cbcbd07da2 | ||
| 
						 | 
					24f6ab73a7 | ||
| 
						 | 
					5e88347e1b | ||
| 
						 | 
					cac0d4ee6f | ||
| 
						 | 
					428759b3d4 | ||
| 
						 | 
					898d3ecce0 | ||
| 
						 | 
					004f16f6c4 | ||
| 
						 | 
					4e2a0e58f2 | ||
| 
						 | 
					39d29195a7 | ||
| 
						 | 
					727c9b8027 | ||
| 
						 | 
					bd4e9b0512 | ||
| 
						 | 
					7844ff735f | ||
| 
						 | 
					49e96badcf | ||
| 
						 | 
					eb6a81bacc | ||
| 
						 | 
					6687f12988 | ||
| 
						 | 
					fcd12fc0f1 | ||
| 
						 | 
					0fb4d54068 | ||
| 
						 | 
					830a468a23 | ||
| 
						 | 
					af3ca7b4a9 | ||
| 
						 | 
					7a6bb17255 | ||
| 
						 | 
					bc6d459a6e | ||
| 
						 | 
					ff7f34e353 | ||
| 
						 | 
					2e3d79aaec | ||
| 
						 | 
					8a41bcc934 | ||
| 
						 | 
					e2414b41ad | ||
| 
						 | 
					266958bce7 | ||
| 
						 | 
					bc5354cbf0 | ||
| 
						 | 
					cc4997843e | ||
| 
						 | 
					ab95eac286 | ||
| 
						 | 
					1cd76233d1 | ||
| 
						 | 
					3d5afc8b83 | ||
| 
						 | 
					d28b7799dd | ||
| 
						 | 
					b0fb889c29 | ||
| 
						 | 
					460e80bd1d | ||
| 
						 | 
					bc1e96e942 | ||
| 
						 | 
					7ea61df414 | ||
| 
						 | 
					431712293d | ||
| 
						 | 
					335ed97263 | ||
| 
						 | 
					e00b165e9b | ||
| 
						 | 
					5467ddf0e1 | ||
| 
						 | 
					7a37dd92ed | ||
| 
						 | 
					d0c11e9d72 | ||
| 
						 | 
					5ec52fee2c | ||
| 
						 | 
					5026bc13bb | ||
| 
						 | 
					c7d27e5247 | ||
| 
						 | 
					b7d7af7ea9 | ||
| 
						 | 
					39663d2c40 | ||
| 
						 | 
					000299a0e6 | ||
| 
						 | 
					0a47d82b9b | ||
| 
						 | 
					198bcece58 | ||
| 
						 | 
					053677d124 | ||
| 
						 | 
					804072f014 | ||
| 
						 | 
					e9429b43ce | ||
| 
						 | 
					3d37d5e24a | ||
| 
						 | 
					2728a1b4f3 | ||
| 
						 | 
					adb040d4cb | ||
| 
						 | 
					479d7934c0 | ||
| 
						 | 
					22d1acd5ac | ||
| 
						 | 
					b257c152c6 | ||
| 
						 | 
					77b97ee0d7 | ||
| 
						 | 
					e2ac4732cd | ||
| 
						 | 
					e8f665b495 | ||
| 
						 | 
					55f3ef29ea | ||
| 
						 | 
					c2d78c9623 | ||
| 
						 | 
					a4578a5413 | ||
| 
						 | 
					e884fcf785 | ||
| 
						 | 
					e96025755d | ||
| 
						 | 
					c9028b0ab5 | ||
| 
						 | 
					b4d2858f95 | ||
| 
						 | 
					dea446d995 | ||
| 
						 | 
					5cd94f9e9d | ||
| 
						 | 
					cad811fc41 | ||
| 
						 | 
					69f6a9f007 | ||
| 
						 | 
					4eeee0c59f | ||
| 
						 | 
					a5afa6c95f | ||
| 
						 | 
					625dacb93d | ||
| 
						 | 
					62e9c2e091 | ||
| 
						 | 
					e4106a4e24 | ||
| 
						 | 
					a506b8c7dd | ||
| 
						 | 
					e5cd536894 | ||
| 
						 | 
					629ea39a88 | ||
| 
						 | 
					7d9e1321c7 | ||
| 
						 | 
					83af7422a0 | ||
| 
						 | 
					ce8945f35c | ||
| 
						 | 
					dd890f0776 | ||
| 
						 | 
					af4ac437ab | ||
| 
						 | 
					607585fdaf | ||
| 
						 | 
					2f596aeef5 | ||
| 
						 | 
					69762c75fa | ||
| 
						 | 
					36b29660ce | ||
| 
						 | 
					4976983f30 | ||
| 
						 | 
					31e4ad25ba | ||
| 
						 | 
					225f4daf15 | ||
| 
						 | 
					b9927cfa2d | ||
| 
						 | 
					af6cafc603 | ||
| 
						 | 
					15da07d436 | ||
| 
						 | 
					886ed3544b | ||
| 
						 | 
					aff2922f9a | ||
| 
						 | 
					f32e0035a3 | ||
| 
						 | 
					7b1e7706d8 | ||
| 
						 | 
					cd74dda72a | ||
| 
						 | 
					032bb2a2c5 | ||
| 
						 | 
					fa96ed06d2 | ||
| 
						 | 
					43133041c9 | ||
| 
						 | 
					e0ee5ea962 | ||
| 
						 | 
					f5634286a3 | ||
| 
						 | 
					97d37c1c1e | ||
| 
						 | 
					739b139cb2 | ||
| 
						 | 
					0bc9920ad4 | ||
| 
						 | 
					3f516ce837 | ||
| 
						 | 
					9f197f9da5 | ||
| 
						 | 
					3dc2cc36e9 | ||
| 
						 | 
					ca3e683747 | ||
| 
						 | 
					38a1757168 | ||
| 
						 | 
					4104a57107 | ||
| 
						 | 
					b0c0f20071 | ||
| 
						 | 
					7870774162 | ||
| 
						 | 
					4213cdaf5d | ||
| 
						 | 
					39b4c974ee | ||
| 
						 | 
					508f56f17c | ||
| 
						 | 
					48665b7c99 | ||
| 
						 | 
					51971f7293 | ||
| 
						 | 
					3d3addb252 | ||
| 
						 | 
					3f8bdd1fdb | ||
| 
						 | 
					6181fd949f | ||
| 
						 | 
					afd61c63c2 | ||
| 
						 | 
					9a2073b4cd | ||
| 
						 | 
					f28468188b | ||
| 
						 | 
					8871d87512 | ||
| 
						 | 
					a2b81188be | ||
| 
						 | 
					f91f6cd5e4 | ||
| 
						 | 
					bd923a7bac | ||
| 
						 | 
					373c88faef | ||
| 
						 | 
					14813d8123 | ||
| 
						 | 
					92f2437f48 | ||
| 
						 | 
					da959761ff | ||
| 
						 | 
					d8cd25aa0d | ||
| 
						 | 
					d63d4f46fc | ||
| 
						 | 
					52161e090d | ||
| 
						 | 
					9e55e06501 | ||
| 
						 | 
					0b6df67fb1 | ||
| 
						 | 
					bf087e1ea1 | ||
| 
						 | 
					885818fb7c | ||
| 
						 | 
					2f370048cb | ||
| 
						 | 
					28dc02a9d8 | ||
| 
						 | 
					54ebaca535 | ||
| 
						 | 
					4fedc91a4a | ||
| 
						 | 
					f734aaa413 | ||
| 
						 | 
					a575d4b9ee | ||
| 
						 | 
					77a87ded3a | ||
| 
						 | 
					b958d2c298 | ||
| 
						 | 
					dc72a195c2 | ||
| 
						 | 
					e2812ff61f | ||
| 
						 | 
					8c2e34e27f | ||
| 
						 | 
					31f3950fbf | ||
| 
						 | 
					75b3654d18 | ||
| 
						 | 
					418f9ac5e3 | ||
| 
						 | 
					ad4afe4edf | ||
| 
						 | 
					c844b971cb | ||
| 
						 | 
					ca9b1c47af | ||
| 
						 | 
					86039d2751 | ||
| 
						 | 
					420a692f04 | ||
| 
						 | 
					1d2a464fe0 | ||
| 
						 | 
					7735dd0750 | ||
| 
						 | 
					bf7b075f0c | 
							
								
								
									
										20
									
								
								.cvsignore
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										20
									
								
								.cvsignore
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,20 @@
 | 
			
		||||
openssl.pc
 | 
			
		||||
MINFO
 | 
			
		||||
makefile.one
 | 
			
		||||
tmp
 | 
			
		||||
out
 | 
			
		||||
outinc
 | 
			
		||||
rehash.time
 | 
			
		||||
testlog
 | 
			
		||||
make.log
 | 
			
		||||
maketest.log
 | 
			
		||||
cctest
 | 
			
		||||
cctest.c
 | 
			
		||||
cctest.a
 | 
			
		||||
*.flc
 | 
			
		||||
semantic.cache
 | 
			
		||||
Makefile
 | 
			
		||||
*.so*
 | 
			
		||||
*.dll*
 | 
			
		||||
*.sl*
 | 
			
		||||
*.dylib*
 | 
			
		||||
							
								
								
									
										11
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							
							
						
						
									
										11
									
								
								.gitignore
									
									
									
									
										vendored
									
									
								
							@@ -11,15 +11,10 @@
 | 
			
		||||
# Top level excludes
 | 
			
		||||
/Makefile.bak
 | 
			
		||||
/Makefile
 | 
			
		||||
/MINFO
 | 
			
		||||
/*.a
 | 
			
		||||
/include
 | 
			
		||||
/*.pc
 | 
			
		||||
/rehash.time
 | 
			
		||||
/inc.*
 | 
			
		||||
/makefile.*
 | 
			
		||||
/out.*
 | 
			
		||||
/tmp.*
 | 
			
		||||
 | 
			
		||||
# Most *.c files under test/ are symlinks
 | 
			
		||||
/test/*.c
 | 
			
		||||
@@ -30,7 +25,6 @@
 | 
			
		||||
!/test/igetest.c
 | 
			
		||||
!/test/r160test.c
 | 
			
		||||
!/test/fips_algvs.c
 | 
			
		||||
!/test/testutil.c
 | 
			
		||||
 | 
			
		||||
/test/*.ss
 | 
			
		||||
/test/*.srl
 | 
			
		||||
@@ -74,7 +68,6 @@ crypto/sha/asm/sha512-sse2.asm
 | 
			
		||||
/apps/openssl
 | 
			
		||||
/test/sha256t
 | 
			
		||||
/test/sha512t
 | 
			
		||||
/test/gost2814789t
 | 
			
		||||
/test/*test
 | 
			
		||||
/test/fips_aesavs
 | 
			
		||||
/test/fips_desmovs
 | 
			
		||||
@@ -98,10 +91,6 @@ crypto/sha/asm/sha512-sse2.asm
 | 
			
		||||
lib
 | 
			
		||||
Makefile.save
 | 
			
		||||
*.bak
 | 
			
		||||
tags
 | 
			
		||||
TAGS
 | 
			
		||||
cscope.out
 | 
			
		||||
*.d
 | 
			
		||||
 | 
			
		||||
# Windows
 | 
			
		||||
/tmp32dll
 | 
			
		||||
 
 | 
			
		||||
@@ -29,7 +29,7 @@ eric (about to go bushwalking for the 4 day easter break :-)
 | 
			
		||||
7-Jan-98
 | 
			
		||||
    - Finally reworked the cipher string to ciphers again, so it
 | 
			
		||||
      works correctly
 | 
			
		||||
    - All the app_data stuff is now ex_data with function calls to access.
 | 
			
		||||
    - All the app_data stuff is now ex_data with funcion calls to access.
 | 
			
		||||
      The index is supplied by a function and 'methods' can be setup
 | 
			
		||||
      for the types that are called on XXX_new/XXX_free.  This lets
 | 
			
		||||
      applications get notified on creation and destruction.  Some of
 | 
			
		||||
@@ -148,7 +148,7 @@ eric (about to go bushwalking for the 4 day easter break :-)
 | 
			
		||||
      This would tend to cause memory overwrites since SSLv3 has
 | 
			
		||||
      a maximum packet size of 16k.  If your program uses
 | 
			
		||||
      buffers <= 16k, you would probably never see this problem.
 | 
			
		||||
    - Fixed a few errors that were cause by malloc() not returning
 | 
			
		||||
    - Fixed a new errors that were cause by malloc() not returning
 | 
			
		||||
      0 initialised memory..
 | 
			
		||||
    - SSL_OP_NETSCAPE_CA_DN_BUG was being switched on when using
 | 
			
		||||
      SSL_CTX_set_options(ssl_ctx,SSL_OP_ALL); which was a bad thing
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										101
									
								
								FAQ
									
									
									
									
									
								
							
							
						
						
									
										101
									
								
								FAQ
									
									
									
									
									
								
							@@ -35,7 +35,6 @@ OpenSSL  -  Frequently Asked Questions
 | 
			
		||||
* What is a "128 bit certificate"? Can I create one with OpenSSL?
 | 
			
		||||
* Why does OpenSSL set the authority key identifier extension incorrectly?
 | 
			
		||||
* How can I set up a bundle of commercial root CA certificates?
 | 
			
		||||
* Some secure servers 'hang' with OpenSSL 1.0.1, is this a bug?
 | 
			
		||||
 | 
			
		||||
[BUILD] Questions about building and testing OpenSSL
 | 
			
		||||
 | 
			
		||||
@@ -76,7 +75,6 @@ OpenSSL  -  Frequently Asked Questions
 | 
			
		||||
* Why does Valgrind complain about the use of uninitialized data?
 | 
			
		||||
* Why doesn't a memory BIO work when a file does?
 | 
			
		||||
* Where are the declarations and implementations of d2i_X509() etc?
 | 
			
		||||
* When debugging I observe SIGILL during OpenSSL initialization: why?
 | 
			
		||||
 | 
			
		||||
===============================================================================
 | 
			
		||||
 | 
			
		||||
@@ -85,6 +83,7 @@ OpenSSL  -  Frequently Asked Questions
 | 
			
		||||
* Which is the current version of OpenSSL?
 | 
			
		||||
 | 
			
		||||
The current version is available from <URL: http://www.openssl.org>.
 | 
			
		||||
OpenSSL 1.0.1d was released on Feb 5th, 2013.
 | 
			
		||||
 | 
			
		||||
In addition to the current stable release, you can also access daily
 | 
			
		||||
snapshots of the OpenSSL development version at <URL:
 | 
			
		||||
@@ -133,7 +132,7 @@ OpenSSL.  Information on the OpenSSL mailing lists is available from
 | 
			
		||||
* Where can I get a compiled version of OpenSSL?
 | 
			
		||||
 | 
			
		||||
You can finder pointers to binary distributions in
 | 
			
		||||
<URL: http://www.openssl.org/about/binaries.html> .
 | 
			
		||||
<URL: http://www.openssl.org/related/binaries.html> .
 | 
			
		||||
 | 
			
		||||
Some applications that use OpenSSL are distributed in binary form.
 | 
			
		||||
When using such an application, you don't need to install OpenSSL
 | 
			
		||||
@@ -185,18 +184,14 @@ Therefore the answer to the common question "when will feature X be
 | 
			
		||||
backported to OpenSSL 1.0.0/0.9.8?" is "never" but it could appear
 | 
			
		||||
in the next minor release.
 | 
			
		||||
 | 
			
		||||
* What happens when the letter release reaches z?
 | 
			
		||||
 | 
			
		||||
It was decided after the release of OpenSSL 0.9.8y the next version should
 | 
			
		||||
be 0.9.8za then 0.9.8zb and so on.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
[LEGAL] =======================================================================
 | 
			
		||||
 | 
			
		||||
* Do I need patent licenses to use OpenSSL?
 | 
			
		||||
 | 
			
		||||
For information on intellectual property rights, please consult a lawyer.
 | 
			
		||||
The OpenSSL team does not offer legal advice.
 | 
			
		||||
The patents section of the README file lists patents that may apply to
 | 
			
		||||
you if you want to use OpenSSL.  For information on intellectual
 | 
			
		||||
property rights, please consult a lawyer.  The OpenSSL team does not
 | 
			
		||||
offer legal advice.
 | 
			
		||||
 | 
			
		||||
You can configure OpenSSL so as not to use IDEA, MDC2 and RC5 by using
 | 
			
		||||
 ./config no-idea no-mdc2 no-rc5
 | 
			
		||||
@@ -434,7 +429,7 @@ software from the US only weak encryption algorithms could be freely exported
 | 
			
		||||
inadequate. A relaxation of the rules allowed the use of strong encryption but
 | 
			
		||||
only to an authorised server.
 | 
			
		||||
 | 
			
		||||
Two slightly different techniques were developed to support this, one used by
 | 
			
		||||
Two slighly different techniques were developed to support this, one used by
 | 
			
		||||
Netscape was called "step up", the other used by MSIE was called "Server Gated
 | 
			
		||||
Cryptography" (SGC). When a browser initially connected to a server it would
 | 
			
		||||
check to see if the certificate contained certain extensions and was issued by
 | 
			
		||||
@@ -485,16 +480,6 @@ bundle used by Mozilla and/or modssl as described in this article:
 | 
			
		||||
  <URL: http://www.mail-archive.com/modssl-users@modssl.org/msg16980.html>
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
* Some secure servers 'hang' with OpenSSL 1.0.1, is this a bug?
 | 
			
		||||
 | 
			
		||||
OpenSSL 1.0.1 is the first release to support TLS 1.2, among other things,
 | 
			
		||||
this increases the size of the default ClientHello message to more than
 | 
			
		||||
255 bytes in length. Some software cannot handle this and hangs. For more
 | 
			
		||||
details and workarounds see:
 | 
			
		||||
 | 
			
		||||
  <URL: http://rt.openssl.org/Ticket/Display.html?user=guest&pass=guest&id=2771>
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
[BUILD] =======================================================================
 | 
			
		||||
 | 
			
		||||
* Why does the linker complain about undefined symbols?
 | 
			
		||||
@@ -623,8 +608,8 @@ valid for the current DOS session.
 | 
			
		||||
* What is special about OpenSSL on Redhat?
 | 
			
		||||
 | 
			
		||||
Red Hat Linux (release 7.0 and later) include a preinstalled limited
 | 
			
		||||
version of OpenSSL. Red Hat has chosen to disable support for IDEA, RC5 and
 | 
			
		||||
MDC2 in this version. The same may apply to other Linux distributions.
 | 
			
		||||
version of OpenSSL. For patent reasons, support for IDEA, RC5 and MDC2
 | 
			
		||||
is disabled in this version. The same may apply to other Linux distributions.
 | 
			
		||||
Users may therefore wish to install more or all of the features left out.
 | 
			
		||||
 | 
			
		||||
To do this you MUST ensure that you do not overwrite the openssl that is in
 | 
			
		||||
@@ -647,6 +632,11 @@ relevant updates in packages up to and including 0.9.6b.
 | 
			
		||||
A possible way around this is to persuade Red Hat to produce a non-US
 | 
			
		||||
version of Red Hat Linux.
 | 
			
		||||
 | 
			
		||||
FYI: Patent numbers and expiry dates of US patents:
 | 
			
		||||
MDC-2: 4,908,861 13/03/2007
 | 
			
		||||
IDEA:  5,214,703 25/05/2010
 | 
			
		||||
RC5:   5,724,428 03/03/2015
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
* Why does the OpenSSL compilation fail on MacOS X?
 | 
			
		||||
 | 
			
		||||
@@ -709,7 +699,7 @@ working across wider range of *BSD branches, not just OpenBSD.
 | 
			
		||||
If the test program in question fails withs SIGILL, Illegal Instruction
 | 
			
		||||
exception, then you more than likely to run SSE2-capable CPU, such as
 | 
			
		||||
Intel P4, under control of kernel which does not support SSE2
 | 
			
		||||
instruction extensions. See accompanying INSTALL file and
 | 
			
		||||
instruction extentions. See accompanying INSTALL file and
 | 
			
		||||
OPENSSL_ia32cap(3) documentation page for further information.
 | 
			
		||||
 | 
			
		||||
* Why does compiler fail to compile sha512.c?
 | 
			
		||||
@@ -723,15 +713,15 @@ possible alternative might be to switch to GCC.
 | 
			
		||||
 | 
			
		||||
* Test suite still fails, what to do?
 | 
			
		||||
 | 
			
		||||
Another common reason for test failures is bugs in the toolchain
 | 
			
		||||
or run-time environment.  Known cases of this are documented in the
 | 
			
		||||
PROBLEMS file, please review it before you beat the drum. Even if you
 | 
			
		||||
don't find anything in that file, please do consider the possibility
 | 
			
		||||
of a compiler bug. Compiler bugs often appear in rather bizarre ways,
 | 
			
		||||
they never make sense, and tend to emerge when you least expect
 | 
			
		||||
them. One thing to try is to reduce the level of optimization (such
 | 
			
		||||
as by editing the CFLAG variable line in the top-level Makefile),
 | 
			
		||||
and then recompile and re-run the test.
 | 
			
		||||
Another common reason for failure to complete some particular test is
 | 
			
		||||
simply bad code generated by a buggy component in toolchain or deficiency
 | 
			
		||||
in run-time environment. There are few cases documented in PROBLEMS file,
 | 
			
		||||
consult it for possible workaround before you beat the drum. Even if you
 | 
			
		||||
don't find solution or even mention there, do reserve for possibility of
 | 
			
		||||
a compiler bug. Compiler bugs might appear in rather bizarre ways, they
 | 
			
		||||
never make sense, and tend to emerge when you least expect them. In order
 | 
			
		||||
to identify one, drop optimization level, e.g. by editing CFLAG line in
 | 
			
		||||
top-level Makefile, recompile and re-run the test.
 | 
			
		||||
 | 
			
		||||
* I think I've found a bug, what should I do?
 | 
			
		||||
 | 
			
		||||
@@ -741,16 +731,9 @@ documentation and the mailing lists for similar queries. If you are still
 | 
			
		||||
unsure whether it is a bug or not submit a query to the openssl-users mailing
 | 
			
		||||
list.
 | 
			
		||||
 | 
			
		||||
If you think you have found a bug based on the output of static analysis tools
 | 
			
		||||
then please manually check the issue is genuine. Such tools can produce a
 | 
			
		||||
LOT of false positives.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
* I'm SURE I've found a bug, how do I report it?
 | 
			
		||||
 | 
			
		||||
To avoid duplicated reports check the mailing lists and release notes for the
 | 
			
		||||
relevant version of OpenSSL to see if the problem has been reported already.
 | 
			
		||||
 | 
			
		||||
Bug reports with no security implications should be sent to the request
 | 
			
		||||
tracker. This can be done by mailing the report to <rt@openssl.org> (or its
 | 
			
		||||
alias <openssl-bugs@openssl.org>), please note that messages sent to the
 | 
			
		||||
@@ -778,9 +761,7 @@ See also <URL: http://www.openssl.org/support/rt.html>
 | 
			
		||||
If you think your bug has security implications then please send it to
 | 
			
		||||
openssl-security@openssl.org if you don't get a prompt reply at least 
 | 
			
		||||
acknowledging receipt then resend or mail it directly to one of the
 | 
			
		||||
more active team members (e.g. Steve). If you wish to use PGP to send
 | 
			
		||||
in a report please use one or more of the keys of the team members listed
 | 
			
		||||
at <URL: http://www.openssl.org/about/>
 | 
			
		||||
more active team members (e.g. Steve).
 | 
			
		||||
 | 
			
		||||
Note that bugs only present in the openssl utility are not in general
 | 
			
		||||
considered to be security issues. 
 | 
			
		||||
@@ -881,7 +862,7 @@ The opposite assumes we already have len bytes in buf:
 | 
			
		||||
 p = buf;
 | 
			
		||||
 p7 = d2i_PKCS7(NULL, &p, len);
 | 
			
		||||
 | 
			
		||||
At this point p7 contains a valid PKCS7 structure or NULL if an error
 | 
			
		||||
At this point p7 contains a valid PKCS7 structure of NULL if an error
 | 
			
		||||
occurred. If an error occurred ERR_print_errors(bio) should give more
 | 
			
		||||
information.
 | 
			
		||||
 | 
			
		||||
@@ -893,21 +874,6 @@ that has been read or written. This may well be uninitialized data
 | 
			
		||||
and attempts to free the buffer will have unpredictable results
 | 
			
		||||
because it no longer points to the same address.
 | 
			
		||||
 | 
			
		||||
Memory allocation and encoding can also be combined in a single
 | 
			
		||||
operation by the ASN1 routines:
 | 
			
		||||
 | 
			
		||||
 unsigned char *buf = NULL;	/* mandatory */
 | 
			
		||||
 int len;
 | 
			
		||||
 len = i2d_PKCS7(p7, &buf);
 | 
			
		||||
 if (len < 0)
 | 
			
		||||
	/* Error */
 | 
			
		||||
 /* Do some things with 'buf' */
 | 
			
		||||
 /* Finished with buf: free it */
 | 
			
		||||
 OPENSSL_free(buf);
 | 
			
		||||
 | 
			
		||||
In this special case the "buf" parameter is *not* incremented, it points
 | 
			
		||||
to the start of the encoding.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
* OpenSSL uses DER but I need BER format: does OpenSSL support BER?
 | 
			
		||||
 | 
			
		||||
@@ -1069,20 +1035,5 @@ These are defined and implemented by macros of the form:
 | 
			
		||||
The implementation passes an ASN1 "template" defining the structure into an
 | 
			
		||||
ASN1 interpreter using generalised functions such as ASN1_item_d2i().
 | 
			
		||||
 | 
			
		||||
* When debugging I observe SIGILL during OpenSSL initialization: why?
 | 
			
		||||
 | 
			
		||||
OpenSSL adapts to processor it executes on and for this reason has to
 | 
			
		||||
query its capabilities. Unfortunately on some processors the only way
 | 
			
		||||
to achieve this for non-privileged code is to attempt instructions
 | 
			
		||||
that can cause Illegal Instruction exceptions. The initialization
 | 
			
		||||
procedure is coded to handle these exceptions to manipulate corresponding
 | 
			
		||||
bits in capabilities vector. This normally appears transparent, except
 | 
			
		||||
when you execute it under debugger, which stops prior delivering signal
 | 
			
		||||
to handler. Simply resuming execution does the trick, but when debugging
 | 
			
		||||
a lot it might feel counterproductive. Two options. Either set explicit
 | 
			
		||||
capability environment variable in order to bypass the capability query
 | 
			
		||||
(see corresponding crypto/*cap.c for details). Or configure debugger not
 | 
			
		||||
to stop upon SIGILL exception, e.g. in gdb case add 'handle SIGILL nostop'
 | 
			
		||||
to your .gdbinit.
 | 
			
		||||
 | 
			
		||||
===============================================================================
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										10
									
								
								GitConfigure
									
									
									
									
									
								
							
							
						
						
									
										10
									
								
								GitConfigure
									
									
									
									
									
								
							@@ -1,10 +0,0 @@
 | 
			
		||||
#!/bin/sh
 | 
			
		||||
 | 
			
		||||
BRANCH=`git rev-parse --abbrev-ref HEAD`
 | 
			
		||||
 | 
			
		||||
./Configure $@ no-symlinks
 | 
			
		||||
make files
 | 
			
		||||
util/mk1mf.pl OUT=out.$BRANCH TMP=tmp.$BRANCH INC=inc.$BRANCH copy > makefile.$BRANCH
 | 
			
		||||
MAKE=make
 | 
			
		||||
which bsdmake > /dev/null && MAKE=bsdmake
 | 
			
		||||
$MAKE -f makefile.$BRANCH init
 | 
			
		||||
							
								
								
									
										7
									
								
								GitMake
									
									
									
									
									
								
							
							
						
						
									
										7
									
								
								GitMake
									
									
									
									
									
								
							@@ -1,7 +0,0 @@
 | 
			
		||||
#!/bin/sh
 | 
			
		||||
 | 
			
		||||
BRANCH=`git rev-parse --abbrev-ref HEAD`
 | 
			
		||||
 | 
			
		||||
MAKE=make
 | 
			
		||||
which bsdmake > /dev/null && MAKE=bsdmake
 | 
			
		||||
$MAKE -f makefile.$BRANCH $@
 | 
			
		||||
							
								
								
									
										8
									
								
								INSTALL
									
									
									
									
									
								
							
							
						
						
									
										8
									
								
								INSTALL
									
									
									
									
									
								
							@@ -79,7 +79,7 @@
 | 
			
		||||
                compiler flags for any other CPU specific configuration,
 | 
			
		||||
                e.g. "-m32" to build x86 code on an x64 system.
 | 
			
		||||
 | 
			
		||||
  no-sse2	Exclude SSE2 code pathes. Normally SSE2 extension is
 | 
			
		||||
  no-sse2	Exclude SSE2 code pathes. Normally SSE2 extention is
 | 
			
		||||
		detected at run-time, but the decision whether or not the
 | 
			
		||||
		machine code will be executed is taken solely on CPU
 | 
			
		||||
		capability vector. This means that if you happen to run OS
 | 
			
		||||
@@ -98,7 +98,7 @@
 | 
			
		||||
                The crypto/<cipher> directory can be removed after running
 | 
			
		||||
                "make depend".
 | 
			
		||||
 | 
			
		||||
  -Dxxx, -lxxx, -Lxxx, -fxxx, -mXXX, -Kxxx These system specific options will
 | 
			
		||||
  -Dxxx, -lxxx, -Lxxx, -fxxx, -mxxx, -Kxxx These system specific options will
 | 
			
		||||
                be passed through to the compiler to allow you to
 | 
			
		||||
                define preprocessor symbols, specify additional libraries,
 | 
			
		||||
                library directories or other compiler options.
 | 
			
		||||
@@ -206,10 +206,6 @@
 | 
			
		||||
                       compile programs with libcrypto or libssl.
 | 
			
		||||
       lib             Contains the OpenSSL library files themselves.
 | 
			
		||||
 | 
			
		||||
     Use "make install_sw" to install the software without documentation,
 | 
			
		||||
     and "install_docs_html" to install HTML renditions of the manual
 | 
			
		||||
     pages.
 | 
			
		||||
 | 
			
		||||
     Package builders who want to configure the library for standard
 | 
			
		||||
     locations, but have the package installed somewhere else so that
 | 
			
		||||
     it can easily be packaged, can use
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										72
									
								
								INSTALL.MacOS
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										72
									
								
								INSTALL.MacOS
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,72 @@
 | 
			
		||||
OpenSSL - Port To The Macintosh OS 9 or Earlier
 | 
			
		||||
===============================================
 | 
			
		||||
 | 
			
		||||
Thanks to Roy Wood <roy@centricsystems.ca> initial support for Mac OS (pre
 | 
			
		||||
X) is now provided. "Initial" means that unlike other platforms where you
 | 
			
		||||
get an SDK and a "swiss army" openssl application, on Macintosh you only
 | 
			
		||||
get one sample application which fetches a page over HTTPS(*) and dumps it
 | 
			
		||||
in a window. We don't even build the test applications so that we can't
 | 
			
		||||
guarantee that all algorithms are operational.
 | 
			
		||||
 | 
			
		||||
Required software:
 | 
			
		||||
 | 
			
		||||
- StuffIt Expander 5.5 or later, alternatively MacGzip and SUNtar;
 | 
			
		||||
- Scriptable Finder;
 | 
			
		||||
- CodeWarrior Pro 5;
 | 
			
		||||
 | 
			
		||||
Installation procedure:
 | 
			
		||||
 | 
			
		||||
- fetch the source at ftp://ftp.openssl.org/ (well, you probably already
 | 
			
		||||
  did, huh?)
 | 
			
		||||
- unpack the .tar.gz file:
 | 
			
		||||
	- if you have StuffIt Expander then just drag it over it;
 | 
			
		||||
	- otherwise uncompress it with MacGzip and then unpack with SUNtar;
 | 
			
		||||
- locate MacOS folder in OpenSSL source tree and open it;
 | 
			
		||||
- unbinhex mklinks.as.hqx and OpenSSL.mcp.hqx if present (**), do it
 | 
			
		||||
  "in-place", i.e. unpacked files should end-up in the very same folder;
 | 
			
		||||
- execute mklinks.as;
 | 
			
		||||
- open OpenSSL.mcp(***) and build 'GetHTTPS PPC' target(****);
 | 
			
		||||
- that's it for now;
 | 
			
		||||
 | 
			
		||||
(*)	URL is hardcoded into ./MacOS/GetHTTPS.src/GetHTTPS.cpp, lines 40
 | 
			
		||||
        to 42, change appropriately.
 | 
			
		||||
(**)	If you use SUNtar, then it might have already unbinhexed the files
 | 
			
		||||
	in question.
 | 
			
		||||
(***)	The project file was saved with CW Pro 5.3. If you have an earlier
 | 
			
		||||
	version and it refuses to open it, then download
 | 
			
		||||
	http://www.openssl.org/~appro/OpenSSL.mcp.xml and import it
 | 
			
		||||
	overwriting the original OpenSSL.mcp.
 | 
			
		||||
(****)	Other targets are works in progress. If you feel like giving 'em a
 | 
			
		||||
	shot, then you should know that OpenSSL* and Lib* targets are
 | 
			
		||||
	supposed to be built with the GUSI, MacOS library which mimics
 | 
			
		||||
	BSD sockets and some other POSIX APIs. The GUSI distribution is
 | 
			
		||||
	expected to be found in the same directory as the openssl source tree,
 | 
			
		||||
	i.e., in the parent directory to the one where this very file,
 | 
			
		||||
	namely INSTALL.MacOS, resides. For more information about GUSI, see
 | 
			
		||||
	http://www.iis.ee.ethz.ch/~neeri/macintosh/gusi-qa.html
 | 
			
		||||
 | 
			
		||||
Finally some essential comments from our generous contributor:-)
 | 
			
		||||
 | 
			
		||||
"I've gotten OpenSSL working on the Macintosh. It's probably a bit of a
 | 
			
		||||
hack, but it works for what I'm doing. If you don't like the way I've done
 | 
			
		||||
it, then feel free to change what I've done. I freely admit that I've done
 | 
			
		||||
some less-than-ideal things in my port, and if you don't like the way I've
 | 
			
		||||
done something, then feel free to change it-- I won't be offended!
 | 
			
		||||
 | 
			
		||||
... I've tweaked "bss_sock.c" a little to call routines in a "MacSocket"
 | 
			
		||||
library I wrote. My MacSocket library is a wrapper around OpenTransport,
 | 
			
		||||
handling stuff like endpoint creation, reading, writing, etc. It is not
 | 
			
		||||
designed as a high-performance package such as you'd use in a webserver,
 | 
			
		||||
but is fine for lots of other applications. MacSocket also uses some other
 | 
			
		||||
code libraries I've written to deal with string manipulations and error
 | 
			
		||||
handling. Feel free to use these things in your own code, but give me
 | 
			
		||||
credit and/or send me free stuff in appreciation! :-)
 | 
			
		||||
 | 
			
		||||
...
 | 
			
		||||
 | 
			
		||||
If you have any questions, feel free to email me as the following:
 | 
			
		||||
 | 
			
		||||
roy@centricsystems.ca
 | 
			
		||||
 | 
			
		||||
-Roy Wood"
 | 
			
		||||
 | 
			
		||||
@@ -378,7 +378,7 @@ The openssl program has numerous options and can be used for many different
 | 
			
		||||
things.  Many of the options operate in an interactive mode requiring the
 | 
			
		||||
user to enter data.  Because of this, a default screen is created for the
 | 
			
		||||
program.  However, when running the test script it is not desirable to
 | 
			
		||||
have a separate screen.  Therefore, the build also creates openssl2.nlm.
 | 
			
		||||
have a seperate screen.  Therefore, the build also creates openssl2.nlm.
 | 
			
		||||
Openssl2.nlm is functionally identical but uses the console screen.
 | 
			
		||||
Openssl2 can be used when a non-interactive mode is desired.
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										54
									
								
								INSTALL.VMS
									
									
									
									
									
								
							
							
						
						
									
										54
									
								
								INSTALL.VMS
									
									
									
									
									
								
							@@ -71,7 +71,7 @@ the top to understand how to use them.  However, if you want to
 | 
			
		||||
compile all you can get, the simplest is to use MAKEVMS.COM in the top
 | 
			
		||||
directory.  The syntax is the following:
 | 
			
		||||
 | 
			
		||||
  @MAKEVMS <option> <bits> <debug-p> [<compiler>]
 | 
			
		||||
  @MAKEVMS <option> <rsaref-p> <debug-p> [<compiler>]
 | 
			
		||||
 | 
			
		||||
<option> must be one of the following:
 | 
			
		||||
 | 
			
		||||
@@ -87,11 +87,24 @@ directory.  The syntax is the following:
 | 
			
		||||
      TEST      Just build the "[.xxx.EXE.TEST]" test programs for OpenSSL.
 | 
			
		||||
      APPS      Just build the "[.xxx.EXE.APPS]" application programs for OpenSSL.
 | 
			
		||||
 | 
			
		||||
<bits> must be one of the following:
 | 
			
		||||
<rsaref-p> must be one of the following:
 | 
			
		||||
 | 
			
		||||
      ""        compile using default pointer size
 | 
			
		||||
      32        compile using 32 bit pointer size
 | 
			
		||||
      64        compile using 64 bit pointer size
 | 
			
		||||
      RSAREF    compile using the RSAREF Library
 | 
			
		||||
      NORSAREF  compile without using RSAREF
 | 
			
		||||
 | 
			
		||||
Note 0: The RSAREF library IS NO LONGER NEEDED.  The RSA patent
 | 
			
		||||
        expires September 20, 2000, and RSA Security chose to make
 | 
			
		||||
        the algorithm public domain two weeks before that.
 | 
			
		||||
 | 
			
		||||
Note 1: If you still want to use RSAREF, the library is NOT INCLUDED
 | 
			
		||||
        and you have to download it.  RSA Security doesn't carry it
 | 
			
		||||
        any more, but there are a number of places where you can find
 | 
			
		||||
        it.  You have to get the ".tar-Z" file as the ".zip" file
 | 
			
		||||
        doesn't have the directory structure stored.  You have to
 | 
			
		||||
        extract the file into the [.RSAREF] directory as that is where
 | 
			
		||||
        the scripts will look for the files.
 | 
			
		||||
 | 
			
		||||
Note 2: I have never done this, so I've no idea if it works or not.
 | 
			
		||||
 | 
			
		||||
<debug-p> must be one of the following:
 | 
			
		||||
 | 
			
		||||
@@ -104,13 +117,12 @@ directory.  The syntax is the following:
 | 
			
		||||
      GNUC      For GNU C.
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
You will find the crypto library in [.xxx.EXE.CRYPTO] (where xxx is VAX,
 | 
			
		||||
ALPHA or IA64), called SSL_LIBCRYPTO32.OLB or SSL_LIBCRYPTO.OLB depending
 | 
			
		||||
on how it was built.  You will find the SSL library in [.xxx.EXE.SSL],
 | 
			
		||||
named SSL_LIBSSL32.OLB or SSL_LIBSSL.OLB, and you will find a bunch of
 | 
			
		||||
useful programs in [.xxx.EXE.APPS].  However, these shouldn't be used
 | 
			
		||||
right off unless it's just to test them.  For production use, make sure
 | 
			
		||||
you install first, see Installation below.
 | 
			
		||||
You will find the crypto library in [.xxx.EXE.CRYPTO], called LIBCRYPTO.OLB,
 | 
			
		||||
where xxx is VAX or AXP.  You will find the SSL library in [.xxx.EXE.SSL],
 | 
			
		||||
named LIBSSL.OLB, and you will find a bunch of useful programs in
 | 
			
		||||
[.xxx.EXE.APPS].  However, these shouldn't be used right off unless it's
 | 
			
		||||
just to test them.  For production use, make sure you install first, see
 | 
			
		||||
Installation below.
 | 
			
		||||
 | 
			
		||||
Note 1: Some programs in this package require a TCP/IP library.
 | 
			
		||||
 | 
			
		||||
@@ -134,7 +146,7 @@ Currently, the logical names supported are:
 | 
			
		||||
                        will not be implemented.  Supported algorithms to
 | 
			
		||||
                        do this with are: RSA, DSA, DH, MD2, MD4, MD5, RIPEMD,
 | 
			
		||||
                        SHA, DES, MDC2, CR2, RC4, RC5, IDEA, BF, CAST, HMAC,
 | 
			
		||||
                        SSL3.  So, for example, having the logical name
 | 
			
		||||
                        SSL2.  So, for example, having the logical name
 | 
			
		||||
                        OPENSSL_NO_RSA with the value YES means that the
 | 
			
		||||
                        LIBCRYPTO.OLB library will not contain an RSA
 | 
			
		||||
                        implementation.
 | 
			
		||||
@@ -158,14 +170,12 @@ Installation:
 | 
			
		||||
 | 
			
		||||
Installation is easy, just do the following:
 | 
			
		||||
 | 
			
		||||
  @INSTALL <root> <bits>
 | 
			
		||||
  @INSTALL <root>
 | 
			
		||||
 | 
			
		||||
<root> is the directory in which everything will be installed,
 | 
			
		||||
subdirectories, libraries, header files, programs and startup command
 | 
			
		||||
procedures.
 | 
			
		||||
 | 
			
		||||
<bits> works the same way as for MAKEVMS.COM
 | 
			
		||||
 | 
			
		||||
N.B.: INSTALL.COM builds a new directory structure, different from
 | 
			
		||||
the directory tree where you have now build OpenSSL.
 | 
			
		||||
 | 
			
		||||
@@ -186,10 +196,6 @@ following command procedures:
 | 
			
		||||
        sets up the symbols to the applications.  Should be called
 | 
			
		||||
        from for example SYS$MANAGER:SYLOGIN.COM 
 | 
			
		||||
 | 
			
		||||
  OPENSSL_UNDO.COM
 | 
			
		||||
 | 
			
		||||
	deassigns the logical names created with OPENSSL_STARTUP.COM.
 | 
			
		||||
 | 
			
		||||
The logical names that are set up are the following:
 | 
			
		||||
 | 
			
		||||
  SSLROOT       a dotted concealed logical name pointing at the
 | 
			
		||||
@@ -197,6 +203,7 @@ The logical names that are set up are the following:
 | 
			
		||||
 | 
			
		||||
  SSLCERTS      Initially an empty directory, this is the default
 | 
			
		||||
		location for certificate files.
 | 
			
		||||
  SSLMISC	Various scripts.
 | 
			
		||||
  SSLPRIVATE	Initially an empty directory, this is the default
 | 
			
		||||
		location for private key files.
 | 
			
		||||
 | 
			
		||||
@@ -204,9 +211,8 @@ The logical names that are set up are the following:
 | 
			
		||||
		programs.
 | 
			
		||||
  SSLINCLUDE    Contains the header files needed if you want to
 | 
			
		||||
		compile programs with libcrypto or libssl.
 | 
			
		||||
  SSLLIB        Contains the OpenSSL library files themselves:
 | 
			
		||||
  		- SSL_LIBCRYPTO32.OLB and SSL_LIBSSL32.OLB or
 | 
			
		||||
		- SSL_LIBCRYPTO.OLB and SSL_LIBSSL.OLB
 | 
			
		||||
  SSLLIB        Contains the OpenSSL library files (LIBCRYPTO.OLB
 | 
			
		||||
		and LIBSSL.OLB) themselves.
 | 
			
		||||
 | 
			
		||||
  OPENSSL	Same as SSLINCLUDE.  This is because the standard
 | 
			
		||||
		way to include OpenSSL header files from version
 | 
			
		||||
@@ -290,4 +296,4 @@ have any ideas.
 | 
			
		||||
 | 
			
		||||
--
 | 
			
		||||
Richard Levitte <richard@levitte.org>
 | 
			
		||||
2000-02-27, 2011-03-18
 | 
			
		||||
2000-02-27
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										172
									
								
								INSTALL.W32
									
									
									
									
									
								
							
							
						
						
									
										172
									
								
								INSTALL.W32
									
									
									
									
									
								
							@@ -5,30 +5,19 @@
 | 
			
		||||
 [Instructions for building for Windows CE can be found in INSTALL.WCE]
 | 
			
		||||
 [Instructions for building for Win64 can be found in INSTALL.W64]
 | 
			
		||||
 | 
			
		||||
 Here are a few comments about building OpenSSL for Win32 environments,
 | 
			
		||||
 such as Windows NT and Windows 9x. It should be noted though that
 | 
			
		||||
 Windows 9x are not ordinarily tested. Its mention merely means that we
 | 
			
		||||
 attempt to maintain certain programming discipline and pay attention
 | 
			
		||||
 to backward compatibility issues, in other words it's kind of expected
 | 
			
		||||
 to work on Windows 9x, but no regression tests are actually performed.
 | 
			
		||||
 Heres a few comments about building OpenSSL in Windows environments.  Most
 | 
			
		||||
 of this is tested on Win32 but it may also work in Win 3.1 with some
 | 
			
		||||
 modification.
 | 
			
		||||
 | 
			
		||||
 On additional note newer OpenSSL versions are compiled and linked with
 | 
			
		||||
 Winsock 2. This means that minimum OS requirement was elevated to NT 4
 | 
			
		||||
 and Windows 98 [there is Winsock 2 update for Windows 95 though].
 | 
			
		||||
 | 
			
		||||
 - you need Perl for Win32.  Unless you will build on Cygwin, you will need
 | 
			
		||||
 You need Perl for Win32.  Unless you will build on Cygwin, you will need
 | 
			
		||||
 ActiveState Perl, available from http://www.activestate.com/ActivePerl.
 | 
			
		||||
 | 
			
		||||
 - one of the following C compilers:
 | 
			
		||||
 and one of the following C compilers:
 | 
			
		||||
 | 
			
		||||
  * Visual C++
 | 
			
		||||
  * Borland C
 | 
			
		||||
  * GNU C (Cygwin or MinGW)
 | 
			
		||||
 | 
			
		||||
- Netwide Assembler, a.k.a. NASM, available from http://nasm.sourceforge.net/
 | 
			
		||||
  is required if you intend to utilize assembler modules. Note that NASM
 | 
			
		||||
  is now the only supported assembler.
 | 
			
		||||
 | 
			
		||||
 If you are compiling from a tarball or a Git snapshot then the Win32 files
 | 
			
		||||
 may well be not up to date. This may mean that some "tweaking" is required to
 | 
			
		||||
 get it all to work. See the trouble shooting section later on for if (when?)
 | 
			
		||||
@@ -37,18 +26,39 @@
 | 
			
		||||
 Visual C++
 | 
			
		||||
 ----------
 | 
			
		||||
 | 
			
		||||
 If you want to compile in the assembly language routines with Visual
 | 
			
		||||
 C++, then you will need already mentioned Netwide Assembler binary,
 | 
			
		||||
 nasmw.exe or nasm.exe, to be available on your %PATH%.
 | 
			
		||||
 If you want to compile in the assembly language routines with Visual C++ then
 | 
			
		||||
 you will need an assembler. This is worth doing because it will result in
 | 
			
		||||
 faster code: for example it will typically result in a 2 times speedup in the
 | 
			
		||||
 RSA routines. Currently the following assemblers are supported:
 | 
			
		||||
 | 
			
		||||
 Firstly you should run Configure with platform VC-WIN32:
 | 
			
		||||
  * Microsoft MASM (aka "ml")
 | 
			
		||||
  * Free Netwide Assembler NASM.
 | 
			
		||||
 | 
			
		||||
 > perl Configure VC-WIN32 --prefix=c:\some\openssl\dir
 | 
			
		||||
 MASM is distributed with most versions of VC++. For the versions where it is
 | 
			
		||||
 not included in VC++, it is also distributed with some Microsoft DDKs, for
 | 
			
		||||
 example the Windows NT 4.0 DDK and the Windows 98 DDK. If you do not have
 | 
			
		||||
 either of these DDKs then you can just download the binaries for the Windows
 | 
			
		||||
 98 DDK and extract and rename the two files XXXXXml.exe and XXXXXml.err, to
 | 
			
		||||
 ml.exe and ml.err and install somewhere on your PATH. Both DDKs can be
 | 
			
		||||
 downloaded from the Microsoft developers site www.msdn.com.
 | 
			
		||||
 | 
			
		||||
 NASM is freely available. Version 0.98 was used during testing: other versions
 | 
			
		||||
 may also work. It is available from many places, see for example:
 | 
			
		||||
 http://www.kernel.org/pub/software/devel/nasm/binaries/win32/
 | 
			
		||||
 The NASM binary nasmw.exe needs to be installed anywhere on your PATH.
 | 
			
		||||
 | 
			
		||||
 Firstly you should run Configure:
 | 
			
		||||
 | 
			
		||||
 > perl Configure VC-WIN32 --prefix=c:/some/openssl/dir
 | 
			
		||||
 | 
			
		||||
Where the prefix argument specifies where OpenSSL will be installed to.
 | 
			
		||||
 | 
			
		||||
 Next you need to build the Makefiles and optionally the assembly
 | 
			
		||||
 language files:
 | 
			
		||||
 Next you need to build the Makefiles and optionally the assembly language
 | 
			
		||||
 files:
 | 
			
		||||
 | 
			
		||||
 - If you are using MASM then run:
 | 
			
		||||
 | 
			
		||||
   > ms\do_masm
 | 
			
		||||
 | 
			
		||||
 - If you are using NASM then run:
 | 
			
		||||
 | 
			
		||||
@@ -56,7 +66,6 @@
 | 
			
		||||
 | 
			
		||||
 - If you don't want to use the assembly language files at all then run:
 | 
			
		||||
 | 
			
		||||
   > perl Configure VC-WIN32 no-asm --prefix=c:/some/openssl/dir
 | 
			
		||||
   > ms\do_ms
 | 
			
		||||
 | 
			
		||||
 If you get errors about things not having numbers assigned then check the
 | 
			
		||||
@@ -67,8 +76,8 @@
 | 
			
		||||
 | 
			
		||||
 > nmake -f ms\ntdll.mak
 | 
			
		||||
 | 
			
		||||
 If all is well it should compile and you will have some DLLs and
 | 
			
		||||
 executables in out32dll. If you want to try the tests then do:
 | 
			
		||||
 If all is well it should compile and you will have some DLLs and executables
 | 
			
		||||
 in out32dll. If you want to try the tests then do:
 | 
			
		||||
 
 | 
			
		||||
 > nmake -f ms\ntdll.mak test
 | 
			
		||||
 | 
			
		||||
@@ -79,27 +88,30 @@
 | 
			
		||||
 | 
			
		||||
 Tweaks:
 | 
			
		||||
 | 
			
		||||
 There are various changes you can make to the Win32 compile
 | 
			
		||||
 environment. By default the library is not compiled with debugging
 | 
			
		||||
 symbols. If you use the platform debug-VC-WIN32 instead of VC-WIN32
 | 
			
		||||
 then debugging symbols will be compiled in.
 | 
			
		||||
 There are various changes you can make to the Win32 compile environment. By
 | 
			
		||||
 default the library is not compiled with debugging symbols. If you add 'debug'
 | 
			
		||||
 to the mk1mf.pl lines in the do_* batch file then debugging symbols will be
 | 
			
		||||
 compiled in. Note that mk1mf.pl expects the platform to be the last argument
 | 
			
		||||
 on the command line, so 'debug' must appear before that, as all other options.
 | 
			
		||||
 | 
			
		||||
 By default in 1.0.0 OpenSSL will compile builtin ENGINES into the
 | 
			
		||||
 separate shared librariesy. If you specify the "enable-static-engine"
 | 
			
		||||
 option on the command line to Configure the shared library build
 | 
			
		||||
 (ms\ntdll.mak) will compile the engines into libeay32.dll instead.
 | 
			
		||||
 | 
			
		||||
 By default in 0.9.8 OpenSSL will compile builtin ENGINES into the libeay32.dll
 | 
			
		||||
 shared library. If you specify the "no-static-engine" option on the command
 | 
			
		||||
 line to Configure the shared library build (ms\ntdll.mak) will compile the
 | 
			
		||||
 engines as separate DLLs.
 | 
			
		||||
 | 
			
		||||
 The default Win32 environment is to leave out any Windows NT specific
 | 
			
		||||
 features.
 | 
			
		||||
 | 
			
		||||
 If you want to enable the NT specific features of OpenSSL (currently
 | 
			
		||||
 only the logging BIO) follow the instructions above but call the batch
 | 
			
		||||
 file do_nt.bat instead of do_ms.bat.
 | 
			
		||||
 If you want to enable the NT specific features of OpenSSL (currently only the
 | 
			
		||||
 logging BIO) follow the instructions above but call the batch file do_nt.bat
 | 
			
		||||
 instead of do_ms.bat.
 | 
			
		||||
 | 
			
		||||
 You can also build a static version of the library using the Makefile
 | 
			
		||||
 ms\nt.mak
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 Borland C++ builder 5
 | 
			
		||||
 ---------------------
 | 
			
		||||
 | 
			
		||||
@@ -125,13 +137,17 @@
 | 
			
		||||
 GNU C (Cygwin)
 | 
			
		||||
 --------------
 | 
			
		||||
 | 
			
		||||
 Cygwin implements a Posix/Unix runtime system (cygwin1.dll) on top of
 | 
			
		||||
 Win32 subsystem and provides a bash shell and GNU tools environment.
 | 
			
		||||
 Consequently, a make of OpenSSL with Cygwin is virtually identical to
 | 
			
		||||
 Unix procedure. It is also possible to create Win32 binaries that only
 | 
			
		||||
 use the Microsoft C runtime system (msvcrt.dll or crtdll.dll) using
 | 
			
		||||
 MinGW. MinGW can be used in the Cygwin development environment or in a
 | 
			
		||||
 standalone setup as described in the following section.
 | 
			
		||||
 Cygwin provides a bash shell and GNU tools environment running
 | 
			
		||||
 on NT 4.0, Windows 9x, Windows ME, Windows 2000, and Windows XP.
 | 
			
		||||
 Consequently, a make of OpenSSL with Cygwin is closer to a GNU
 | 
			
		||||
 bash environment such as Linux than to other the other Win32
 | 
			
		||||
 makes.
 | 
			
		||||
 | 
			
		||||
 Cygwin implements a Posix/Unix runtime system (cygwin1.dll).
 | 
			
		||||
 It is also possible to create Win32 binaries that only use the
 | 
			
		||||
 Microsoft C runtime system (msvcrt.dll or crtdll.dll) using
 | 
			
		||||
 MinGW. MinGW can be used in the Cygwin development environment
 | 
			
		||||
 or in a standalone setup as described in the following section.
 | 
			
		||||
 | 
			
		||||
 To build OpenSSL using Cygwin:
 | 
			
		||||
 | 
			
		||||
@@ -176,44 +192,35 @@
 | 
			
		||||
 non-fatal error in "make test" but is otherwise harmless.  If
 | 
			
		||||
 desired and needed, GNU bc can be built with Cygwin without change.
 | 
			
		||||
 | 
			
		||||
 GNU C (MinGW/MSYS)
 | 
			
		||||
 GNU C (MinGW)
 | 
			
		||||
 -------------
 | 
			
		||||
 | 
			
		||||
 * Compiler and shell environment installation:
 | 
			
		||||
 * Compiler installation:
 | 
			
		||||
 | 
			
		||||
   MinGW and MSYS are available from http://www.mingw.org/, both are
 | 
			
		||||
   required. Run the installers and do whatever magic they say it takes
 | 
			
		||||
   to start MSYS bash shell with GNU tools on its PATH.
 | 
			
		||||
 | 
			
		||||
   N.B. Since source tar-ball can contain symbolic links, it's essential
 | 
			
		||||
   that you use accompanying MSYS tar to unpack the source. It will
 | 
			
		||||
   either handle them in one way or another or fail to extract them,
 | 
			
		||||
   which does the trick too. Latter means that you may safely ignore all
 | 
			
		||||
   "cannot create symlink" messages, as they will be "re-created" at
 | 
			
		||||
   configure stage by copying corresponding files. Alternative programs
 | 
			
		||||
   were observed to create empty files instead, which results in build
 | 
			
		||||
   failure.
 | 
			
		||||
   MinGW is available from http://www.mingw.org. Run the installer and
 | 
			
		||||
   set the MinGW bin directory to the PATH in "System Properties" or
 | 
			
		||||
   autoexec.bat.
 | 
			
		||||
 | 
			
		||||
 * Compile OpenSSL:
 | 
			
		||||
 | 
			
		||||
   $ ./config
 | 
			
		||||
   [...]
 | 
			
		||||
   $ make
 | 
			
		||||
   [...]
 | 
			
		||||
   $ make test
 | 
			
		||||
   > ms\mingw32
 | 
			
		||||
 | 
			
		||||
   This will create the library and binaries in root source directory
 | 
			
		||||
   and openssl.exe application in apps directory.
 | 
			
		||||
 | 
			
		||||
   It is also possible to cross-compile it on Linux by configuring
 | 
			
		||||
   with './Configure --cross-compile-prefix=i386-mingw32- mingw ...'.
 | 
			
		||||
   'make test' is naturally not applicable then.
 | 
			
		||||
   This will create the library and binaries in out. In case any problems
 | 
			
		||||
   occur, try
 | 
			
		||||
   > ms\mingw32 no-asm
 | 
			
		||||
   instead.
 | 
			
		||||
 | 
			
		||||
   libcrypto.a and libssl.a are the static libraries. To use the DLLs,
 | 
			
		||||
   link with libeay32.a and libssl32.a instead.
 | 
			
		||||
 | 
			
		||||
   See troubleshooting if you get error messages about functions not
 | 
			
		||||
   having a number assigned.
 | 
			
		||||
   See troubleshooting if you get error messages about functions not having
 | 
			
		||||
   a number assigned.
 | 
			
		||||
 | 
			
		||||
 * You can now try the tests:
 | 
			
		||||
 | 
			
		||||
   > cd out
 | 
			
		||||
   > ..\ms\test
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 Installation
 | 
			
		||||
 ------------
 | 
			
		||||
@@ -300,24 +307,13 @@
 | 
			
		||||
 | 
			
		||||
 If you link with static OpenSSL libraries [those built with ms/nt.mak],
 | 
			
		||||
 then you're expected to additionally link your application with
 | 
			
		||||
 WS2_32.LIB, ADVAPI32.LIB, GDI32.LIB and USER32.LIB. Those developing
 | 
			
		||||
 WSOCK32.LIB, ADVAPI32.LIB, GDI32.LIB and USER32.LIB. Those developing
 | 
			
		||||
 non-interactive service applications might feel concerned about linking
 | 
			
		||||
 with the latter two, as they are justly associated with interactive
 | 
			
		||||
 desktop, which is not available to service processes. The toolkit is
 | 
			
		||||
 designed to detect in which context it's currently executed, GUI,
 | 
			
		||||
 console app or service, and act accordingly, namely whether or not to
 | 
			
		||||
 actually make GUI calls. Additionally those who wish to
 | 
			
		||||
 /DELAYLOAD:GDI32.DLL and /DELAYLOAD:USER32.DLL and actually keep them
 | 
			
		||||
 off service process should consider implementing and exporting from
 | 
			
		||||
 .exe image in question own _OPENSSL_isservice not relying on USER32.DLL.
 | 
			
		||||
 E.g., on Windows Vista and later you could:
 | 
			
		||||
 | 
			
		||||
	__declspec(dllexport) __cdecl BOOL _OPENSSL_isservice(void)
 | 
			
		||||
	{   DWORD sess;
 | 
			
		||||
	    if (ProcessIdToSessionId(GetCurrentProcessId(),&sess))
 | 
			
		||||
	        return sess==0;
 | 
			
		||||
	    return FALSE;
 | 
			
		||||
	}
 | 
			
		||||
 with latter two, as they are justly associated with interactive desktop,
 | 
			
		||||
 which is not available to service processes. The toolkit is designed
 | 
			
		||||
 to detect in which context it's currently executed, GUI, console app
 | 
			
		||||
 or service, and act accordingly, namely whether or not to actually make
 | 
			
		||||
 GUI calls.
 | 
			
		||||
 | 
			
		||||
 If you link with OpenSSL .DLLs, then you're expected to include into
 | 
			
		||||
 your application code small "shim" snippet, which provides glue between
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										75
									
								
								INSTALL.WCE
									
									
									
									
									
								
							
							
						
						
									
										75
									
								
								INSTALL.WCE
									
									
									
									
									
								
							@@ -4,36 +4,27 @@
 | 
			
		||||
 | 
			
		||||
 Building OpenSSL for Windows CE requires the following external tools:
 | 
			
		||||
 | 
			
		||||
  * Microsoft eMbedded Visual C++ 3.0 or later
 | 
			
		||||
  * Appropriate SDK might be required
 | 
			
		||||
  * Perl for Win32 [commonly recommended ActiveState Perl is available
 | 
			
		||||
    from http://www.activestate.com/Products/ActivePerl/]
 | 
			
		||||
  * Microsoft eMbedded Visual C++ 3.0
 | 
			
		||||
  * wcecompat compatibility library (www.essemer.com.au)
 | 
			
		||||
  * Optionally ceutils for running automated tests (www.essemer.com.au)
 | 
			
		||||
 | 
			
		||||
  * wcecompat compatibility library available at
 | 
			
		||||
    http://www.essemer.com.au/windowsce/
 | 
			
		||||
  * Optionally ceutils for running automated tests (same location)
 | 
			
		||||
 You also need Perl for Win32.  You will need ActiveState Perl, available
 | 
			
		||||
 from http://www.activestate.com/ActivePerl.
 | 
			
		||||
 | 
			
		||||
  _or_
 | 
			
		||||
 Windows CE support in OpenSSL relies on wcecompat and therefore it's
 | 
			
		||||
 appropriate to check http://www.essemer.com.au/windowsce/ for updates in
 | 
			
		||||
 case of compilation problems. As for the moment of this writing version
 | 
			
		||||
 1.1 is available and actually required for WCE 4.2 and newer platforms.
 | 
			
		||||
 All Windows CE specific issues should be directed to www.essemer.com.au.
 | 
			
		||||
 | 
			
		||||
  * PocketConsole driver and PortSDK available at
 | 
			
		||||
    http://www.symbolictools.de/public/pocketconsole/
 | 
			
		||||
  * CMD command interpreter (same location)
 | 
			
		||||
 | 
			
		||||
 As Windows CE support in OpenSSL relies on 3rd party compatibility
 | 
			
		||||
 library, it's appropriate to check corresponding URL for updates. For
 | 
			
		||||
 example if you choose wcecompat, note that as for the moment of this
 | 
			
		||||
 writing version 1.2 is available and actually required for WCE 4.2
 | 
			
		||||
 and newer platforms. All wcecompat issues should be directed to
 | 
			
		||||
 www.essemer.com.au.
 | 
			
		||||
 | 
			
		||||
 Why compatibility library at all? The C Runtime Library implementation
 | 
			
		||||
 for Windows CE that is included with Microsoft eMbedded Visual C++ is
 | 
			
		||||
 incomplete and in some places incorrect.  Compatibility library plugs
 | 
			
		||||
 the holes and tries to bring the Windows CE CRT to [more] usable level.
 | 
			
		||||
 Most gaping hole in CRT is support for stdin/stdout/stderr IO, which
 | 
			
		||||
 proposed compatibility libraries solve in two different ways: wcecompat
 | 
			
		||||
 redirects IO to active sync link, while PortSDK - to NT-like console
 | 
			
		||||
 driver on the handheld itself.
 | 
			
		||||
 The C Runtime Library implementation for Windows CE that is included with
 | 
			
		||||
 Microsoft eMbedded Visual C++ 3.0 is incomplete and in some places
 | 
			
		||||
 incorrect.  wcecompat plugs the holes and tries to bring the Windows CE
 | 
			
		||||
 CRT to a level that is more compatible with ANSI C.  wcecompat goes further
 | 
			
		||||
 and provides low-level IO and stream IO support for stdin/stdout/stderr
 | 
			
		||||
 (which Windows CE does not provide).  This IO functionality is not needed
 | 
			
		||||
 by the OpenSSL library itself but is used for the tests and openssl.exe.
 | 
			
		||||
 More information is available at www.essemer.com.au.
 | 
			
		||||
 | 
			
		||||
 Building
 | 
			
		||||
 --------
 | 
			
		||||
@@ -43,21 +34,9 @@
 | 
			
		||||
 | 
			
		||||
 > "C:\Program Files\Microsoft eMbedded Tools\EVC\WCE300\BIN\WCEARM.BAT"
 | 
			
		||||
 | 
			
		||||
 Next pick compatibility library according to your preferences.
 | 
			
		||||
 | 
			
		||||
 1. To choose wcecompat set up WCECOMPAT environment variable pointing
 | 
			
		||||
    at the location of wcecompat tree "root":
 | 
			
		||||
 Next indicate where wcecompat is located:
 | 
			
		||||
 | 
			
		||||
 > set WCECOMPAT=C:\wcecompat
 | 
			
		||||
    > set PORTSDK_LIBPATH=
 | 
			
		||||
 | 
			
		||||
 2. To choose PortSDK set up PORTSDK_LIBPATH to point at hardware-
 | 
			
		||||
    specific location where your portlib.lib is installed:
 | 
			
		||||
 | 
			
		||||
    > set PORTSDK_LIBPATH=C:\PortSDK\lib\ARM
 | 
			
		||||
    > set WCECOMPAT=
 | 
			
		||||
 | 
			
		||||
 Note that you may not set both variables.
 | 
			
		||||
 | 
			
		||||
 Next you should run Configure:
 | 
			
		||||
 | 
			
		||||
@@ -73,16 +52,16 @@
 | 
			
		||||
 | 
			
		||||
 Then from the VC++ environment at a prompt do:
 | 
			
		||||
 | 
			
		||||
 - to build static libraries:
 | 
			
		||||
 | 
			
		||||
   > nmake -f ms\ce.mak
 | 
			
		||||
 | 
			
		||||
 - or to build DLLs:
 | 
			
		||||
 | 
			
		||||
   > nmake -f ms\cedll.mak
 | 
			
		||||
 | 
			
		||||
 [note that static builds are not supported under CE]
 | 
			
		||||
 | 
			
		||||
 If all is well it should compile and you will have some DLLs and executables
 | 
			
		||||
 in out32dll*. 
 | 
			
		||||
 | 
			
		||||
 <<< everyting below needs revision in respect to wcecompat vs. PortSDK >>>
 | 
			
		||||
 | 
			
		||||
 If you want
 | 
			
		||||
 If all is well it should compile and you will have some static libraries and
 | 
			
		||||
 executables in out32, or some DLLs and executables in out32dll.  If you want
 | 
			
		||||
 to try the tests then make sure the ceutils are in the path and do:
 | 
			
		||||
 
 | 
			
		||||
 > cd out32
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										62
									
								
								MacOS/GUSI_Init.cpp
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										62
									
								
								MacOS/GUSI_Init.cpp
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,62 @@
 | 
			
		||||
/**************** BEGIN GUSI CONFIGURATION ****************************
 | 
			
		||||
 *
 | 
			
		||||
 * GUSI Configuration section generated by GUSI Configurator
 | 
			
		||||
 * last modified: Wed Jan  5 20:33:51 2000
 | 
			
		||||
 *
 | 
			
		||||
 * This section will be overwritten by the next run of Configurator.
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
#define GUSI_SOURCE
 | 
			
		||||
#include <GUSIConfig.h>
 | 
			
		||||
#include <sys/cdefs.h>
 | 
			
		||||
 | 
			
		||||
/* Declarations of Socket Factories */
 | 
			
		||||
 | 
			
		||||
__BEGIN_DECLS
 | 
			
		||||
void GUSIwithInetSockets();
 | 
			
		||||
void GUSIwithLocalSockets();
 | 
			
		||||
void GUSIwithMTInetSockets();
 | 
			
		||||
void GUSIwithMTTcpSockets();
 | 
			
		||||
void GUSIwithMTUdpSockets();
 | 
			
		||||
void GUSIwithOTInetSockets();
 | 
			
		||||
void GUSIwithOTTcpSockets();
 | 
			
		||||
void GUSIwithOTUdpSockets();
 | 
			
		||||
void GUSIwithPPCSockets();
 | 
			
		||||
void GUSISetupFactories();
 | 
			
		||||
__END_DECLS
 | 
			
		||||
 | 
			
		||||
/* Configure Socket Factories */
 | 
			
		||||
 | 
			
		||||
void GUSISetupFactories()
 | 
			
		||||
{
 | 
			
		||||
#ifdef GUSISetupFactories_BeginHook
 | 
			
		||||
	GUSISetupFactories_BeginHook
 | 
			
		||||
#endif
 | 
			
		||||
	GUSIwithInetSockets();
 | 
			
		||||
#ifdef GUSISetupFactories_EndHook
 | 
			
		||||
	GUSISetupFactories_EndHook
 | 
			
		||||
#endif
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
/* Declarations of File Devices */
 | 
			
		||||
 | 
			
		||||
__BEGIN_DECLS
 | 
			
		||||
void GUSIwithDConSockets();
 | 
			
		||||
void GUSIwithNullSockets();
 | 
			
		||||
void GUSISetupDevices();
 | 
			
		||||
__END_DECLS
 | 
			
		||||
 | 
			
		||||
/* Configure File Devices */
 | 
			
		||||
 | 
			
		||||
void GUSISetupDevices()
 | 
			
		||||
{
 | 
			
		||||
#ifdef GUSISetupDevices_BeginHook
 | 
			
		||||
	GUSISetupDevices_BeginHook
 | 
			
		||||
#endif
 | 
			
		||||
	GUSIwithNullSockets();
 | 
			
		||||
#ifdef GUSISetupDevices_EndHook
 | 
			
		||||
	GUSISetupDevices_EndHook
 | 
			
		||||
#endif
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
/**************** END GUSI CONFIGURATION *************************/
 | 
			
		||||
							
								
								
									
										2753
									
								
								MacOS/GetHTTPS.src/CPStringUtils.cpp
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										2753
									
								
								MacOS/GetHTTPS.src/CPStringUtils.cpp
									
									
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										104
									
								
								MacOS/GetHTTPS.src/CPStringUtils.hpp
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										104
									
								
								MacOS/GetHTTPS.src/CPStringUtils.hpp
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,104 @@
 | 
			
		||||
#pragma once
 | 
			
		||||
 | 
			
		||||
#ifdef __cplusplus
 | 
			
		||||
extern "C" {
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
void CopyPStrToCStr(const unsigned char *thePStr,char *theCStr,const int maxCStrLength);
 | 
			
		||||
void CopyPStrToPStr(const unsigned char *theSrcPStr,unsigned char *theDstPStr,const int maxDstStrLength);
 | 
			
		||||
void CopyCStrToCStr(const char *theSrcCStr,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
void CopyCStrToPStr(const char *theSrcCStr,unsigned char *theDstPStr,const int maxDstStrLength);
 | 
			
		||||
void ConcatPStrToCStr(const unsigned char *thePStr,char *theCStr,const int maxCStrLength);
 | 
			
		||||
void ConcatPStrToPStr(const unsigned char *theSrcPStr,unsigned char *theDstPStr,const int maxDstStrLength);
 | 
			
		||||
void ConcatCStrToPStr(const char *theSrcCStr,unsigned char *theDstPStr,const int maxDstStrLength);
 | 
			
		||||
void ConcatCStrToCStr(const char *theSrcCStr,char *theDstCStr,const int maxCStrLength);
 | 
			
		||||
 | 
			
		||||
void ConcatCharToCStr(const char theChar,char *theDstCStr,const int maxCStrLength);
 | 
			
		||||
void ConcatCharToPStr(const char theChar,unsigned char *theDstPStr,const int maxPStrLength);
 | 
			
		||||
 | 
			
		||||
int ComparePStrs(const unsigned char *theFirstPStr,const unsigned char *theSecondPStr,const Boolean ignoreCase = true);
 | 
			
		||||
int CompareCStrs(const char *theFirstCStr,const char *theSecondCStr,const Boolean ignoreCase = true);
 | 
			
		||||
int CompareCStrToPStr(const char *theCStr,const unsigned char *thePStr,const Boolean ignoreCase = true);
 | 
			
		||||
 | 
			
		||||
Boolean CStrsAreEqual(const char *theFirstCStr,const char *theSecondCStr,const Boolean ignoreCase = true);
 | 
			
		||||
Boolean PStrsAreEqual(const unsigned char *theFirstCStr,const unsigned char *theSecondCStr,const Boolean ignoreCase = true);
 | 
			
		||||
 | 
			
		||||
void CopyLongIntToCStr(const long theNum,char *theCStr,const int maxCStrLength,const int numDigits = -1);
 | 
			
		||||
void CopyUnsignedLongIntToCStr(const unsigned long theNum,char *theCStr,const int maxCStrLength);
 | 
			
		||||
void ConcatLongIntToCStr(const long theNum,char *theCStr,const int maxCStrLength,const int numDigits = -1);
 | 
			
		||||
void CopyCStrAndConcatLongIntToCStr(const char *theSrcCStr,const long theNum,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
 | 
			
		||||
void CopyLongIntToPStr(const long theNum,unsigned char *thePStr,const int maxPStrLength,const int numDigits = -1);
 | 
			
		||||
void ConcatLongIntToPStr(const long theNum,unsigned char *thePStr,const int maxPStrLength,const int numDigits = -1);
 | 
			
		||||
 | 
			
		||||
long CStrLength(const char *theCString);
 | 
			
		||||
long PStrLength(const unsigned char *thePString);
 | 
			
		||||
 | 
			
		||||
OSErr CopyCStrToExistingHandle(const char *theCString,Handle theHandle);
 | 
			
		||||
OSErr CopyLongIntToExistingHandle(const long inTheLongInt,Handle theHandle);
 | 
			
		||||
 | 
			
		||||
OSErr CopyCStrToNewHandle(const char *theCString,Handle *theHandle);
 | 
			
		||||
OSErr CopyPStrToNewHandle(const unsigned char *thePString,Handle *theHandle);
 | 
			
		||||
OSErr CopyLongIntToNewHandle(const long inTheLongInt,Handle *theHandle);
 | 
			
		||||
 | 
			
		||||
OSErr AppendCStrToHandle(const char *theCString,Handle theHandle,long *currentLength = nil,long *maxLength = nil);
 | 
			
		||||
OSErr AppendCharsToHandle(const char *theChars,const int numChars,Handle theHandle,long *currentLength = nil,long *maxLength = nil);
 | 
			
		||||
OSErr AppendPStrToHandle(const unsigned char *thePString,Handle theHandle,long *currentLength = nil);
 | 
			
		||||
OSErr AppendLongIntToHandle(const long inTheLongInt,Handle theHandle,long *currentLength = nil);
 | 
			
		||||
 | 
			
		||||
void ZeroMem(void *theMemPtr,const unsigned long numBytes);
 | 
			
		||||
 | 
			
		||||
char *FindCharInCStr(const char theChar,const char *theCString);
 | 
			
		||||
long FindCharOffsetInCStr(const char theChar,const char *theCString,const Boolean inIgnoreCase = false);
 | 
			
		||||
long FindCStrOffsetInCStr(const char *theCSubstring,const char *theCString,const Boolean inIgnoreCase = false);
 | 
			
		||||
 | 
			
		||||
void CopyCSubstrToCStr(const char *theSrcCStr,const int maxCharsToCopy,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
void CopyCSubstrToPStr(const char *theSrcCStr,const int maxCharsToCopy,unsigned char *theDstPStr,const int maxDstStrLength);
 | 
			
		||||
 | 
			
		||||
void InsertCStrIntoCStr(const char *theSrcCStr,const int theInsertionOffset,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
void InsertPStrIntoCStr(const unsigned char *theSrcPStr,const int theInsertionOffset,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
OSErr InsertCStrIntoHandle(const char *theCString,Handle theHandle,const long inInsertOffset);
 | 
			
		||||
 | 
			
		||||
void CopyCStrAndInsertCStrIntoCStr(const char *theSrcCStr,const char *theInsertCStr,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
 | 
			
		||||
void CopyCStrAndInsertCStrsLongIntsIntoCStr(const char *theSrcCStr,const char **theInsertCStrs,const long *theLongInts,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
 | 
			
		||||
void CopyCStrAndInsert1LongIntIntoCStr(const char *theSrcCStr,const long theNum,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
void CopyCStrAndInsert2LongIntsIntoCStr(const char *theSrcCStr,const long long1,const long long2,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
void CopyCStrAndInsert3LongIntsIntoCStr(const char *theSrcCStr,const long long1,const long long2,const long long3,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
 | 
			
		||||
void CopyCStrAndInsertCStrLongIntIntoCStr(const char *theSrcCStr,const char *theInsertCStr,const long theNum,char *theDstCStr,const int maxDstStrLength);
 | 
			
		||||
OSErr CopyCStrAndInsertCStrLongIntIntoHandle(const char *theSrcCStr,const char *theInsertCStr,const long theNum,Handle *theHandle);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
OSErr CopyIndexedWordToCStr(char *theSrcCStr,int whichWord,char *theDstCStr,int maxDstCStrLength);
 | 
			
		||||
OSErr CopyIndexedWordToNewHandle(char *theSrcCStr,int whichWord,Handle *outTheHandle);
 | 
			
		||||
 | 
			
		||||
OSErr CopyIndexedLineToCStr(const char *theSrcCStr,int inWhichLine,int *lineEndIndex,Boolean *gotLastLine,char *theDstCStr,const int maxDstCStrLength);
 | 
			
		||||
OSErr CopyIndexedLineToNewHandle(const char *theSrcCStr,int inWhichLine,Handle *outNewHandle);
 | 
			
		||||
 | 
			
		||||
OSErr ExtractIntFromCStr(const char *theSrcCStr,int *outInt,Boolean skipLeadingSpaces = true);
 | 
			
		||||
OSErr ExtractIntFromPStr(const unsigned char *theSrcPStr,int *outInt,Boolean skipLeadingSpaces = true);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
void ConvertCStrToUpperCase(char *theSrcCStr);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
int CountOccurencesOfCharInCStr(const char inChar,const char *inSrcCStr);
 | 
			
		||||
int CountWordsInCStr(const char *inSrcCStr);
 | 
			
		||||
 | 
			
		||||
OSErr CountDigits(const char *inCStr,int *outNumIntegerDigits,int *outNumFractDigits);
 | 
			
		||||
 | 
			
		||||
void ExtractCStrItemFromCStr(const char *inSrcCStr,const char inItemDelimiter,const int inItemNumber,Boolean *foundItem,char *outDstCharPtr,const int inDstCharPtrMaxLength,const Boolean inTreatMultipleDelimsAsSingleDelim = false);
 | 
			
		||||
OSErr ExtractCStrItemFromCStrIntoNewHandle(const char *inSrcCStr,const char inItemDelimiter,const int inItemNumber,Boolean *foundItem,Handle *outNewHandle,const Boolean inTreatMultipleDelimsAsSingleDelim = false);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
OSErr ExtractFloatFromCStr(const char *inCString,extended80 *outFloat);
 | 
			
		||||
OSErr CopyFloatToCStr(const extended80 *theFloat,char *theCStr,const int maxCStrLength,const int inMaxNumIntDigits = -1,const int inMaxNumFractDigits = -1);
 | 
			
		||||
 | 
			
		||||
void SkipWhiteSpace(char **ioSrcCharPtr,const Boolean inStopAtEOL = false);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#ifdef __cplusplus
 | 
			
		||||
}
 | 
			
		||||
#endif
 | 
			
		||||
@@ -1,5 +1,5 @@
 | 
			
		||||
/* ====================================================================
 | 
			
		||||
 * Copyright (c) 1998-2014 The OpenSSL Project.  All rights reserved.
 | 
			
		||||
 * Copyright (c) 1998-1999 The OpenSSL Project.  All rights reserved.
 | 
			
		||||
 *
 | 
			
		||||
 * Redistribution and use in source and binary forms, with or without
 | 
			
		||||
 * modification, are permitted provided that the following conditions
 | 
			
		||||
@@ -52,72 +52,119 @@
 | 
			
		||||
 *
 | 
			
		||||
 */
 | 
			
		||||
 
 | 
			
		||||
#ifndef HEADER_BN_INT_H
 | 
			
		||||
# define HEADER_BN_INT_H
 | 
			
		||||
 
 | 
			
		||||
# include <openssl/bn.h>
 | 
			
		||||
 
 | 
			
		||||
#ifdef  __cplusplus
 | 
			
		||||
extern "C" {
 | 
			
		||||
 #include "ErrorHandling.hpp"
 | 
			
		||||
#include "CPStringUtils.hpp"
 | 
			
		||||
 | 
			
		||||
#ifdef __EXCEPTIONS_ENABLED__
 | 
			
		||||
	#include "CMyException.hpp"
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
# define bn_expand(a,bits) ((((((bits+BN_BITS2-1))/BN_BITS2)) <= (a)->dmax)?\
 | 
			
		||||
        (a):bn_expand2((a),(bits+BN_BITS2-1)/BN_BITS2))
 | 
			
		||||
BIGNUM *bn_wexpand(BIGNUM *a, int words);
 | 
			
		||||
BIGNUM *bn_expand2(BIGNUM *a, int words);
 | 
			
		||||
 | 
			
		||||
void bn_correct_top(BIGNUM *a);
 | 
			
		||||
static char					gErrorMessageBuffer[512];
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * Determine the modified width-(w+1) Non-Adjacent Form (wNAF) of 'scalar'.
 | 
			
		||||
 * This is an array r[] of values that are either zero or odd with an
 | 
			
		||||
 * absolute value less than 2^w satisfying scalar = \sum_j r[j]*2^j where at
 | 
			
		||||
 * most one of any w+1 consecutive digits is non-zero with the exception that
 | 
			
		||||
 * the most significant digit may be only w-1 zeros away from that next
 | 
			
		||||
 * non-zero digit.
 | 
			
		||||
 */
 | 
			
		||||
signed char *bn_compute_wNAF(const BIGNUM *scalar, int w, size_t *ret_len);
 | 
			
		||||
 | 
			
		||||
int bn_get_top(const BIGNUM *a);
 | 
			
		||||
 | 
			
		||||
void bn_set_top(BIGNUM *a, int top);
 | 
			
		||||
 | 
			
		||||
int bn_get_dmax(const BIGNUM *a);
 | 
			
		||||
 | 
			
		||||
/* Set all words to zero */
 | 
			
		||||
void bn_set_all_zero(BIGNUM *a);
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * Copy the internal BIGNUM words into out which holds size elements (and size
 | 
			
		||||
 * must be bigger than top)
 | 
			
		||||
 */
 | 
			
		||||
int bn_copy_words(BN_ULONG *out, const BIGNUM *in, int size);
 | 
			
		||||
 | 
			
		||||
BN_ULONG *bn_get_words(const BIGNUM *a);
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * Set the internal data words in a to point to words which contains size
 | 
			
		||||
 * elements. The BN_FLG_STATIC_DATA flag is set
 | 
			
		||||
 */
 | 
			
		||||
void bn_set_static_words(BIGNUM *a, BN_ULONG *words, int size);
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * Copy data into the BIGNUM. The caller must check that dmax is sufficient to
 | 
			
		||||
 * hold the data
 | 
			
		||||
 */
 | 
			
		||||
void bn_set_data(BIGNUM *a, const void *data, size_t size);
 | 
			
		||||
 | 
			
		||||
size_t bn_sizeof_BIGNUM(void);
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * Return element el from an array of BIGNUMs starting at base (required
 | 
			
		||||
 * because callers do not know the size of BIGNUM at compilation time)
 | 
			
		||||
 */
 | 
			
		||||
BIGNUM *bn_array_el(BIGNUM *base, int el);
 | 
			
		||||
char 						*gErrorMessage = gErrorMessageBuffer;
 | 
			
		||||
int							gErrorMessageMaxLength = sizeof(gErrorMessageBuffer);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#ifdef  __cplusplus
 | 
			
		||||
 | 
			
		||||
void SetErrorMessage(const char *theErrorMessage)
 | 
			
		||||
{
 | 
			
		||||
	if (theErrorMessage != nil)
 | 
			
		||||
	{
 | 
			
		||||
		CopyCStrToCStr(theErrorMessage,gErrorMessage,gErrorMessageMaxLength);
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
void SetErrorMessageAndAppendLongInt(const char *theErrorMessage,const long theLongInt)
 | 
			
		||||
{
 | 
			
		||||
	if (theErrorMessage != nil)
 | 
			
		||||
	{
 | 
			
		||||
		CopyCStrAndConcatLongIntToCStr(theErrorMessage,theLongInt,gErrorMessage,gErrorMessageMaxLength);
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void SetErrorMessageAndCStrAndLongInt(const char *theErrorMessage,const char * theCStr,const long theLongInt)
 | 
			
		||||
{
 | 
			
		||||
	if (theErrorMessage != nil)
 | 
			
		||||
	{
 | 
			
		||||
		CopyCStrAndInsertCStrLongIntIntoCStr(theErrorMessage,theCStr,theLongInt,gErrorMessage,gErrorMessageMaxLength);
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void SetErrorMessageAndCStr(const char *theErrorMessage,const char * theCStr)
 | 
			
		||||
{
 | 
			
		||||
	if (theErrorMessage != nil)
 | 
			
		||||
	{
 | 
			
		||||
		CopyCStrAndInsertCStrLongIntIntoCStr(theErrorMessage,theCStr,-1,gErrorMessage,gErrorMessageMaxLength);
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
void AppendCStrToErrorMessage(const char *theErrorMessage)
 | 
			
		||||
{
 | 
			
		||||
	if (theErrorMessage != nil)
 | 
			
		||||
	{
 | 
			
		||||
		ConcatCStrToCStr(theErrorMessage,gErrorMessage,gErrorMessageMaxLength);
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
void AppendLongIntToErrorMessage(const long theLongInt)
 | 
			
		||||
{
 | 
			
		||||
	ConcatLongIntToCStr(theLongInt,gErrorMessage,gErrorMessageMaxLength);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
char *GetErrorMessage(void)
 | 
			
		||||
{
 | 
			
		||||
	return gErrorMessage;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
OSErr GetErrorMessageInNewHandle(Handle *inoutHandle)
 | 
			
		||||
{
 | 
			
		||||
OSErr		errCode;
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
	errCode = CopyCStrToNewHandle(gErrorMessage,inoutHandle);
 | 
			
		||||
	
 | 
			
		||||
	return(errCode);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
OSErr GetErrorMessageInExistingHandle(Handle inoutHandle)
 | 
			
		||||
{
 | 
			
		||||
OSErr		errCode;
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
	errCode = CopyCStrToExistingHandle(gErrorMessage,inoutHandle);
 | 
			
		||||
	
 | 
			
		||||
	return(errCode);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
OSErr AppendErrorMessageToHandle(Handle inoutHandle)
 | 
			
		||||
{
 | 
			
		||||
OSErr		errCode;
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
	errCode = AppendCStrToHandle(gErrorMessage,inoutHandle,nil);
 | 
			
		||||
	
 | 
			
		||||
	return(errCode);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#ifdef __EXCEPTIONS_ENABLED__
 | 
			
		||||
 | 
			
		||||
void ThrowErrorMessageException(void)
 | 
			
		||||
{
 | 
			
		||||
	ThrowDescriptiveException(gErrorMessage);
 | 
			
		||||
}
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
							
								
								
									
										147
									
								
								MacOS/GetHTTPS.src/ErrorHandling.hpp
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										147
									
								
								MacOS/GetHTTPS.src/ErrorHandling.hpp
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,147 @@
 | 
			
		||||
#ifdef __cplusplus
 | 
			
		||||
extern "C" {
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#ifndef kGenericError
 | 
			
		||||
	#define kGenericError		-1
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
extern char	*gErrorMessage;
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
void SetErrorMessage(const char *theErrorMessage);
 | 
			
		||||
void SetErrorMessageAndAppendLongInt(const char *theErrorMessage,const long theLongInt);
 | 
			
		||||
void SetErrorMessageAndCStrAndLongInt(const char *theErrorMessage,const char * theCStr,const long theLongInt);
 | 
			
		||||
void SetErrorMessageAndCStr(const char *theErrorMessage,const char * theCStr);
 | 
			
		||||
void AppendCStrToErrorMessage(const char *theErrorMessage);
 | 
			
		||||
void AppendLongIntToErrorMessage(const long theLongInt);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
char *GetErrorMessage(void);
 | 
			
		||||
OSErr GetErrorMessageInNewHandle(Handle *inoutHandle);
 | 
			
		||||
OSErr GetErrorMessageInExistingHandle(Handle inoutHandle);
 | 
			
		||||
OSErr AppendErrorMessageToHandle(Handle inoutHandle);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#ifdef __EXCEPTIONS_ENABLED__
 | 
			
		||||
	void ThrowErrorMessageException(void);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
//	A bunch of evil macros that would be unnecessary if I were always using C++ !
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageAndBailIfNil(theArg,theMessage)								\
 | 
			
		||||
{																					\
 | 
			
		||||
	if (theArg == nil)																\
 | 
			
		||||
	{																				\
 | 
			
		||||
		SetErrorMessage(theMessage);												\
 | 
			
		||||
		errCode = kGenericError;													\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
	}																				\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageAndBail(theMessage)											\
 | 
			
		||||
{																					\
 | 
			
		||||
		SetErrorMessage(theMessage);												\
 | 
			
		||||
		errCode = kGenericError;													\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageAndLongIntAndBail(theMessage,theLongInt)						\
 | 
			
		||||
{																					\
 | 
			
		||||
		SetErrorMessageAndAppendLongInt(theMessage,theLongInt);						\
 | 
			
		||||
		errCode = kGenericError;													\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageAndLongIntAndBailIfError(theErrCode,theMessage,theLongInt)	\
 | 
			
		||||
{																					\
 | 
			
		||||
	if (theErrCode != noErr)														\
 | 
			
		||||
	{																				\
 | 
			
		||||
		SetErrorMessageAndAppendLongInt(theMessage,theLongInt);						\
 | 
			
		||||
		errCode = theErrCode;														\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
	}																				\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageCStrLongIntAndBailIfError(theErrCode,theMessage,theCStr,theLongInt)	\
 | 
			
		||||
{																					\
 | 
			
		||||
	if (theErrCode != noErr)														\
 | 
			
		||||
	{																				\
 | 
			
		||||
		SetErrorMessageAndCStrAndLongInt(theMessage,theCStr,theLongInt);			\
 | 
			
		||||
		errCode = theErrCode;														\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
	}																				\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageAndCStrAndBail(theMessage,theCStr)							\
 | 
			
		||||
{																					\
 | 
			
		||||
	SetErrorMessageAndCStr(theMessage,theCStr);										\
 | 
			
		||||
	errCode = kGenericError;														\
 | 
			
		||||
	goto EXITPOINT;																	\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageAndBailIfError(theErrCode,theMessage)						\
 | 
			
		||||
{																					\
 | 
			
		||||
	if (theErrCode != noErr)														\
 | 
			
		||||
	{																				\
 | 
			
		||||
		SetErrorMessage(theMessage);												\
 | 
			
		||||
		errCode = theErrCode;														\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
	}																				\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorMessageAndLongIntAndBailIfNil(theArg,theMessage,theLongInt)			\
 | 
			
		||||
{																					\
 | 
			
		||||
	if (theArg == nil)																\
 | 
			
		||||
	{																				\
 | 
			
		||||
		SetErrorMessageAndAppendLongInt(theMessage,theLongInt);						\
 | 
			
		||||
		errCode = kGenericError;													\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
	}																				\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define BailIfError(theErrCode)														\
 | 
			
		||||
{																					\
 | 
			
		||||
	if ((theErrCode) != noErr)														\
 | 
			
		||||
	{																				\
 | 
			
		||||
		goto EXITPOINT;																\
 | 
			
		||||
	}																				\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrCodeAndBail(theErrCode)												\
 | 
			
		||||
{																					\
 | 
			
		||||
	errCode = theErrCode;															\
 | 
			
		||||
																					\
 | 
			
		||||
	goto EXITPOINT;																	\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define SetErrorCodeAndMessageAndBail(theErrCode,theMessage)						\
 | 
			
		||||
{																					\
 | 
			
		||||
	SetErrorMessage(theMessage);													\
 | 
			
		||||
	errCode = theErrCode;															\
 | 
			
		||||
	goto EXITPOINT;																	\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#define BailNow()																	\
 | 
			
		||||
{																					\
 | 
			
		||||
	errCode = kGenericError;														\
 | 
			
		||||
	goto EXITPOINT;																	\
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#ifdef __cplusplus
 | 
			
		||||
}
 | 
			
		||||
#endif
 | 
			
		||||
							
								
								
									
										209
									
								
								MacOS/GetHTTPS.src/GetHTTPS.cpp
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										209
									
								
								MacOS/GetHTTPS.src/GetHTTPS.cpp
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,209 @@
 | 
			
		||||
/*
 | 
			
		||||
 *	An demo illustrating how to retrieve a URI from a secure HTTP server.
 | 
			
		||||
 *
 | 
			
		||||
 *	Author: 	Roy Wood
 | 
			
		||||
 *	Date:		September 7, 1999
 | 
			
		||||
 *	Comments:	This relies heavily on my MacSockets library.
 | 
			
		||||
 *				This project is also set up so that it expects the OpenSSL source folder (0.9.4 as I write this)
 | 
			
		||||
 *				to live in a folder called "OpenSSL-0.9.4" in this project's parent folder.  For example:
 | 
			
		||||
 *
 | 
			
		||||
 *					Macintosh HD:
 | 
			
		||||
 *						Development:
 | 
			
		||||
 *							OpenSSL-0.9.4:
 | 
			
		||||
 *								(OpenSSL sources here)
 | 
			
		||||
 *							OpenSSL Example:
 | 
			
		||||
 *								(OpenSSL example junk here)
 | 
			
		||||
 *
 | 
			
		||||
 *
 | 
			
		||||
 *				Also-- before attempting to compile this, make sure the aliases in "OpenSSL-0.9.4:include:openssl" 
 | 
			
		||||
 *				are installed!  Use the AppleScript applet in the "openssl-0.9.4" folder to do this!
 | 
			
		||||
 */
 | 
			
		||||
/* modified to seed the PRNG */
 | 
			
		||||
/* modified to use CRandomizer for seeding */
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
//	Include some funky libs I've developed over time
 | 
			
		||||
 | 
			
		||||
#include "CPStringUtils.hpp"
 | 
			
		||||
#include "ErrorHandling.hpp"
 | 
			
		||||
#include "MacSocket.h"
 | 
			
		||||
#include "Randomizer.h"
 | 
			
		||||
 | 
			
		||||
//	We use the OpenSSL implementation of SSL....
 | 
			
		||||
//	This was a lot of work to finally get going, though you wouldn't know it by the results!
 | 
			
		||||
 | 
			
		||||
#include <openssl/ssl.h>
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
 | 
			
		||||
#include <timer.h>
 | 
			
		||||
 | 
			
		||||
//	Let's try grabbing some data from here:
 | 
			
		||||
 | 
			
		||||
#define kHTTPS_DNS		"www.apache-ssl.org"
 | 
			
		||||
#define kHTTPS_Port		443
 | 
			
		||||
#define kHTTPS_URI		"/"
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
//	Forward-declare this
 | 
			
		||||
 | 
			
		||||
OSErr MyMacSocket_IdleWaitCallback(void *inUserRefPtr);
 | 
			
		||||
 | 
			
		||||
//	My idle-wait callback.  Doesn't do much, does it?  Silly cooperative multitasking.
 | 
			
		||||
 | 
			
		||||
OSErr MyMacSocket_IdleWaitCallback(void *inUserRefPtr)
 | 
			
		||||
{
 | 
			
		||||
#pragma unused(inUserRefPtr)
 | 
			
		||||
 | 
			
		||||
EventRecord		theEvent;
 | 
			
		||||
	::EventAvail(everyEvent,&theEvent);
 | 
			
		||||
	
 | 
			
		||||
	CRandomizer *randomizer = (CRandomizer*)inUserRefPtr;
 | 
			
		||||
	if (randomizer)
 | 
			
		||||
		randomizer->PeriodicAction();
 | 
			
		||||
 | 
			
		||||
	return(noErr);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
//	Finally!
 | 
			
		||||
 | 
			
		||||
void main(void)
 | 
			
		||||
{
 | 
			
		||||
	OSErr				errCode;
 | 
			
		||||
	int					theSocket = -1;
 | 
			
		||||
	int					theTimeout = 30;
 | 
			
		||||
 | 
			
		||||
	SSL_CTX				*ssl_ctx = nil;
 | 
			
		||||
	SSL					*ssl = nil;
 | 
			
		||||
 | 
			
		||||
	char				tempString[256];
 | 
			
		||||
	UnsignedWide		microTickCount;
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
	CRandomizer randomizer;
 | 
			
		||||
	
 | 
			
		||||
	printf("OpenSSL Demo by Roy Wood, roy@centricsystems.ca\n\n");
 | 
			
		||||
	
 | 
			
		||||
	BailIfError(errCode = MacSocket_Startup());
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
	//	Create a socket-like object
 | 
			
		||||
	
 | 
			
		||||
	BailIfError(errCode = MacSocket_socket(&theSocket,false,theTimeout * 60,MyMacSocket_IdleWaitCallback,&randomizer));
 | 
			
		||||
 | 
			
		||||
	
 | 
			
		||||
	//	Set up the connect string and try to connect
 | 
			
		||||
	
 | 
			
		||||
	CopyCStrAndInsertCStrLongIntIntoCStr("%s:%ld",kHTTPS_DNS,kHTTPS_Port,tempString,sizeof(tempString));
 | 
			
		||||
	
 | 
			
		||||
	printf("Connecting to %s....\n",tempString);
 | 
			
		||||
 | 
			
		||||
	BailIfError(errCode = MacSocket_connect(theSocket,tempString));
 | 
			
		||||
	
 | 
			
		||||
	
 | 
			
		||||
	//	Init SSL stuff
 | 
			
		||||
	
 | 
			
		||||
	SSL_load_error_strings();
 | 
			
		||||
	
 | 
			
		||||
	SSLeay_add_ssl_algorithms();
 | 
			
		||||
	
 | 
			
		||||
	
 | 
			
		||||
	//	Pick the SSL method
 | 
			
		||||
	
 | 
			
		||||
//	ssl_ctx = SSL_CTX_new(SSLv2_client_method());
 | 
			
		||||
	ssl_ctx = SSL_CTX_new(SSLv23_client_method());
 | 
			
		||||
//	ssl_ctx = SSL_CTX_new(SSLv3_client_method());
 | 
			
		||||
			
 | 
			
		||||
 | 
			
		||||
	//	Create an SSL thingey and try to negotiate the connection
 | 
			
		||||
	
 | 
			
		||||
	ssl = SSL_new(ssl_ctx);
 | 
			
		||||
	
 | 
			
		||||
	SSL_set_fd(ssl,theSocket);
 | 
			
		||||
	
 | 
			
		||||
	errCode = SSL_connect(ssl);
 | 
			
		||||
	
 | 
			
		||||
	if (errCode < 0)
 | 
			
		||||
	{
 | 
			
		||||
		SetErrorMessageAndLongIntAndBail("OpenSSL: Can't initiate SSL connection, SSL_connect() = ",errCode);
 | 
			
		||||
	}
 | 
			
		||||
	
 | 
			
		||||
	//	Request the URI from the host
 | 
			
		||||
	
 | 
			
		||||
	CopyCStrToCStr("GET ",tempString,sizeof(tempString));
 | 
			
		||||
	ConcatCStrToCStr(kHTTPS_URI,tempString,sizeof(tempString));
 | 
			
		||||
	ConcatCStrToCStr(" HTTP/1.0\r\n\r\n",tempString,sizeof(tempString));
 | 
			
		||||
 | 
			
		||||
	
 | 
			
		||||
	errCode = SSL_write(ssl,tempString,CStrLength(tempString));
 | 
			
		||||
	
 | 
			
		||||
	if (errCode < 0)
 | 
			
		||||
	{
 | 
			
		||||
		SetErrorMessageAndLongIntAndBail("OpenSSL: Error writing data via ssl, SSL_write() = ",errCode);
 | 
			
		||||
	}
 | 
			
		||||
	
 | 
			
		||||
 | 
			
		||||
	for (;;)
 | 
			
		||||
	{
 | 
			
		||||
	char	tempString[256];
 | 
			
		||||
	int		bytesRead;
 | 
			
		||||
		
 | 
			
		||||
 | 
			
		||||
		//	Read some bytes and dump them to the console
 | 
			
		||||
		
 | 
			
		||||
		bytesRead = SSL_read(ssl,tempString,sizeof(tempString) - 1);
 | 
			
		||||
		
 | 
			
		||||
		if (bytesRead == 0 && MacSocket_RemoteEndIsClosing(theSocket))
 | 
			
		||||
		{
 | 
			
		||||
			break;
 | 
			
		||||
		}
 | 
			
		||||
		
 | 
			
		||||
		else if (bytesRead < 0)
 | 
			
		||||
		{
 | 
			
		||||
			SetErrorMessageAndLongIntAndBail("OpenSSL: Error reading data via ssl, SSL_read() = ",bytesRead);
 | 
			
		||||
		}
 | 
			
		||||
		
 | 
			
		||||
		
 | 
			
		||||
		tempString[bytesRead] = '\0';
 | 
			
		||||
		
 | 
			
		||||
		printf("%s", tempString);
 | 
			
		||||
	}
 | 
			
		||||
	
 | 
			
		||||
	printf("\n\n\n");
 | 
			
		||||
	
 | 
			
		||||
	//	All done!
 | 
			
		||||
	
 | 
			
		||||
	errCode = noErr;
 | 
			
		||||
	
 | 
			
		||||
	
 | 
			
		||||
EXITPOINT:
 | 
			
		||||
 | 
			
		||||
	//	Clean up and go home
 | 
			
		||||
	
 | 
			
		||||
	if (theSocket >= 0)
 | 
			
		||||
	{
 | 
			
		||||
		MacSocket_close(theSocket);
 | 
			
		||||
	}
 | 
			
		||||
	
 | 
			
		||||
	if (ssl != nil)
 | 
			
		||||
	{
 | 
			
		||||
		SSL_free(ssl);
 | 
			
		||||
	}
 | 
			
		||||
	
 | 
			
		||||
	if (ssl_ctx != nil)
 | 
			
		||||
	{
 | 
			
		||||
		SSL_CTX_free(ssl_ctx);
 | 
			
		||||
	}
 | 
			
		||||
	
 | 
			
		||||
	
 | 
			
		||||
	if (errCode != noErr)
 | 
			
		||||
	{
 | 
			
		||||
		printf("An error occurred:\n");
 | 
			
		||||
		
 | 
			
		||||
		printf("%s",GetErrorMessage());
 | 
			
		||||
	}
 | 
			
		||||
	
 | 
			
		||||
	
 | 
			
		||||
	MacSocket_Shutdown();
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										1607
									
								
								MacOS/GetHTTPS.src/MacSocket.cpp
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										1607
									
								
								MacOS/GetHTTPS.src/MacSocket.cpp
									
									
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										104
									
								
								MacOS/GetHTTPS.src/MacSocket.h
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										104
									
								
								MacOS/GetHTTPS.src/MacSocket.h
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,104 @@
 | 
			
		||||
#pragma once
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#ifdef __cplusplus
 | 
			
		||||
extern "C" {
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
enum {
 | 
			
		||||
    kMacSocket_TimeoutErr = -2
 | 
			
		||||
};
 | 
			
		||||
 | 
			
		||||
// Since MacSocket does busy waiting, I do a callback while waiting
 | 
			
		||||
 | 
			
		||||
typedef OSErr(*MacSocket_IdleWaitCallback) (void *);
 | 
			
		||||
 | 
			
		||||
// Call this before anything else!
 | 
			
		||||
 | 
			
		||||
OSErr MacSocket_Startup(void);
 | 
			
		||||
 | 
			
		||||
// Call this to cleanup before quitting
 | 
			
		||||
 | 
			
		||||
OSErr MacSocket_Shutdown(void);
 | 
			
		||||
 | 
			
		||||
// Call this to allocate a "socket" (reference number is returned in
 | 
			
		||||
// outSocketNum)
 | 
			
		||||
// Note that inDoThreadSwitching is pretty much irrelevant right now, since I
 | 
			
		||||
// ignore it
 | 
			
		||||
// The inTimeoutTicks parameter is applied during reads/writes of data
 | 
			
		||||
// The inIdleWaitCallback parameter specifies a callback which is called
 | 
			
		||||
// during busy-waiting periods
 | 
			
		||||
// The inUserRefPtr parameter is passed back to the idle-wait callback
 | 
			
		||||
 | 
			
		||||
OSErr MacSocket_socket(int *outSocketNum, const Boolean inDoThreadSwitching,
 | 
			
		||||
                       const long inTimeoutTicks,
 | 
			
		||||
                       MacSocket_IdleWaitCallback inIdleWaitCallback,
 | 
			
		||||
                       void *inUserRefPtr);
 | 
			
		||||
 | 
			
		||||
// Call this to connect to an IP/DNS address
 | 
			
		||||
// Note that inTargetAddressAndPort is in "IP:port" format-- e.g.
 | 
			
		||||
// 10.1.1.1:123
 | 
			
		||||
 | 
			
		||||
OSErr MacSocket_connect(const int inSocketNum, char *inTargetAddressAndPort);
 | 
			
		||||
 | 
			
		||||
// Call this to listen on a port
 | 
			
		||||
// Since this a low-performance implementation, I allow a maximum of 1 (one!)
 | 
			
		||||
// incoming request when I listen
 | 
			
		||||
 | 
			
		||||
OSErr MacSocket_listen(const int inSocketNum, const int inPortNum);
 | 
			
		||||
 | 
			
		||||
// Call this to close a socket
 | 
			
		||||
 | 
			
		||||
OSErr MacSocket_close(const int inSocketNum);
 | 
			
		||||
 | 
			
		||||
// Call this to receive data on a socket
 | 
			
		||||
// Most parameters' purpose are obvious-- except maybe "inBlock" which
 | 
			
		||||
// controls whether I wait for data or return immediately
 | 
			
		||||
 | 
			
		||||
int MacSocket_recv(const int inSocketNum, void *outBuff, int outBuffLength,
 | 
			
		||||
                   const Boolean inBlock);
 | 
			
		||||
 | 
			
		||||
// Call this to send data on a socket
 | 
			
		||||
 | 
			
		||||
int MacSocket_send(const int inSocketNum, const void *inBuff,
 | 
			
		||||
                   int inBuffLength);
 | 
			
		||||
 | 
			
		||||
// If zero bytes were read in a call to MacSocket_recv(), it may be that the
 | 
			
		||||
// remote end has done a half-close
 | 
			
		||||
// This function will let you check whether that's true or not
 | 
			
		||||
 | 
			
		||||
Boolean MacSocket_RemoteEndIsClosing(const int inSocketNum);
 | 
			
		||||
 | 
			
		||||
// Call this to see if the listen has completed after a call to
 | 
			
		||||
// MacSocket_listen()
 | 
			
		||||
 | 
			
		||||
Boolean MacSocket_ListenCompleted(const int inSocketNum);
 | 
			
		||||
 | 
			
		||||
// These really aren't very useful anymore
 | 
			
		||||
 | 
			
		||||
Boolean MacSocket_LocalEndIsOpen(const int inSocketNum);
 | 
			
		||||
Boolean MacSocket_RemoteEndIsOpen(const int inSocketNum);
 | 
			
		||||
 | 
			
		||||
// You may wish to change the userRefPtr for a socket callback-- use this to
 | 
			
		||||
// do it
 | 
			
		||||
 | 
			
		||||
void MacSocket_SetUserRefPtr(const int inSocketNum, void *inNewRefPtr);
 | 
			
		||||
 | 
			
		||||
// Call these to get the socket's IP:port descriptor
 | 
			
		||||
 | 
			
		||||
void MacSocket_GetLocalIPAndPort(const int inSocketNum, char *outIPAndPort,
 | 
			
		||||
                                 const int inIPAndPortLength);
 | 
			
		||||
void MacSocket_GetRemoteIPAndPort(const int inSocketNum, char *outIPAndPort,
 | 
			
		||||
                                  const int inIPAndPortLength);
 | 
			
		||||
 | 
			
		||||
// Call this to get error info from a socket
 | 
			
		||||
 | 
			
		||||
void MacSocket_GetSocketErrorInfo(const int inSocketNum,
 | 
			
		||||
                                  int *outSocketErrCode,
 | 
			
		||||
                                  char *outSocketErrString,
 | 
			
		||||
                                  const int inSocketErrStringMaxLength);
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
#ifdef __cplusplus
 | 
			
		||||
}
 | 
			
		||||
#endif
 | 
			
		||||
							
								
								
									
										4940
									
								
								MacOS/OpenSSL.mcp.hqx
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										4940
									
								
								MacOS/OpenSSL.mcp.hqx
									
									
									
									
									
										Normal file
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										476
									
								
								MacOS/Randomizer.cpp
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										476
									
								
								MacOS/Randomizer.cpp
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,476 @@
 | 
			
		||||
/* 
 | 
			
		||||
------- Strong random data generation on a Macintosh (pre - OS X) ------
 | 
			
		||||
		
 | 
			
		||||
--	GENERAL: We aim to generate unpredictable bits without explicit
 | 
			
		||||
	user interaction. A general review of the problem may be found
 | 
			
		||||
	in RFC 1750, "Randomness Recommendations for Security", and some
 | 
			
		||||
	more discussion, of general and Mac-specific issues has appeared
 | 
			
		||||
	in "Using and Creating Cryptographic- Quality Random Numbers" by
 | 
			
		||||
	Jon Callas (www.merrymeet.com/jon/usingrandom.html).
 | 
			
		||||
 | 
			
		||||
	The data and entropy estimates provided below are based on my
 | 
			
		||||
	limited experimentation and estimates, rather than by any
 | 
			
		||||
	rigorous study, and the entropy estimates tend to be optimistic.
 | 
			
		||||
	They should not be considered absolute.
 | 
			
		||||
 | 
			
		||||
	Some of the information being collected may be correlated in
 | 
			
		||||
	subtle ways. That includes mouse positions, timings, and disk
 | 
			
		||||
	size measurements. Some obvious correlations will be eliminated
 | 
			
		||||
	by the programmer, but other, weaker ones may remain. The
 | 
			
		||||
	reliability of the code depends on such correlations being
 | 
			
		||||
	poorly understood, both by us and by potential interceptors.
 | 
			
		||||
 | 
			
		||||
	This package has been planned to be used with OpenSSL, v. 0.9.5.
 | 
			
		||||
	It requires the OpenSSL function RAND_add. 
 | 
			
		||||
 | 
			
		||||
--	OTHER WORK: Some source code and other details have been
 | 
			
		||||
	published elsewhere, but I haven't found any to be satisfactory
 | 
			
		||||
	for the Mac per se:
 | 
			
		||||
 | 
			
		||||
	* The Linux random number generator (by Theodore Ts'o, in
 | 
			
		||||
	  drivers/char/random.c), is a carefully designed open-source
 | 
			
		||||
	  crypto random number package. It collects data from a variety
 | 
			
		||||
	  of sources, including mouse, keyboard and other interrupts.
 | 
			
		||||
	  One nice feature is that it explicitly estimates the entropy
 | 
			
		||||
	  of the data it collects. Some of its features (e.g. interrupt
 | 
			
		||||
	  timing) cannot be reliably exported to the Mac without using
 | 
			
		||||
	  undocumented APIs.
 | 
			
		||||
 | 
			
		||||
	* Truerand by Don P. Mitchell and Matt Blaze uses variations
 | 
			
		||||
	  between different timing mechanisms on the same system. This
 | 
			
		||||
	  has not been tested on the Mac, but requires preemptive
 | 
			
		||||
	  multitasking, and is hardware-dependent, and can't be relied
 | 
			
		||||
	  on to work well if only one oscillator is present.
 | 
			
		||||
 | 
			
		||||
	* Cryptlib's RNG for the Mac (RNDMAC.C by Peter Gutmann),
 | 
			
		||||
	  gathers a lot of information about the machine and system
 | 
			
		||||
	  environment. Unfortunately, much of it is constant from one
 | 
			
		||||
	  startup to the next. In other words, the random seed could be
 | 
			
		||||
	  the same from one day to the next. Some of the APIs are
 | 
			
		||||
	  hardware-dependent, and not all are compatible with Carbon (OS
 | 
			
		||||
	  X). Incidentally, the EGD library is based on the UNIX entropy
 | 
			
		||||
	  gathering methods in cryptlib, and isn't suitable for MacOS
 | 
			
		||||
	  either.
 | 
			
		||||
 | 
			
		||||
	* Mozilla (and perhaps earlier versions of Netscape) uses the
 | 
			
		||||
	  time of day (in seconds) and an uninitialized local variable
 | 
			
		||||
	  to seed the random number generator. The time of day is known
 | 
			
		||||
	  to an outside interceptor (to within the accuracy of the
 | 
			
		||||
	  system clock). The uninitialized variable could easily be
 | 
			
		||||
	  identical between subsequent launches of an application, if it
 | 
			
		||||
	  is reached through the same path.
 | 
			
		||||
 | 
			
		||||
	* OpenSSL provides the function RAND_screen(), by G. van
 | 
			
		||||
	  Oosten, which hashes the contents of the screen to generate a
 | 
			
		||||
	  seed. This is not useful for an extension or for an
 | 
			
		||||
	  application which launches at startup time, since the screen
 | 
			
		||||
	  is likely to look identical from one launch to the next. This
 | 
			
		||||
	  method is also rather slow.
 | 
			
		||||
 | 
			
		||||
	* Using variations in disk drive seek times has been proposed
 | 
			
		||||
	  (Davis, Ihaka and Fenstermacher, world.std.com/~dtd/;
 | 
			
		||||
	  Jakobsson, Shriver, Hillyer and Juels,
 | 
			
		||||
	  www.bell-labs.com/user/shriver/random.html). These variations
 | 
			
		||||
	  appear to be due to air turbulence inside the disk drive
 | 
			
		||||
	  mechanism, and are very strongly unpredictable. Unfortunately
 | 
			
		||||
	  this technique is slow, and some implementations of it may be
 | 
			
		||||
	  patented (see Shriver's page above.) It of course cannot be
 | 
			
		||||
	  used with a RAM disk.
 | 
			
		||||
 | 
			
		||||
--	TIMING: On the 601 PowerPC the time base register is guaranteed
 | 
			
		||||
	to change at least once every 10 addi instructions, i.e. 10
 | 
			
		||||
	cycles. On a 60 MHz machine (slowest PowerPC) this translates to
 | 
			
		||||
	a resolution of 1/6 usec. Newer machines seem to be using a 10
 | 
			
		||||
	cycle resolution as well.
 | 
			
		||||
	
 | 
			
		||||
	For 68K Macs, the Microseconds() call may be used. See Develop
 | 
			
		||||
	issue 29 on the Apple developer site
 | 
			
		||||
	(developer.apple.com/dev/techsupport/develop/issue29/minow.html)
 | 
			
		||||
	for information on its accuracy and resolution. The code below
 | 
			
		||||
	has been tested only on PowerPC based machines.
 | 
			
		||||
 | 
			
		||||
	The time from machine startup to the launch of an application in
 | 
			
		||||
	the startup folder has a variance of about 1.6 msec on a new G4
 | 
			
		||||
	machine with a defragmented and optimized disk, most extensions
 | 
			
		||||
	off and no icons on the desktop. This can be reasonably taken as
 | 
			
		||||
	a lower bound on the variance. Most of this variation is likely
 | 
			
		||||
	due to disk seek time variability. The distribution of startup
 | 
			
		||||
	times is probably not entirely even or uncorrelated. This needs
 | 
			
		||||
	to be investigated, but I am guessing that it not a majpor
 | 
			
		||||
	problem. Entropy = log2 (1600/0.166) ~= 13 bits on a 60 MHz
 | 
			
		||||
	machine, ~16 bits for a 450 MHz machine.
 | 
			
		||||
 | 
			
		||||
	User-launched application startup times will have a variance of
 | 
			
		||||
	a second or more relative to machine startup time. Entropy >~22
 | 
			
		||||
	bits.
 | 
			
		||||
 | 
			
		||||
	Machine startup time is available with a 1-second resolution. It
 | 
			
		||||
	is predictable to no better a minute or two, in the case of
 | 
			
		||||
	people who show up punctually to work at the same time and
 | 
			
		||||
	immediately start their computer. Using the scheduled startup
 | 
			
		||||
	feature (when available) will cause the machine to start up at
 | 
			
		||||
	the same time every day, making the value predictable. Entropy
 | 
			
		||||
	>~7 bits, or 0 bits with scheduled startup.
 | 
			
		||||
 | 
			
		||||
	The time of day is of course known to an outsider and thus has 0
 | 
			
		||||
	entropy if the system clock is regularly calibrated.
 | 
			
		||||
 | 
			
		||||
--	KEY TIMING: A  very fast typist (120 wpm) will have a typical
 | 
			
		||||
	inter-key timing interval of 100 msec. We can assume a variance
 | 
			
		||||
	of no less than 2 msec -- maybe. Do good typists have a constant
 | 
			
		||||
	rhythm, like drummers? Since what we measure is not the
 | 
			
		||||
	key-generated interrupt but the time at which the key event was
 | 
			
		||||
	taken off the event queue, our resolution is roughly the time
 | 
			
		||||
	between process switches, at best 1 tick (17 msec). I  therefore
 | 
			
		||||
	consider this technique questionable and not very useful for
 | 
			
		||||
	obtaining high entropy data on the Mac.
 | 
			
		||||
 | 
			
		||||
--	MOUSE POSITION AND TIMING: The high bits of the mouse position
 | 
			
		||||
	are far from arbitrary, since the mouse tends to stay in a few
 | 
			
		||||
	limited areas of the screen. I am guessing that the position of
 | 
			
		||||
	the mouse is arbitrary within a 6 pixel square. Since the mouse
 | 
			
		||||
	stays still for long periods of time, it should be sampled only
 | 
			
		||||
	after it was moved, to avoid correlated data. This gives an
 | 
			
		||||
	entropy of log2(6*6) ~= 5 bits per measurement.
 | 
			
		||||
 | 
			
		||||
	The time during which the mouse stays still can vary from zero
 | 
			
		||||
	to, say, 5 seconds (occasionally longer). If the still time is
 | 
			
		||||
	measured by sampling the mouse during null events, and null
 | 
			
		||||
	events are received once per tick, its resolution is 1/60th of a
 | 
			
		||||
	second, giving an entropy of log2 (60*5) ~= 8 bits per
 | 
			
		||||
	measurement. Since the distribution of still times is uneven,
 | 
			
		||||
	this estimate is on the high side.
 | 
			
		||||
 | 
			
		||||
	For simplicity and compatibility across system versions, the
 | 
			
		||||
	mouse is to be sampled explicitly (e.g. in the event loop),
 | 
			
		||||
	rather than in a time manager task.
 | 
			
		||||
 | 
			
		||||
--	STARTUP DISK TOTAL FILE SIZE: Varies typically by at least 20k
 | 
			
		||||
	from one startup to the next, with 'minimal' computer use. Won't
 | 
			
		||||
	vary at all if machine is started again immediately after
 | 
			
		||||
	startup (unless virtual memory is on), but any application which
 | 
			
		||||
	uses the web and caches information to disk is likely to cause
 | 
			
		||||
	this much variation or more. The variation is probably not
 | 
			
		||||
	random, but I don't know in what way. File sizes tend to be
 | 
			
		||||
	divisible by 4 bytes since file format fields are often
 | 
			
		||||
	long-aligned. Entropy > log2 (20000/4) ~= 12 bits.
 | 
			
		||||
	
 | 
			
		||||
--	STARTUP DISK FIRST AVAILABLE ALLOCATION BLOCK: As the volume
 | 
			
		||||
	gets fragmented this could be anywhere in principle. In a
 | 
			
		||||
	perfectly unfragmented volume this will be strongly correlated
 | 
			
		||||
	with the total file size on the disk. With more fragmentation
 | 
			
		||||
	comes less certainty. I took the variation in this value to be
 | 
			
		||||
	1/8 of the total file size on the volume.
 | 
			
		||||
 | 
			
		||||
--	SYSTEM REQUIREMENTS: The code here requires System 7.0 and above
 | 
			
		||||
	(for Gestalt and Microseconds calls). All the calls used are
 | 
			
		||||
	Carbon-compatible.
 | 
			
		||||
*/
 | 
			
		||||
 | 
			
		||||
/*------------------------------ Includes ----------------------------*/
 | 
			
		||||
 | 
			
		||||
#include "Randomizer.h"
 | 
			
		||||
 | 
			
		||||
// Mac OS API
 | 
			
		||||
#include <Files.h>
 | 
			
		||||
#include <Folders.h>
 | 
			
		||||
#include <Events.h>
 | 
			
		||||
#include <Processes.h>
 | 
			
		||||
#include <Gestalt.h>
 | 
			
		||||
#include <Resources.h>
 | 
			
		||||
#include <LowMem.h>
 | 
			
		||||
 | 
			
		||||
// Standard C library
 | 
			
		||||
#include <stdlib.h>
 | 
			
		||||
#include <math.h>
 | 
			
		||||
 | 
			
		||||
/*---------------------- Function declarations -----------------------*/
 | 
			
		||||
 | 
			
		||||
// declared in OpenSSL/crypto/rand/rand.h
 | 
			
		||||
extern "C" void RAND_add (const void *buf, int num, double entropy);
 | 
			
		||||
 | 
			
		||||
unsigned long GetPPCTimer (bool is601);	// Make it global if needed
 | 
			
		||||
					// elsewhere
 | 
			
		||||
 | 
			
		||||
/*---------------------------- Constants -----------------------------*/
 | 
			
		||||
 | 
			
		||||
#define kMouseResolution 6		// Mouse position has to differ
 | 
			
		||||
					// from the last one by this
 | 
			
		||||
					// much to be entered
 | 
			
		||||
#define kMousePositionEntropy 5.16	// log2 (kMouseResolution**2)
 | 
			
		||||
#define kTypicalMouseIdleTicks 300.0	// I am guessing that a typical
 | 
			
		||||
					// amount of time between mouse
 | 
			
		||||
					// moves is 5 seconds
 | 
			
		||||
#define kVolumeBytesEntropy 12.0	// about log2 (20000/4),
 | 
			
		||||
					// assuming a variation of 20K
 | 
			
		||||
					// in total file size and
 | 
			
		||||
					// long-aligned file formats.
 | 
			
		||||
#define kApplicationUpTimeEntropy 6.0	// Variance > 1 second, uptime
 | 
			
		||||
					// in ticks  
 | 
			
		||||
#define kSysStartupEntropy 7.0		// Entropy for machine startup
 | 
			
		||||
					// time
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
/*------------------------ Function definitions ----------------------*/
 | 
			
		||||
 | 
			
		||||
CRandomizer::CRandomizer (void)
 | 
			
		||||
{
 | 
			
		||||
	long	result;
 | 
			
		||||
	
 | 
			
		||||
	mSupportsLargeVolumes =
 | 
			
		||||
		(Gestalt(gestaltFSAttr, &result) == noErr) &&
 | 
			
		||||
		((result & (1L << gestaltFSSupports2TBVols)) != 0);
 | 
			
		||||
	
 | 
			
		||||
	if (Gestalt (gestaltNativeCPUtype, &result) != noErr)
 | 
			
		||||
	{
 | 
			
		||||
		mIsPowerPC = false;
 | 
			
		||||
		mIs601 = false;
 | 
			
		||||
	}
 | 
			
		||||
	else
 | 
			
		||||
	{
 | 
			
		||||
		mIs601 = (result == gestaltCPU601);
 | 
			
		||||
		mIsPowerPC = (result >= gestaltCPU601);
 | 
			
		||||
	}
 | 
			
		||||
	mLastMouse.h = mLastMouse.v = -10;	// First mouse will
 | 
			
		||||
						// always be recorded
 | 
			
		||||
	mLastPeriodicTicks = TickCount();
 | 
			
		||||
	GetTimeBaseResolution ();
 | 
			
		||||
	
 | 
			
		||||
	// Add initial entropy
 | 
			
		||||
	AddTimeSinceMachineStartup ();
 | 
			
		||||
	AddAbsoluteSystemStartupTime ();
 | 
			
		||||
	AddStartupVolumeInfo ();
 | 
			
		||||
	AddFiller ();
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void CRandomizer::PeriodicAction (void)
 | 
			
		||||
{
 | 
			
		||||
	AddCurrentMouse ();
 | 
			
		||||
	AddNow (0.0);	// Should have a better entropy estimate here
 | 
			
		||||
	mLastPeriodicTicks = TickCount();
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
/*------------------------- Private Methods --------------------------*/
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddCurrentMouse (void)
 | 
			
		||||
{
 | 
			
		||||
	Point mouseLoc;
 | 
			
		||||
	unsigned long lastCheck;	// Ticks since mouse was last
 | 
			
		||||
					// sampled
 | 
			
		||||
 | 
			
		||||
#if TARGET_API_MAC_CARBON
 | 
			
		||||
	GetGlobalMouse (&mouseLoc);
 | 
			
		||||
#else
 | 
			
		||||
	mouseLoc = LMGetMouseLocation();
 | 
			
		||||
#endif
 | 
			
		||||
	
 | 
			
		||||
	if (labs (mLastMouse.h - mouseLoc.h) > kMouseResolution/2 &&
 | 
			
		||||
	    labs (mLastMouse.v - mouseLoc.v) > kMouseResolution/2)
 | 
			
		||||
		AddBytes (&mouseLoc, sizeof (mouseLoc),
 | 
			
		||||
				kMousePositionEntropy);
 | 
			
		||||
	
 | 
			
		||||
	if (mLastMouse.h == mouseLoc.h && mLastMouse.v == mouseLoc.v)
 | 
			
		||||
		mMouseStill ++;
 | 
			
		||||
	else
 | 
			
		||||
	{
 | 
			
		||||
		double entropy;
 | 
			
		||||
		
 | 
			
		||||
		// Mouse has moved. Add the number of measurements for
 | 
			
		||||
		// which it's been still. If the resolution is too
 | 
			
		||||
		// coarse, assume the entropy is 0.
 | 
			
		||||
 | 
			
		||||
		lastCheck = TickCount() - mLastPeriodicTicks;
 | 
			
		||||
		if (lastCheck <= 0)
 | 
			
		||||
			lastCheck = 1;
 | 
			
		||||
		entropy = log2l
 | 
			
		||||
			(kTypicalMouseIdleTicks/(double)lastCheck);
 | 
			
		||||
		if (entropy < 0.0)
 | 
			
		||||
			entropy = 0.0;
 | 
			
		||||
		AddBytes (&mMouseStill, sizeof (mMouseStill), entropy);
 | 
			
		||||
		mMouseStill = 0;
 | 
			
		||||
	}
 | 
			
		||||
	mLastMouse = mouseLoc;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddAbsoluteSystemStartupTime (void)
 | 
			
		||||
{
 | 
			
		||||
	unsigned long	now;		// Time in seconds since
 | 
			
		||||
					// 1/1/1904
 | 
			
		||||
	GetDateTime (&now);
 | 
			
		||||
	now -= TickCount() / 60;	// Time in ticks since machine
 | 
			
		||||
					// startup
 | 
			
		||||
	AddBytes (&now, sizeof (now), kSysStartupEntropy);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddTimeSinceMachineStartup (void)
 | 
			
		||||
{
 | 
			
		||||
	AddNow (1.5);			// Uncertainty in app startup
 | 
			
		||||
					// time is > 1.5 msec (for
 | 
			
		||||
					// automated app startup).
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddAppRunningTime (void)
 | 
			
		||||
{
 | 
			
		||||
	ProcessSerialNumber PSN;
 | 
			
		||||
	ProcessInfoRec		ProcessInfo;
 | 
			
		||||
	
 | 
			
		||||
	ProcessInfo.processInfoLength = sizeof (ProcessInfoRec);
 | 
			
		||||
	ProcessInfo.processName = nil;
 | 
			
		||||
	ProcessInfo.processAppSpec = nil;
 | 
			
		||||
	
 | 
			
		||||
	GetCurrentProcess (&PSN);
 | 
			
		||||
	GetProcessInformation (&PSN, &ProcessInfo);
 | 
			
		||||
 | 
			
		||||
	// Now add the amount of time in ticks that the current process
 | 
			
		||||
	// has been active
 | 
			
		||||
 | 
			
		||||
	AddBytes (&ProcessInfo, sizeof (ProcessInfoRec),
 | 
			
		||||
			kApplicationUpTimeEntropy);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddStartupVolumeInfo (void)
 | 
			
		||||
{
 | 
			
		||||
	short			vRefNum;
 | 
			
		||||
	long			dirID;
 | 
			
		||||
	XVolumeParam	pb;
 | 
			
		||||
	OSErr			err;
 | 
			
		||||
	
 | 
			
		||||
	if (!mSupportsLargeVolumes)
 | 
			
		||||
		return;
 | 
			
		||||
		
 | 
			
		||||
	FindFolder (kOnSystemDisk, kSystemFolderType, kDontCreateFolder,
 | 
			
		||||
			&vRefNum, &dirID);
 | 
			
		||||
	pb.ioVRefNum = vRefNum;
 | 
			
		||||
	pb.ioCompletion = 0;
 | 
			
		||||
	pb.ioNamePtr = 0;
 | 
			
		||||
	pb.ioVolIndex = 0;
 | 
			
		||||
	err = PBXGetVolInfoSync (&pb);
 | 
			
		||||
	if (err != noErr)
 | 
			
		||||
		return;
 | 
			
		||||
		
 | 
			
		||||
	// Base the entropy on the amount of space used on the disk and
 | 
			
		||||
	// on the next available allocation block. A lot else might be
 | 
			
		||||
	// unpredictable, so might as well toss the whole block in. See
 | 
			
		||||
	// comments for entropy estimate justifications.
 | 
			
		||||
 | 
			
		||||
	AddBytes (&pb, sizeof (pb),
 | 
			
		||||
		kVolumeBytesEntropy +
 | 
			
		||||
		log2l (((pb.ioVTotalBytes.hi - pb.ioVFreeBytes.hi)
 | 
			
		||||
				* 4294967296.0D +
 | 
			
		||||
			(pb.ioVTotalBytes.lo - pb.ioVFreeBytes.lo))
 | 
			
		||||
				/ pb.ioVAlBlkSiz - 3.0));
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
	On a typical startup CRandomizer will come up with about 60
 | 
			
		||||
	bits of good, unpredictable data. Assuming no more input will
 | 
			
		||||
	be available, we'll need some more lower-quality data to give
 | 
			
		||||
	OpenSSL the 128 bits of entropy it desires. AddFiller adds some
 | 
			
		||||
	relatively predictable data into the soup.
 | 
			
		||||
*/
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddFiller (void)
 | 
			
		||||
{
 | 
			
		||||
	struct
 | 
			
		||||
	{
 | 
			
		||||
		ProcessSerialNumber psn;	// Front process serial
 | 
			
		||||
						// number
 | 
			
		||||
		RGBColor	hiliteRGBValue;	// User-selected
 | 
			
		||||
						// highlight color
 | 
			
		||||
		long		processCount;	// Number of active
 | 
			
		||||
						// processes
 | 
			
		||||
		long		cpuSpeed;	// Processor speed
 | 
			
		||||
		long		totalMemory;	// Total logical memory
 | 
			
		||||
						// (incl. virtual one)
 | 
			
		||||
		long		systemVersion;	// OS version
 | 
			
		||||
		short		resFile;	// Current resource file
 | 
			
		||||
	} data;
 | 
			
		||||
	
 | 
			
		||||
	GetNextProcess ((ProcessSerialNumber*) kNoProcess);
 | 
			
		||||
	while (GetNextProcess (&data.psn) == noErr)
 | 
			
		||||
		data.processCount++;
 | 
			
		||||
	GetFrontProcess (&data.psn);
 | 
			
		||||
	LMGetHiliteRGB (&data.hiliteRGBValue);
 | 
			
		||||
	Gestalt (gestaltProcClkSpeed, &data.cpuSpeed);
 | 
			
		||||
	Gestalt (gestaltLogicalRAMSize, &data.totalMemory);
 | 
			
		||||
	Gestalt (gestaltSystemVersion, &data.systemVersion);
 | 
			
		||||
	data.resFile = CurResFile ();
 | 
			
		||||
	
 | 
			
		||||
	// Here we pretend to feed the PRNG completely random data. This
 | 
			
		||||
	// is of course false, as much of the above data is predictable
 | 
			
		||||
	// by an outsider. At this point we don't have any more
 | 
			
		||||
	// randomness to add, but with OpenSSL we must have a 128 bit
 | 
			
		||||
	// seed before we can start. We just add what we can, without a
 | 
			
		||||
	// real entropy estimate, and hope for the best.
 | 
			
		||||
 | 
			
		||||
	AddBytes (&data, sizeof(data), 8.0 * sizeof(data));
 | 
			
		||||
	AddCurrentMouse ();
 | 
			
		||||
	AddNow (1.0);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
//-------------------  LOW LEVEL ---------------------
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddBytes (void *data, long size, double entropy)
 | 
			
		||||
{
 | 
			
		||||
	RAND_add (data, size, entropy * 0.125);	// Convert entropy bits
 | 
			
		||||
						// to bytes
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
void CRandomizer::AddNow (double millisecondUncertainty)
 | 
			
		||||
{
 | 
			
		||||
	long time = SysTimer();
 | 
			
		||||
	AddBytes (&time, sizeof (time), log2l (millisecondUncertainty *
 | 
			
		||||
			mTimebaseTicksPerMillisec));
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
//----------------- TIMING SUPPORT ------------------
 | 
			
		||||
 | 
			
		||||
void CRandomizer::GetTimeBaseResolution (void)
 | 
			
		||||
{	
 | 
			
		||||
#ifdef __powerc
 | 
			
		||||
	long speed;
 | 
			
		||||
	
 | 
			
		||||
	// gestaltProcClkSpeed available on System 7.5.2 and above
 | 
			
		||||
	if (Gestalt (gestaltProcClkSpeed, &speed) != noErr)
 | 
			
		||||
		// Only PowerPCs running pre-7.5.2 are 60-80 MHz
 | 
			
		||||
		// machines.
 | 
			
		||||
		mTimebaseTicksPerMillisec =  6000.0D;
 | 
			
		||||
	// Assume 10 cycles per clock update, as in 601 spec. Seems true
 | 
			
		||||
	// for later chips as well.
 | 
			
		||||
	mTimebaseTicksPerMillisec = speed / 1.0e4D;
 | 
			
		||||
#else
 | 
			
		||||
	// 68K VIA-based machines (see Develop Magazine no. 29)
 | 
			
		||||
	mTimebaseTicksPerMillisec = 783.360D;
 | 
			
		||||
#endif
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
unsigned long CRandomizer::SysTimer (void)	// returns the lower 32
 | 
			
		||||
						// bit of the chip timer
 | 
			
		||||
{
 | 
			
		||||
#ifdef __powerc
 | 
			
		||||
	return GetPPCTimer (mIs601);
 | 
			
		||||
#else
 | 
			
		||||
	UnsignedWide usec;
 | 
			
		||||
	Microseconds (&usec);
 | 
			
		||||
	return usec.lo;
 | 
			
		||||
#endif
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#ifdef __powerc
 | 
			
		||||
// The timebase is available through mfspr on 601, mftb on later chips.
 | 
			
		||||
// Motorola recommends that an 601 implementation map mftb to mfspr
 | 
			
		||||
// through an exception, but I haven't tested to see if MacOS actually
 | 
			
		||||
// does this. We only sample the lower 32 bits of the timer (i.e. a
 | 
			
		||||
// few minutes of resolution)
 | 
			
		||||
 | 
			
		||||
asm unsigned long GetPPCTimer (register bool is601)
 | 
			
		||||
{
 | 
			
		||||
	cmplwi	is601, 0	// Check if 601
 | 
			
		||||
	bne	_601		// if non-zero goto _601
 | 
			
		||||
	mftb  	r3		// Available on 603 and later.
 | 
			
		||||
	blr			// return with result in r3
 | 
			
		||||
_601:
 | 
			
		||||
	mfspr r3, spr5  	// Available on 601 only.
 | 
			
		||||
				// blr inserted automatically
 | 
			
		||||
}
 | 
			
		||||
#endif
 | 
			
		||||
							
								
								
									
										42
									
								
								MacOS/Randomizer.h
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										42
									
								
								MacOS/Randomizer.h
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,42 @@
 | 
			
		||||
 | 
			
		||||
// Gathers unpredictable system data to be used for generating
 | 
			
		||||
// random bits
 | 
			
		||||
 | 
			
		||||
#include <MacTypes.h>
 | 
			
		||||
 | 
			
		||||
class CRandomizer {
 | 
			
		||||
 public:
 | 
			
		||||
    CRandomizer(void);
 | 
			
		||||
    void PeriodicAction(void);
 | 
			
		||||
 | 
			
		||||
 private:
 | 
			
		||||
 | 
			
		||||
    // Private calls
 | 
			
		||||
 | 
			
		||||
    void AddTimeSinceMachineStartup(void);
 | 
			
		||||
    void AddAbsoluteSystemStartupTime(void);
 | 
			
		||||
    void AddAppRunningTime(void);
 | 
			
		||||
    void AddStartupVolumeInfo(void);
 | 
			
		||||
    void AddFiller(void);
 | 
			
		||||
 | 
			
		||||
    void AddCurrentMouse(void);
 | 
			
		||||
    void AddNow(double millisecondUncertainty);
 | 
			
		||||
    void AddBytes(void *data, long size, double entropy);
 | 
			
		||||
 | 
			
		||||
    void GetTimeBaseResolution(void);
 | 
			
		||||
    unsigned long SysTimer(void);
 | 
			
		||||
 | 
			
		||||
    // System Info
 | 
			
		||||
    bool mSupportsLargeVolumes;
 | 
			
		||||
    bool mIsPowerPC;
 | 
			
		||||
    bool mIs601;
 | 
			
		||||
 | 
			
		||||
    // Time info
 | 
			
		||||
    double mTimebaseTicksPerMillisec;
 | 
			
		||||
    unsigned long mLastPeriodicTicks;
 | 
			
		||||
 | 
			
		||||
    // Mouse info
 | 
			
		||||
    long mSamplePeriod;
 | 
			
		||||
    Point mLastMouse;
 | 
			
		||||
    long mMouseStill;
 | 
			
		||||
};
 | 
			
		||||
							
								
								
									
										18
									
								
								MacOS/TODO
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										18
									
								
								MacOS/TODO
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,18 @@
 | 
			
		||||
-------------------------------------------------------------------
 | 
			
		||||
Verify server certificate
 | 
			
		||||
-------------------------------------------------------------------
 | 
			
		||||
Currently omitted from the project:
 | 
			
		||||
 | 
			
		||||
	crypto/tmdiff.c
 | 
			
		||||
	crypto/bio/bss_conn.c
 | 
			
		||||
	crypto/bio/b_sock.c
 | 
			
		||||
	crypto/bio/bss_acpt.c
 | 
			
		||||
	crypto/bio/bss_log.h
 | 
			
		||||
 | 
			
		||||
-------------------------------------------------------------------
 | 
			
		||||
Build libraries to link with...
 | 
			
		||||
-------------------------------------------------------------------
 | 
			
		||||
Port openssl application.
 | 
			
		||||
-------------------------------------------------------------------
 | 
			
		||||
BN optimizations (currently PPC version is compiled with BN_LLONG)
 | 
			
		||||
-------------------------------------------------------------------
 | 
			
		||||
							
								
								
									
										9
									
								
								MacOS/_MWERKS_GUSI_prefix.h
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										9
									
								
								MacOS/_MWERKS_GUSI_prefix.h
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,9 @@
 | 
			
		||||
#include <MacHeaders.h>
 | 
			
		||||
#define B_ENDIAN
 | 
			
		||||
#ifdef __POWERPC__
 | 
			
		||||
# pragma longlong on
 | 
			
		||||
#endif
 | 
			
		||||
#if 1
 | 
			
		||||
# define MAC_OS_GUSI_SOURCE
 | 
			
		||||
#endif
 | 
			
		||||
#define MONOLITH
 | 
			
		||||
							
								
								
									
										9
									
								
								MacOS/_MWERKS_prefix.h
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										9
									
								
								MacOS/_MWERKS_prefix.h
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,9 @@
 | 
			
		||||
#include <MacHeaders.h>
 | 
			
		||||
#define B_ENDIAN
 | 
			
		||||
#ifdef __POWERPC__
 | 
			
		||||
# pragma longlong on
 | 
			
		||||
#endif
 | 
			
		||||
#if 0
 | 
			
		||||
# define MAC_OS_GUSI_SOURCE
 | 
			
		||||
#endif
 | 
			
		||||
#define MONOLITH
 | 
			
		||||
							
								
								
									
										5
									
								
								MacOS/buildinf.h
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										5
									
								
								MacOS/buildinf.h
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,5 @@
 | 
			
		||||
#ifndef MK1MF_BUILD
 | 
			
		||||
# define CFLAGS        "-DB_ENDIAN"
 | 
			
		||||
# define PLATFORM      "macos"
 | 
			
		||||
# define DATE          "Sun Feb 27 19:44:16 MET 2000"
 | 
			
		||||
#endif
 | 
			
		||||
							
								
								
									
										820
									
								
								MacOS/mklinks.as.hqx
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										820
									
								
								MacOS/mklinks.as.hqx
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,820 @@
 | 
			
		||||
(This file must be converted with BinHex 4.0)
 | 
			
		||||
 | 
			
		||||
:#QeVE'PZDh-ZBA-!39"36'&`E(3J!!!!!!!!!*LiI6m!!!!!!3!!!*G#!!#@3J!
 | 
			
		||||
!!AChFQPd!!!!K3)"!3m(Fh9`F'pbG!!!!)B#!3%$"(0eFQ8!!!#(!J-%"!3("3C
 | 
			
		||||
cGfPdBfJ!!!#)!J%"#39cH@jMD!!!!)N#"J%$!`-&"3-'FhPcG'9Y!!!!LJ)&"3)
 | 
			
		||||
%!J8("!-#!`4dB@*X!!!!L`))!3-$!`-$!`-$"(4PE'`!!!#-!J)"#38$G'KP!!!
 | 
			
		||||
!M3))(J)@!Ki#!J))!K)#!`)B!Kd%G'KPE3!!!)i#!J%&#`4dD'9j!!!!M`)#!J)
 | 
			
		||||
#$3TdD(*[G@GSEh9d!!!!N!!#!3%&"(4TCQB!!!#4!J%"!`4dD@eP!!!!NJ)"!JS
 | 
			
		||||
#!h4T!!!!'N!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!H!!!!!!!#!!!!!!
 | 
			
		||||
!!!!!!!!!!!!!rrrrr`!!!$3!!!!N!!!!!#"[!!5JAb"[!!5K++!M6R9$9'mJFR9
 | 
			
		||||
Z)(4SDA-JFf0bDA"d)'&`F'aTBf&dD@pZ,#"jEh8JEA9cG#"QDA*cG#"TER0dB@a
 | 
			
		||||
X)%&`F'aP8f0bDA"d,J!!!)C8D'Pc)(0MFQP`G#"MFQ9KG'9c)#iZ,fPZBfaeC'8
 | 
			
		||||
[Eh"PER0cE#"KEQ3JCQPXE(-JDA3JGfPdD#"ZC@0PFh0KFRNJB@aTBA0PFbi0$8P
 | 
			
		||||
d)'eTCfKd)(4KDf8JB5"hD'PXC5"dEb"MEfe`E'9dC5"cEb"`E'9KFf8JBQ8JF'&
 | 
			
		||||
dD@9ZG$SY+3!!!#S!!J!!!!!!$3!+!"!!!!!-!!!!!!!!!!!!63!0!!S!%!%!!!`
 | 
			
		||||
!!!!!!!!!!!!B!!!!+!!!!!!!!!!)!!!!)!#N2c`!!DR`!!!!l!!!!!&19[ri,`0
 | 
			
		||||
f!#m$-$bKVDG'*KmY52ri,`-`2+LITdBQ(b!ZrrLa`'FJ,`-J2'0`ER4"l[rm)NL
 | 
			
		||||
KV5+)*Kp+3'B)5Ulrr'F#GJ%3!bBZrr41ANje6PB!!#m-@Bm[2%j29%Nr2!#!U"m
 | 
			
		||||
SAb!-CJK`!cm!UFKJ+#m-UC)J9#!)d+J!'#&!!"JJ9#!)d+J!(#&!!"a9Mbm8)&q
 | 
			
		||||
JAMk!9%mSE[rm6Pj1G8j@!!![$%kkre4+!'FU@Bm[2'&`E(3[2(0MF(4`)DJU+&m
 | 
			
		||||
J$'F5@Bm[$#mm!!!!!A!!U#UTp&K26VVrG#KZrra1ANje!!!!('&`E(3!!!!"4P*
 | 
			
		||||
&4J!!!!!!J%P$6L-!!!!!!*B!!!!"!!!!!!G"8&"-!!!!!!!"!!!"!!!!!S!!!!4
 | 
			
		||||
!!!"i)!!!K"!!!3))!!)#"!!%"!)!#!J"!"!8!)!J)J"!3%%!)2#!J"#*!%!)KJ!
 | 
			
		||||
J")3!)!*!!"!")!!3!K!!%!3)!"!)"!!J%!)!3#!"!)"!!S%!J!5#!3!)4!)!#%J
 | 
			
		||||
%!!KB#!!%C"!!!m)J!!!"3!!!!)!!!!%!!!!$J!!!"m!!!(rJ!!$rm!!"rrJ!!rr
 | 
			
		||||
m!!IrrJ!2rrm!(rrrJ$rrrm"rrrrJrrrrm2rrrrMrrrrmrrrrrRrrrrmrrrrq(rr
 | 
			
		||||
rr!rrrrJ(rrr`!rrri!(rrm!$rrq!"rrr!!rrrJ!2rr`!$rri!!IRm!!$`q!!!!(
 | 
			
		||||
!!!!!J!!!!!)!!!!!!!!!!!m!!!!!!!!!!!!!!!!!!!$`m!!!!!!!!!!!!!!!!!!
 | 
			
		||||
2!!m!!!!!!!!!!!!!!!rrm!!!m!!!!!!!!!!!!!$`c0m!!!m!!!!!!!!!!!!2!!c
 | 
			
		||||
-m!!!m!!!!!!!!!!!m!$-cI!!!!m!!!!!!!!!$`!-c0m!!!!!m!!!!!!!!2!!c-h
 | 
			
		||||
`!!!!!!m!!!!!!!m!$-cIh`!!!!!!m!!!!!$`!-c0rGh`!!!!!!m!!!!2!!c-hph
 | 
			
		||||
-h`!!!!!!m!!!rrr-cIhF`-h`!!!!!!m!!2lFr0rGc!`-h`!!!!!!m!$pc-rph-$
 | 
			
		||||
!`-h`!!!!!!m!r-`2cF`-$!!-r3!!!!!!m!m!`-c!`-!!$0m!!!!!$-m!m!`-$!`
 | 
			
		||||
!!-cI!!!!!-c`!!m!`-$!!!`-h`!!!!c2!!!!m!`-!!$!c0m!!!$-m!!!!!m!`!!
 | 
			
		||||
-$-hm!!!-c`!!!!!!m!!!`-cIc!!!c2!!!!!!!!m!$!c0r-`!$-m!!!!!!!$pm-$
 | 
			
		||||
-hmc!!-c`!!!!!!!2hI`-cIc-!!c2!!!!!!!!rGc2c0r-`!$-m!!!!!!!!2h-cmh
 | 
			
		||||
mc!!-c`!!!!!!!!$mc!rIr-!!c2!!!!!!!!!!$m$2m!r-$-m!!!!!!!!!!!$rr`!
 | 
			
		||||
!r-c`!!!!!!!!!!!!!!!!!!r2!!!!!!!!!!!!!!!!!!!!m!!!!!!!!!!!!!"!!B!
 | 
			
		||||
13"%J)4"##18%Q)+3!%&!)5!L%%3BL#83*L!G3!#!!B!2`"rJ2r"rq2rmrrlrrhr
 | 
			
		||||
r2riIr"ri2r!ri"h!!)!!!!#!!!!!$r!!!!!!!2r`$`!!!!!2$!m!m!!!!2$!c`!
 | 
			
		||||
2!!!2$!c`!!$`!2r`cpm!!!m!rGrpc2!!!2$p$p`-c`!!$`m!`-$0m!$2!2!-$-h
 | 
			
		||||
`$2!!$`$-hm$2!!!2m-hm$2!!!2h2hm$2!!!!r-rm$2!!!!!2r`r2!!!!!!!!!2!
 | 
			
		||||
!!!!!!!#D8f0bDA"d)%&`F'aTBf&dD@pZ$3e8D'Pc)(0MFQP`G#"MFQ9KG'9c)#i
 | 
			
		||||
Z,fPZBfaeC'8[Eh"PER0cE#"KEQ3JCQPXE(-JDA3JGfPdD#"ZC@0PFh0KFRNJB@a
 | 
			
		||||
TBA0PFbi0$8Pd)'eTCfKd)(4KDf8JB5"hD'PXC5"dEb"MEfe`E'9dC5"cEb"`E'9
 | 
			
		||||
KFf8JBQ8JF'&dD@9ZG$SY+3!!!")!!J!!!!!!!!!!!!%!"J!'%iN!!!!+@1!!!b!
 | 
			
		||||
!!!-J!!!!!"3!+`!(!Cm#@!!V!!F"f!*B!!!!!3!!M`C'BA0N98&6)$%Z-6!a,M%
 | 
			
		||||
`$J!!!!32rrm!!3!#!!-"rrm!!!d!!3!"D`!!!!!!!!!%!J!%!!)!"3!'$3!&!!*
 | 
			
		||||
X!!)!!!U`!!IrrJd!"`!#6`!!!!!+X!!)!!N0!!J!!@X!!!!%#Um!#J)!#J!#!!X
 | 
			
		||||
!$!d!#`!#E!!#!!3!"2rprr`"rrd!!!(rr!!!!J!-!!)!$3!1$3!0!!*X!!%!"!!
 | 
			
		||||
%rrX!$`(rq`!!$!!2!&N!8b"(CA3JF'&dD#"dEb"dD'Pc)%&`F'aP8f0bDA"d)'&
 | 
			
		||||
`F'aPG$XJGA0P)'Pd)(4[)'C[FQdJG'KP)("KG'JJG'mJG'KP)'PZBfaeC'8JCQp
 | 
			
		||||
XC'9b!!)!!!)!$J!#!"!!%3d!%!!#E!!"!!3!"2rk!")"rrS!!!`!%J!Q!#!JB@j
 | 
			
		||||
N)(4SC5"[G'KPFL"bC@aPGQ&ZG#"QEfaNCA*c,J!#!!!#!"%!!J!6!"30!"-!!R-
 | 
			
		||||
!!!!%!"%!&3!@$3!9!!*M!!!!"!!1!"F!'!d!&`!#E!!&!!3!$!!CrrN0!"N!!Qi
 | 
			
		||||
!!!!%!!`!'J!E$3!D!!)d!!!!"3!-rrJ!(!Vrq!!%#Q0[BQS0!"`!!Q`!"3!'!!X
 | 
			
		||||
!(Irh$3!G!!0*!!)!"J!,rrB!([re#[rf!"JZC@&bFfCQC(*KE'Pc!!!!!!!!)!"
 | 
			
		||||
KCQ4b$3!H!!"Q!!!!"J!(![re!!!"rrF!!!d!'`!"E3!!!!3!"3!I$`!I!6J)ER9
 | 
			
		||||
XE!!!!!!!!Gq!rrm!!!!A"NCTEQ4PFJ!!(`*[Me!!ASfm!Qq,i!"HA[!!I&M!!!!
 | 
			
		||||
!!!!!'mi!!JN#!Qq-1!!!Kb%#Ei`J!!!!!%C14&*038e"3e-!!"%!B@aTF`!!!!!
 | 
			
		||||
!fJ!#!!!-6@&MD@jdEh0S)%K%!!!!!!!!!!!!!!!!!!!!XSA5h%*%!!!!!!!A"NC
 | 
			
		||||
TEQ4PFJ!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
 | 
			
		||||
!!!!!!!!!!!!!!!!!!!!!3rLc#@a!4Nj%8Ne"3e2rrrrr!!!!!!!!!!!!!!!!!!!
 | 
			
		||||
!!!!!!!e6HA0dC@dJ4QpXC'9b!!!"!!3!!!!A!!)!)8eKBfPZG'pcD#")4$T6HA0
 | 
			
		||||
dC@dJ4QpXC'9b1NCTEQ4PFJ$rr`!!!Irj!!!0!"J!!@d!!!!-!!hrp!Vrp!!%#Q0
 | 
			
		||||
dH(30!"B!!@m!!!!!!!$rm`[rm`!5-!!(G'KPF'&dD!!(G'KP8'&dD!)!&!!#!#!
 | 
			
		||||
!)3d!)!!#E!!#!")!%[rbrr%"rr)!!!(rm3!!!J!K!!)!)J!M$3!L!!*b!!!!%J!
 | 
			
		||||
A!#3!*3d!*!!#EJ!$!")!&3!Q!#F0!#B!!6%!!!!6!"Arm!Vrm!!%#R4iC'`0!#F
 | 
			
		||||
!!6%!!!!5!"2rl`Vrl`!%#Q&cBh)0!#8!!@m!!!!!!!$rlJ[rlJ!F-!!-G'KPEfa
 | 
			
		||||
NC'9XD@ec!!adD'92E'4%C@aTEA-#!#-!!J!S!#N0!#J!!R)!!!!B!"d!+J!V$3!
 | 
			
		||||
U!!&Y!!!!'!!C!#`-!#`!"`!"1J!#!!!0!#X!!Qi!!`!!!!!!,3!Z$3!Y!!%a!!!
 | 
			
		||||
!'J!Frqd+rqd!"!TdH'4X$3!Z!!%a!!!!'3!Drq`+rq`!"!TKFf0b!J!T!!)!,`!
 | 
			
		||||
`$3![!!*X!!)!(J!Hrq[rkJ(rk`!!!IrU!!!#!$!!!J!a!$)0!$%!!R)!!!!H!#X
 | 
			
		||||
!-`!d$3!c!!*X!!8!(J!T!$Ark3d!03!#EJ!!!"i!+3!f!$F0!$B!!cF"!!!I!#R
 | 
			
		||||
rk!!i!$N+rqJ!"!TMDA4Y$3!i!!&Y!!!!)`!PrqF$rqF!!3d!13!"E3!!!#B!+2r
 | 
			
		||||
Q!rrQrrd0!$F!!@m!!!!H!"rrj3[rj3!5-!!(G'KPF'&dD!!(G'KP8'&dD!(rk3!
 | 
			
		||||
!$3!d!!&[!!!!!!!!rq3,rq3!)$!!$R4SCA"bEfTPBh4`BA4S!!jdD'93FQpUC@0
 | 
			
		||||
d8'&dD!)!-J!#!$S!1`d!1J!#FJ!!!#`!1`!m!$d0!$`!!Q-!!!!X!$N!2J!r$3!
 | 
			
		||||
q!!*X!!8!,!!h!%$ri`d!3!!#EJ!!!#`!0`""!%)0!%%!!cF"!!!Y!$IriJ"$!%3
 | 
			
		||||
+rq)!"!TMDA4Y$3"$!!&Y!!!!-3!crq%$rq%!!3d!4!!"E3!!!$3!0[rJ!rrJrri
 | 
			
		||||
0!%)!!@m!!!!X!#hrh`[rh`!5-!!(G'KPF'&dD!!(G'KP8'&dD!(ri`!!$3!r!!&
 | 
			
		||||
Y!!!!0`!irpi+rpi!"!T849K8$3!p!!&[!!!!!!!!rpd,rpd!&M!!#A4SC@ePF'&
 | 
			
		||||
dD!!*G'KP6@93BA4S!J!l!!)!43"'$3"&!!*X!!)!2!!mrpcrf`(rh!!!!IrE!!!
 | 
			
		||||
#!%B!!J"(!%J0!%F!!R)!!!!m!%8!53"+$3"*!!*M!!!!2!""!%X!6!d!5`!#BJ!
 | 
			
		||||
!!$`!2`"0!%i0!%d!!@m!!!!m!$hrfJ[rfJ!J-!!1G'KPF(*[DQ9MG("KG'J!$R4
 | 
			
		||||
SC9"bEfTPBh43BA4S$3"1!!&Y!!!!23!q!%m-!%m!$3!(D@jME(9NC3!#!!!0!%`
 | 
			
		||||
!!@d!!!!r!%$rf3Vrf3!%#P4&@&30!%S!!@m!!!!!!!$rf![rf!!Q-!!4D@jME(9
 | 
			
		||||
NC@C[E'4PFR"KG'J!%@PZBfaeC'9'EfaNCA*3BA4S!J")!!)!8!"4$3"3!!*b!!!
 | 
			
		||||
!4J"9!&)!8`d!8J!#B`!!!%B!83"8!&80!&3!!Q)!!!"'!%m!9J"A$3"@!!*L!!!
 | 
			
		||||
!4J",!&J!@3d!@!!"E`!!!%B!4rrA#rrA!#!`!!jdD'9`FQpUC@0dF'&dD!!1G'K
 | 
			
		||||
P8(*[DQ9MG&"KG'J0!&N!!@d!!!"(!%S!@J`!@J!0!!GTEQ0XG@4P!!)!!!d!9`!
 | 
			
		||||
"E3!!!%X!6J"E$!"E!!d!"fp`C@jcFf`!!J!!$3"9!!&Y!!!!6`"3rpB+rpB!"!T
 | 
			
		||||
849K8$3"6!!&[!!!!!!!!rp8,rp8!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&
 | 
			
		||||
dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S!J"4!!)!A!"G$3"F!!*b!!!!9J"
 | 
			
		||||
K!&i!A`d!AJ!#B`!!!&B!A3"J!'%0!'!!!Q)!!!"@!&X!BJ"M$3"L!!&[!!!!9J"
 | 
			
		||||
Arp3,rp3!)$!!$R4SCA"bEfTPBh4`BA4S!!jdD'93FQpUC@0d8'&dD!d!B`!"E3!
 | 
			
		||||
!!&F!@J"N$!"N!!`!"Q0bHA"dE`!#!!!0!'%!!@d!!!"E!&crd`Vrd`!%#P4&@&3
 | 
			
		||||
0!&m!!@m!!!!!!!$rdJ[rdJ!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4Qp
 | 
			
		||||
XC'9b8'&dD!)!A3!#!'8!CJd!C3!#FJ!!!')!E3"R!'J0!'F!!Q-!!!"L!'N!D3"
 | 
			
		||||
U$3"T!!*L!!!!BJ"R!'X!E!d!D`!"E`!!!')!Brr4#rr4!#!`!!jdD'9`FQpUC@0
 | 
			
		||||
dF'&dD!!1G'KP8(*[DQ9MG&"KG'J0!'`!!@d!!!"M!'B!E3`!E3!*!!0cFf`!!J!
 | 
			
		||||
!$3"U!!&Y!!!!C`"Srp!+rp!!"!T849K8$3"S!!&[!!!!!!!!rmm,rmm!(M!!$A0
 | 
			
		||||
cE'C[E'4PFR"KG'J!$A0cE%C[E'4PFP"KG'J#!'B!!J"Z!'m0!'i!!R)!!!"Z!(8
 | 
			
		||||
!F!"a$3"`!!*M!!!!EJ"a!()!F`d!FJ!"E`!!!'i!Err1#rr1!#!`!!jdD'9`FQp
 | 
			
		||||
UC@0dF'&dD!!1G'KP8(*[DQ9MG&"KG'J0!(-!!@d!!!"[!($rc3Vrc3!%#P4&@&3
 | 
			
		||||
0!(%!!@m!!!!!!!$rc![rc!!Q-!!4Eh"PER0cE'C[E'4PFR"KG'J!%@p`C@jcFfa
 | 
			
		||||
'EfaNCA*3BA4S!J"[!!)!G!"e$3"d!!*X!!)!GJ"frm[rbJ(rb`!!!Ir+!!!#!(8
 | 
			
		||||
!!J"f!(F0!(B!!R)!!!"f!(X!H!"j$3"i!!&[!!!!GJ"hrmN,rmN!($!!$(4SC@p
 | 
			
		||||
XC'4PE'PYF`!-G'KP6faN4'9XD@ec$3"j!!*Z!!-!!!!!!(S!H`d!HJ!"-3!!!(J
 | 
			
		||||
!H[r)#[r)!!3+G(KNE!d!H`!"-3!!!(F!H2r(#[r(!!3+BA0MFJ)!G`!#!(`!I3d
 | 
			
		||||
!I!!#E!!#!(`!I2r'rm8"rmB!!!(ra3!!!J"p!!)!IJ"r$3"q!!*X!!%!I!"mrm3
 | 
			
		||||
!J!(ra!!!$!#!!%!!1L"NC@aPG'8JEfaN)'PZBfaeC'8kEh"PER0cE#"QEfaNCA)
 | 
			
		||||
JB@jN)(*PBh*PBA4P)'Pd)'0XC@&ZE(N!!J!!!J"r!!)!J3##$3#"!!*X!!)!I!"
 | 
			
		||||
mrm2r`J(r``!!!Ir#!!!#!))!!J#$!)30!)-!!e%!!!"m!+8!K3#'!)F0!)8!!@X
 | 
			
		||||
!!!"r!*`!L!)!L!!#!)N!LJd!L3!$53!#!(m!N[r"!)[r`!Vr`3!B,QeTFf0cE'0
 | 
			
		||||
d+LSU+J!!!!!!!*!!!#SU+LS0!)X!!Qi!!!"r!)i!M!#0$3#-!!)d!!!!K`#1rlm
 | 
			
		||||
!MJVr[`!%#Q0QEf`0!)i!!@d!!!#+!)d!M``!M`!0!!G[F'9ZFh0X!!)!!!d!M3!
 | 
			
		||||
#0!!!!(m!Krqq!*!!#[qq!!3+BfC[E!d!N!!!!@m!!!#$!)Er[3[r[3!Q-!!4D@j
 | 
			
		||||
ME(9NC@C[E'4PFR"KG'J!%@PZBfaeC'9'EfaNCA*3BA4S![r!!!!#!)S!!J#4rl`
 | 
			
		||||
0!*%!!dN!!J#6!*crZ`#5rlS+rlX!'#jMEh*PC'9XEbSU+LS!!!!!!!#3!!!U+LS
 | 
			
		||||
U$3#5!!%a!!!!N`#BrlN+rlN!"!TcC@aP![qk!!!#rl`!!!d!KJ!$8J!!!!!!!2q
 | 
			
		||||
irlIrYJVrZ!!B,Q&cBh*PFR)J+LSU+J!!!!!!!*!!!#SU+LS"rlF!!!,rYJ!!$3#
 | 
			
		||||
(!!*X!!%!T!#Nrl8!N`(rY3!!$!#6!"-!$5"TCfj[FQ8JCA*bEh)!!J!!!J#%!!)
 | 
			
		||||
!P!#9$3#8!!*X!!)!TJ#Qrl6rX`(rY!!!!Iqc!!!#!*8!!J#@!*F0!*B!!dN!!J#
 | 
			
		||||
Q!,lrX[qa!*J+rl)!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!Iqa!!!'!*J
 | 
			
		||||
!!rq`!*N!QJVrX!!%#QY[Bf`0!*N!!@d!!!#U!+hrV`VrV`!%#Q0QEf`'!*S!!rq
 | 
			
		||||
Z!*[rV3VrVJ!%#QPZFfJ0!*X!!M3!!!#`!,MrV!#F#[qX!!3+BfC[E!d!R!!"E`!
 | 
			
		||||
!!,3!YrqV#rqV!#B`!"&TEQ0XG@4PCQpXC'9bF'&dD!!4D@jME(9NC8C[E'4PFP"
 | 
			
		||||
KG'J'rkd!!!)!P`!#!*d!RJd!R3!#FJ!!!,m!aJ#I!+!0!*m!!Q`"!!#r!-)!SIq
 | 
			
		||||
U$3#K!!%a!!!![`$#rkN+rkN!"!TbFfad!IqU!!!0!+!!!@m!!!!!!!$rU![rU!!
 | 
			
		||||
Z-!!9G'KPEQ9hCQpXC'9bFQ9QCA*PEQ0P!"9dD'91CAG'EfaNCA*5C@CPFQ9ZBf8
 | 
			
		||||
#!*i!!J#L!+-0!+)!!dN!!J$(!-lrT`#NrkB+rkF!'#jYDA0MFfaMG#SU+LS!!!!
 | 
			
		||||
!!!#3!!!U+LSU$3#N!!&[!!!!a`$+rk8,rk8!,M!!&A4SC@jPGfC[E'4PFR*PCQ9
 | 
			
		||||
bC@jMC3!9G'KP6Q9h4QpXC'9b8Q9QCA*PEQ0P![qQ!!!#!+-!!J#P!+B0!+8!!R)
 | 
			
		||||
!!!$2!0`!T`#S$3#R!!&Y!!!!c`$5!+N-!+N!$3!(Eh"PER0cE!!#!!!0!+J!!Qi
 | 
			
		||||
!!!!!!!!!UJ#V$3#U!!%a!!!!e`$Erk3+rk3!"!T`EQ&Y$3#V!!%a!!!!dJ$Ark-
 | 
			
		||||
+rk-!"!TcC@aP!J#Q!!)!V!#Y$3#X!!*X!!)!h3$Grk,rS3(rSJ!!!IqK!!!#!+d
 | 
			
		||||
!!J#Z!+m0!+i!!Q`!!3$G!0hrS!#`!IqJ!!!-!,!!(`!C)&0dBA*d)'eKDfPZCb"
 | 
			
		||||
dD'8JB@aTBA0PF`!#!!!#!+m!!J#a!,)0!,%!!dN!!J$G!3ArRrqH!,-+rjm!'#j
 | 
			
		||||
MEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!IqH!!!'!,-!!rqG!,3!Y3VrR3!%#QY
 | 
			
		||||
[Bf`0!,3!!@d!!!$K!16rR!VrR!!%#Q&XD@%'!,8!!rqE!,B!Y`VrQ`!%#QPZFfJ
 | 
			
		||||
0!,B!!M3!!!$R!1rrQJ#i#[qD!!3+BfC[E!d!Z!!"E`!!!1X!l[qC#rqC!$3`!"K
 | 
			
		||||
[F'9ZFh0XD@jME(9NC@C[E'4PFR"KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&
 | 
			
		||||
dD!B!Y`!$rjJ!ZIqA#[qB!!3+G'mJ)!d!Z3!#EJ!!!2)!r`#k!,X0!,S!!M3!!!$
 | 
			
		||||
i!2rrPJ#m#[q@!!3+CQPXC3d![!!"E3!!!2X!rJ#p$!#p!"-!$@p`C@jcFfaMEfj
 | 
			
		||||
Q,QJ!!J!!$3#l!!)d!!!!mJ$irj8![JVrP3!%#Q0QEf`0!,i!!@m!!!$f!2IrP![
 | 
			
		||||
rP!!@-!!*G'KPE@9`BA4S!!PdD'90C9"KG'J'rjF!!!)!XJ!#!,m!`!d![`!#E!!
 | 
			
		||||
#!3B""[q6rj)"rj-!!!(rNJ!!!J$!!!)!`3$#$3$"!!*b!!!""J%4!--!a!d!``!
 | 
			
		||||
#BJ!!!3B"$3$&!-B0!-8!!@m!!!%'!3RrN3[rN3!N-!!3Bh*jF(4[CQpXC'9bF'&
 | 
			
		||||
dD!!3Bh*jF(4[4QpXC'9b8'&dD!d!aJ!"E3!!!3N"$!$($!$(!!X!"6TKFfia!!)
 | 
			
		||||
!!!d!a!!"E`!!!!!!!2q3!![rN!!!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!)!`J!
 | 
			
		||||
#!-J!b3d!b!!$53!#!4)"22q2rii!bJVrM`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!
 | 
			
		||||
!!'jeE'`"rii!!!B!bJ!$rid!b`$-#[q0!!3+DfpME!d!b`!"E3!!!4B"'Iq-#[q
 | 
			
		||||
-!!3+B@aTB3B!c!!$riX!c3$1#[q,!!3+D@jcD!d!c3!#0!!!!4`"*2q+!-m+riS
 | 
			
		||||
!"!TMCQpX$3$2!!&[!!!")!%MriN,riN!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9
 | 
			
		||||
bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J$1!!2rL!$3riF+riJ!"!T
 | 
			
		||||
dEb!J$3$3!!*Z!!!"*`%f!0%!dJd!d3!#0!!!!5m"0[q'!0-+riB!"!TQD@aP$3$
 | 
			
		||||
6!!&Y!!!"-J%e!03-!03!$!!'BA0Z-5jS!!)!!!d!dJ!#0!!!!5F",rq&!08+ri8
 | 
			
		||||
!"!TMCQpX$3$9!!&[!!!"+`%Zri3,ri3!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!E
 | 
			
		||||
rK`!!!J$*!!)!eJ$A$3$@!!0*!!)"23&Rri2rJJ$B#[q$!"JZBfpbC@0bC@`U+LS
 | 
			
		||||
U!!!!!!!!N!!!ER9XE!(rJJ!!"J$B!!2rJ3$C!0S+ri%!"!TVEf0X$3$C!!&Y!!!
 | 
			
		||||
"33&%ri!+ri!!"!TKE'PK"J$D!!2rI`$E!0`+rhm!"!TTER0S$3$E!!)d!!!"4`&
 | 
			
		||||
2rhi!h3VrIJ!%#Q0QEf`0!0d!!@m!!!&,!8lrI3[rI3!d-!!BEh"PER0cE'PZBfa
 | 
			
		||||
eC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!0`!!rpm!0l
 | 
			
		||||
rH`VrI!!%#R4[)#!0!0i!!Qi!!!&5!@%!h`$J$3$I!!)d!!!"@J&KrhS!i3VrHJ!
 | 
			
		||||
%#QCTE'80!1%!!@d!!!&G!@!!iJ`!iJ!3!!TKFfiaAfeKBbjS!!)!!!d!i!!#0!!
 | 
			
		||||
!!9)"@[pj!1-+rhN!"!TMCQpX$3$M!!&[!!!"9J&CrhJ,rhJ!&$!!#(4PEA"`BA4
 | 
			
		||||
S!!KdC@e`8'&dD!ErH`!!!J$A!!)!j!$P$3$N!!*X!!)"D!&SrhIrGJ(rG`!!!Ip
 | 
			
		||||
f!!!#!18!!J$Q!1F0!1B!!R)!!!&S!A-!k!$T$3$S!!*L!!!"D!&[!1S!k`d!kJ!
 | 
			
		||||
"E`!!!@J"Drpe#rpe!#3`!""MFRP`G'pQEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*
 | 
			
		||||
3BA4S$3$V!!&Y!!!"D`&Z!1`-!1`!#J!%1Q*TE`!#!!!0!1N!!@m!!!!!!!$rG![
 | 
			
		||||
rG!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S!J$R!!)!l3$Z$3$Y!!0*!!)"G!'Hrh2
 | 
			
		||||
rFJ$[#[pc!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9XE!(rFJ!!"J$[!!2rF3$
 | 
			
		||||
`!2%+rh%!"!TVEf0X$3$`!!&Y!!!"H!&lrh!+rh!!"!TKE'PK"J$a!!2rE`$b!2-
 | 
			
		||||
+rfm!"!TTER0S$3$b!!)d!!!"IJ''rfi!p!VrEJ!%#Q0QEf`0!23!!@m!!!'#!BA
 | 
			
		||||
rE3[rE3!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9
 | 
			
		||||
NC8C[E'4PFP"KG'J'!2-!!rpX!2ArD`VrE!!%#R4[)#!0!28!!Qi!!!'*!CJ!pJ$
 | 
			
		||||
h$3$f!!)d!!!"N3'BrfS!q!VrDJ!%#QCTE'80!2J!!@d!!!'8!CF!q3`!q3!,!!9
 | 
			
		||||
LD@mZD!!#!!!0!2F!!M3!!!'*!C(rD3$k#[pT!!3+BfC[E!d!qJ!"E`!!!Bd"N!$
 | 
			
		||||
rD![rD!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S"[pV!!!#!1i!!J$l!2`0!2X!!Q`
 | 
			
		||||
!!J'I!CrrCrpQ!IpR!!!"rfB!!!)!r!!#!2d!rJd!r3!#FJ!!!Cm"UJ$r!3!0!2m
 | 
			
		||||
!!Q)!!!'I!DB"!3%#$3%"!!&[!!!"R`'Lrf8,rf8!*$!!%'0bHA"dEfC[E'4PFR"
 | 
			
		||||
KG'J!%'0bHA"dEdC[E'4PFP"KG'J0!3)!!@d!!!'L!D8"!``"!`!*!!-kBQB!!J!
 | 
			
		||||
!$3%!!!&[!!!!!!!!rf3,rf3!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!)!rJ!#!33
 | 
			
		||||
""3d""!!$53!#!DX"eIpMrf)""JVrB`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'j
 | 
			
		||||
eE'`"rf)!!!B""J!$rf%""`%)#[pK!!3+DfpME!d""`!"E3!!!Dm"X[pJ#[pJ!!3
 | 
			
		||||
+B@aTB3B"#!!$rem"#3%+#[pI!!3+D@jcD!d"#3!#0!!!!E8"[IpH!3X+rei!"!T
 | 
			
		||||
MCQpX$3%,!!&[!!!"Z3'mred,red!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&
 | 
			
		||||
dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J%+!!2rA!%-reX+re`!"!TdEb!
 | 
			
		||||
J$3%-!!*Z!!!"`!(2!3d"$Jd"$3!#0!!!!FJ"crpD!3m+reS!"!TQD@aP$3%2!!&
 | 
			
		||||
Y!!!"b`(1!4!-!4!!%!!+BQa[GfCTFfJZD!!#!!!0!3i!!M3!!!(!!FMr@3%4#[p
 | 
			
		||||
C!!3+BfC[E!d"%3!"E`!!!F3"arpB#rpB!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J
 | 
			
		||||
'reX!!!)""3!#!4)"%`d"%J!#E!!#!GB"e[pAreB"reF!!!(r9J!!!J%6!!)"&!%
 | 
			
		||||
9$3%8!!*b!!!"eJ(K!4B"&`d"&J!#BJ!!!GB"h3%B!4N0!4J!!@m!!!(@!GRr93[
 | 
			
		||||
r93!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d"'3!"E3!
 | 
			
		||||
!!GN"h!%D$!%D!!N!!cTLEJ!#!!!0!4F!!@m!!!!!!!$r9![r9!!8-!!)G'9YF("
 | 
			
		||||
KG'J!#(4PEA"3BA4S!J%9!!)"'`%F$3%E!!0*!!)"iJ)-re2r8J%G#[p6!"JZBfp
 | 
			
		||||
bC@0bC@`U+LSU!!!!!!!!N!!!ER9XE!(r8J!!"J%G!!2r83%H!4m+re%!"!TVEf0
 | 
			
		||||
X$3%H!!&Y!!!"jJ(Tre!+re!!"!TKE'PK"J%I!!2r6`%J!5%+rdm!"!TTER0S$3%
 | 
			
		||||
J!!)d!!!"l!(drdi")JVr6J!%#Q0QEf`0!5)!!@m!!!(`!I2r63[r63!d-!!BEh"
 | 
			
		||||
PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J
 | 
			
		||||
'!5%!!rp-!52r5`Vr6!!%#R4[)#!0!5-!!Qi!!!(h!JB"*!%P$3%N!!)d!!!"r`)
 | 
			
		||||
'rdS"*JVr5J!%#QCTE'80!5B!!@d!!!)#!J8"*``"*`!+!!4LELjS!!)!!!d"*3!
 | 
			
		||||
#0!!!!IF"rrp*!5J+rdN!"!TMCQpX$3%S!!&[!!!"q`(qrdJ,rdJ!&$!!#(4PEA"
 | 
			
		||||
`BA4S!!KdC@e`8'&dD!Er5`!!!J%F!!)"+3%U$3%T!!*X!!)#$3)0rdIr4J(r4`!
 | 
			
		||||
!!Ip'!!!#!5S!!J%V!5`0!5X!!R)!!!)0!KJ",3%Z$3%Y!!*L!!!#$3)8!5m"-!d
 | 
			
		||||
",`!"E`!!!Jd#%2p&#rp&!#3`!""MFRP`G'pQEfaNCA*`BA4S!""MFRP`G'p'Efa
 | 
			
		||||
NCA*3BA4S$3%`!!&Y!!!#%!)6!6%-!6%!$3!(1Q*eCQCPFJ!#!!!0!5i!!@m!!!!
 | 
			
		||||
!!!$r4![r4!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S!J%X!!)"-J%c$3%b!!0*!!)
 | 
			
		||||
#'3*$rd2r3J%d#[p$!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9XE!(r3J!!"J%
 | 
			
		||||
d!!2r33%e!6B+rd%!"!TVEf0X$3%e!!&Y!!!#(3)Jrd!+rd!!"!TKE'PK"J%f!!2
 | 
			
		||||
r2`%h!6J+rcm!"!TTER0S$3%h!!)d!!!#)`)Vrci"13Vr2J!%#Q0QEf`0!6N!!@m
 | 
			
		||||
!!!)R!LVr23[r23!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0
 | 
			
		||||
-5@jME(9NC8C[E'4PFP"KG'J'!6J!!rmm!6Vr1`Vr2!!%#R4[)#!0!6S!!Qi!!!)
 | 
			
		||||
Z!Md"1`%m$3%l!!)d!!!#0J)prcS"23Vr1J!%#QCTE'80!6d!!@d!!!)j!M`"2J`
 | 
			
		||||
"2J!1!!KLG@CQCA)ZD!!#!!!0!6`!!M3!!!)Z!MEr13%r#[mj!!3+BfC[E!d"2`!
 | 
			
		||||
"E`!!!M)#0Imi#rmi!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J'rcX!!!)"-`!#!8!
 | 
			
		||||
"33d"3!!#E!!#!N3#42mhrcB"rcF!!!(r0J!!!J&"!!)"3J&$$3&#!!*b!!!#4!*
 | 
			
		||||
2!83"43d"4!!#BJ!!!N3#5`&'!8F0!8B!!@m!!!*%!NIr03[r03!N-!!3Bh*jF(4
 | 
			
		||||
[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d"4`!"E3!!!NF#5J&)$!&)!!X
 | 
			
		||||
!"6TMBA0d!!)!!!d"43!"E`!!!!!!!2md#rmd!"3`!!KdC@e`F'&dD!!)G'9YF&"
 | 
			
		||||
KG'J#!8-!!J&*!8S0!8N!!dN!!J*3!RVr-rmb!8X+rc-!'#jMEh*PBh*PE#SU+LS
 | 
			
		||||
!!!!!!!#3!!"ZG@aX!Imb!!!'!8X!!rma!8`"63Vr-3!%#QY[Bf`0!8`!!@d!!!*
 | 
			
		||||
8!PIr-!Vr-!!%#Q&XD@%'!8d!!rm[!8i"6`Vr,`!%#QPZFfJ0!8i!!M3!!!*D!Q,
 | 
			
		||||
r,J&3#[mZ!!3+BfC[E!d"8!!"E`!!!Pi#BImY#rmY!$3`!"K[F'9ZFh0XD@jME(9
 | 
			
		||||
NC@C[E'4PFR"KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&dD!B"6`!$rb`"8Im
 | 
			
		||||
V#[mX!!3+G'mJ)!d"83!#EJ!!!Q8#G!&5!9-0!9)!!M3!!!*Y!R6r+J&8#[mU!!3
 | 
			
		||||
+CQPXC3d"9!!"E3!!!R!#F`&9$!&9!!`!"Q0KFh3ZD!!#!!!0!9-!!M3!!!*P!Qh
 | 
			
		||||
r+3&@#[mT!!3+BfC[E!d"9J!"E`!!!QN#E2mS#rmS!"3`!!KdC@e`F'&dD!!)G'9
 | 
			
		||||
YF&"KG'J'rbX!!!)"5J!#!9F"@!d"9`!#E!!#!RX#HrmRrbB"rbF!!!(r*J!!!J&
 | 
			
		||||
B!!)"@3&D$3&C!!*b!!!#H`+'!9X"A!d"@`!#BJ!!!RX#JJ&G!9i0!9d!!@m!!!*
 | 
			
		||||
l!Rlr*3[r*3!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d
 | 
			
		||||
"AJ!"E3!!!Ri#J3&I$!&I!!X!"6TMEfe`!!)!!!d"A!!"E`!!!!!!!2mN#rmN!"3
 | 
			
		||||
`!!KdC@e`F'&dD!!)G'9YF&"KG'J#!9S!!J&J!@%0!@!!!dN!!J+(!V(r)rmL!@)
 | 
			
		||||
+rb-!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!ImL!!!'!@)!!rmK!@-"C!V
 | 
			
		||||
r)3!%#QY[Bf`0!@-!!@d!!!+,!Slr)!Vr)!!%#Q&XD@%'!@3!!rmI!@8"CJVr(`!
 | 
			
		||||
%#QPZFfJ0!@8!!M3!!!+4!TRr(J&R#[mH!!3+BfC[E!d"C`!"E`!!!T8#Q2mG#rm
 | 
			
		||||
G!$3`!"K[F'9ZFh0XD@jME(9NC@C[E'4PFR"KG'J!''p`C@j68da*EQ0XG@4P4Qp
 | 
			
		||||
XC'9b8'&dD!B"CJ!$ra`"D2mE#[mF!!3+G'mJ)!d"D!!#EJ!!!T`#U`&T!@S0!@N
 | 
			
		||||
!!M3!!!+N!U[r'J&V#[mD!!3+CQPXC3d"D`!"E3!!!UF#UJ&X$!&X!!`!"Q0[EA!
 | 
			
		||||
ZD!!#!!!0!@S!!M3!!!+F!U6r'3&Y#[mC!!3+BfC[E!d"E3!"E`!!!U!#SrmB#rm
 | 
			
		||||
B!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J'raX!!!)"B3!#!@i"E`d"EJ!#E!!#!V)
 | 
			
		||||
#X[mAraB"raF!!!(r&J!!!J&[!!)"F!&a$3&`!!*b!!!#XJ+p!A)"F`d"FJ!#BJ!
 | 
			
		||||
!!V)#Z3&d!A80!A3!!@m!!!+b!VAr&3[r&3!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!
 | 
			
		||||
3Bh*jF(4[4QpXC'9b8'&dD!d"G3!"E3!!!V8#Z!&f$!&f!!X!"6TMEfjQ!!)!!!d
 | 
			
		||||
"F`!"E`!!!!!!!2m8#rm8!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J#!A%!!J&h!AJ
 | 
			
		||||
0!AF!!dN!!J+q!ZMr%rm5!AN+ra-!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@a
 | 
			
		||||
X!Im5!!!'!AN!!rm4!AS"H`Vr%3!%#QY[Bf`0!AS!!@d!!!,#!XAr%!Vr%!!%#Q&
 | 
			
		||||
XD@%'!AX!!rm2!A`"I3Vr$`!%#QPZFfJ0!A`!!M3!!!,)!Y$r$J&q#[m1!!3+BfC
 | 
			
		||||
[E!d"IJ!"E`!!!X`#crm0#rm0!$3`!"K[F'9ZFh0XD@jME(9NC@C[E'4PFR"KG'J
 | 
			
		||||
!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&dD!B"I3!$r``"Irm,#[m-!!3+G'mJ)!d
 | 
			
		||||
"I`!#EJ!!!Y-#iJ'!!B%0!B!!!M3!!!,E!Z,r#J'##[m+!!3+CQPXC3d"JJ!"E3!
 | 
			
		||||
!!Yi#i3'$$!'$!!`!"Q0[EQBZD!!#!!!0!B%!!M3!!!,6!Y[r#3'%#[m*!!3+BfC
 | 
			
		||||
[E!d"K!!"E`!!!YF#f[m)#rm)!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J'r`X!!!)
 | 
			
		||||
"H!!#!B8"KJd"K3!#E!!#!ZN#kIm(r`B"r`F!!!(r"J!!!J''!!)"K`')$3'(!!*
 | 
			
		||||
b!!!#k3,d!BN"LJd"L3!#BJ!!!ZN#m!',!B`0!BX!!@m!!!,T!Zcr"3[r"3!N-!!
 | 
			
		||||
3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d"M!!"E3!!!Z`#l`'
 | 
			
		||||
0$!'0!!S!"$TNCA-!!J!!$3'+!!&[!!!!!!!!r`3,r`3!&$!!#(4PEA"`BA4S!!K
 | 
			
		||||
dC@e`8'&dD!)"L!!#!Bi"M`d"MJ!$53!#![8$(rm$r`)"N!!+r`-!'#jMEh*PBh*
 | 
			
		||||
PE#SU+LS!!!!!!!#3!!"ZG@aX!Im#!!!'!C!!!!2r!3'4!C)+r`%!"!TVEf0X$3'
 | 
			
		||||
4!!&Y!!!#q3,mr`!+r`!!"!TKE'PK"J'5!!2qr`'6!C3+r[m!"!TTER0S$3'6!!)
 | 
			
		||||
d!!!#r`-(r[i"P3VqrJ!%#Q0QEf`0!C8!!@m!!!-$!`Eqr3[qr3!d-!!BEh"PER0
 | 
			
		||||
cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!C3
 | 
			
		||||
!!rlm!CEqq`Vqr!!%#R4[)#!0!CB!!Qi!!!-+!aN"P`'B$3'A!!)d!!!$%J-Cr[S
 | 
			
		||||
"Q3VqqJ!%#QCTE'80!CN!!@d!!!-9!aJ"QJ`"QJ!,!!9NCA-ZD!!#!!!0!CJ!!M3
 | 
			
		||||
!!!-+!a,qq3'E#[lj!!3+BfC[E!d"Q`!"E`!!!`i$%Ili#rli!"3`!!KdC@e`F'&
 | 
			
		||||
dD!!)G'9YF&"KG'J'r[X!!!)"M`!#!C`"R3d"R!!#E!!#!b!$)2lhr[B"r[F!!!(
 | 
			
		||||
qpJ!!!J'G!!)"RJ'I$3'H!!*b!!!$)!-V!D!"S3d"S!!#BJ!!!b!$*`'L!D-0!D)
 | 
			
		||||
!!@m!!!-J!b2qp3[qp3!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9
 | 
			
		||||
b8'&dD!d"S`!"E3!!!b-$*J'N$!'N!!N!!cTND!!#!!!0!D%!!@m!!!!!!!$qp![
 | 
			
		||||
qp!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S!J'I!!)"T3'Q$3'P!!0*!!)$,!0@r[2
 | 
			
		||||
qmJ'R#[lc!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9XE!(qmJ!!"J'R!!2qm3'
 | 
			
		||||
S!DN+r[%!"!TVEf0X$3'S!!&Y!!!$-!-cr[!+r[!!"!TKE'PK"J'T!!2ql`'U!DX
 | 
			
		||||
+rZm!"!TTER0S$3'U!!)d!!!$0J-qrZi"V!VqlJ!%#Q0QEf`0!D`!!@m!!!-k!ch
 | 
			
		||||
ql3[ql3!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9
 | 
			
		||||
NC8C[E'4PFP"KG'J'!DX!!rlX!Dhqk`Vql!!%#R4[)#!0!Dd!!Qi!!!0"!e!"VJ'
 | 
			
		||||
[$3'Z!!)d!!!$5303rZS"X!VqkJ!%#QCTE'80!E!!!@d!!!0-!dm"X3`"X3!+!!4
 | 
			
		||||
ND#jS!!)!!!d"V`!#0!!!!d%$5IlT!E)+rZN!"!TMCQpX$3'b!!&[!!!$430)rZJ
 | 
			
		||||
,rZJ!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!Eqk`!!!J'Q!!)"X`'d$3'c!!*X!!)
 | 
			
		||||
$9`0ArZIqjJ(qj`!!!IlQ!!!#!E3!!J'e!EB0!E8!!R)!!!0A!f)"Y`'i$3'h!!*
 | 
			
		||||
L!!!$9`0H!EN"ZJd"Z3!"E`!!!eF$@[lP#rlP!#3`!""MFRP`G'pQEfaNCA*`BA4
 | 
			
		||||
S!""MFRP`G'p'EfaNCA*3BA4S$3'k!!&Y!!!$@J0G!EX-!EX!#J!%1Q4cB3!#!!!
 | 
			
		||||
0!EJ!!@m!!!!!!!$qj![qj!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S!J'f!!)"[!'
 | 
			
		||||
p$3'm!!0*!!)$B`10rZ2qiJ'q#[lM!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9
 | 
			
		||||
XE!(qiJ!!"J'q!!2qi3'r!F!+rZ%!"!TVEf0X$3'r!!&Y!!!$C`0UrZ!+rZ!!"!T
 | 
			
		||||
KE'PK"J(!!!2qh`("!F)+rYm!"!TTER0S$3("!!)d!!!$E30erYi"``VqhJ!%#Q0
 | 
			
		||||
QEf`0!F-!!@m!!!0a!h6qh3[qh3!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4
 | 
			
		||||
S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!F)!!rlF!F6qf`Vqh!!%#R4[)#!
 | 
			
		||||
0!F3!!Qi!!!0i!iF"a3('$3(&!!)d!!!$J!1(rYS"a`VqfJ!%#QCTE'80!FF!!@d
 | 
			
		||||
!!!1$!iB"b!`"b!!,!!9NFf%ZD!!#!!!0!FB!!M3!!!0i!i$qf3(*#[lC!!3+BfC
 | 
			
		||||
[E!d"b3!"E`!!!h`$IrlB#rlB!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J'rYX!!!)
 | 
			
		||||
"[3!#!FS"b`d"bJ!#E!!#!ii$M[lArYB"rYF!!!(qeJ!!!J(,!!)"c!(0$3(-!!*
 | 
			
		||||
b!!!$MJ1C!Fi"c`d"cJ!#BJ!!!ii$P3(3!G%0!G!!!@m!!!11!j(qe3[qe3!N-!!
 | 
			
		||||
3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d"d3!"E3!!!j%$P!(
 | 
			
		||||
5$!(5!!S!"$TPFR)!!J!!$3(2!!&[!!!!!!!!rY3,rY3!&$!!#(4PEA"`BA4S!!K
 | 
			
		||||
dC@e`8'&dD!)"c3!#!G-"e!d"d`!$53!#!jS$a2l6rY)"e3Vqd`!B,Q0[FQ9MFQ9
 | 
			
		||||
X+LSU+J!!!!!!!*!!!'jeE'`"rY)!!!B"e3!$rY%"eJ(A#[l4!!3+DfpME!d"eJ!
 | 
			
		||||
"E3!!!ji$SIl3#[l3!!3+B@aTB3B"e`!$rXm"f!(C#[l2!!3+D@jcD!d"f!!#0!!
 | 
			
		||||
!!k3$V2l1!GS+rXi!"!TMCQpX$3(D!!&[!!!$U!1VrXd,rXd!0$!!''p`C@jcFfa
 | 
			
		||||
TEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J(C!!2
 | 
			
		||||
qc!(ErXX+rX`!"!TdEb!J$3(E!!*Z!!!$V`1q!G`"h3d"h!!#0!!!!lF$[[l+!Gi
 | 
			
		||||
+rXS!"!TQD@aP$3(H!!&Y!!!$ZJ1p!Gm-!Gm!#`!&CA*b,QJ!!J!!$3(G!!)d!!!
 | 
			
		||||
$V`1hrXN"i!Vqb3!%#Q0QEf`0!H!!!@m!!!1c!lEqb![qb!!8-!!)G'9YF("KG'J
 | 
			
		||||
!#(4PEA"3BA4S"[l,!!!#!G3!!J(K!H)0!H%!!Q`!!J2&!mAqarl'!Il(!!!"rXB
 | 
			
		||||
!!!)"iJ!#!H-"j!d"i`!#FJ!!!m8$d!(P!HB0!H8!!Q)!!!2&!m`"j`(S$3(R!!&
 | 
			
		||||
[!!!$a32)rX8,rX8!*$!!%'0bHA"dEfC[E'4PFR"KG'J!%'0bHA"dEdC[E'4PFP"
 | 
			
		||||
KG'J0!HJ!!@d!!!2)!mX"k3`"k3!+!!3kCAC`!!)!!!d"jJ!"E`!!!!!!!2l%#rl
 | 
			
		||||
%!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J#!H3!!J(U!HX0!HS!!dN!!J24!r[q`rl
 | 
			
		||||
#!H`+rX-!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!Il#!!!'!H`!!rl"!Hd
 | 
			
		||||
"lJVq`3!%#QY[Bf`0!Hd!!@d!!!29!pMq`!Vq`!!%#Q&XD@%'!Hi!!rkr!Hm"m!V
 | 
			
		||||
q[`!%#QPZFfJ0!Hm!!M3!!!2E!q2q[J(a#[kq!!3+BfC[E!d"m3!"E`!!!pm$i[k
 | 
			
		||||
p#rkp!$3`!"K[F'9ZFh0XD@jME(9NC@C[E'4PFR"KG'J!''p`C@j68da*EQ0XG@4
 | 
			
		||||
P4QpXC'9b8'&dD!B"m!!$rV`"m[kl#[km!!3+G'mJ)!d"mJ!#EJ!!!qB$p3(c!I3
 | 
			
		||||
0!I-!!M3!!!2Z!rAqZJ(e#[kk!!3+CQPXC3d"p3!"E3!!!r%$p!(f$!(f!!X!"@9
 | 
			
		||||
fF#jS!!)!!!d"p!!#0!!!!qB$l[kj!IF+rVN!"!TMCQpX$3(h!!&[!!!$kJ2YrVJ
 | 
			
		||||
,rVJ!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!EqZ`!!!J(V!!)"q!(j$3(i!!*X!!)
 | 
			
		||||
$r!2mrVIqYJ(qY`!!!Ikf!!!#!IN!!J(k!IX0!IS!!R)!!!2m"!F"r!(p$3(m!!*
 | 
			
		||||
L!!!$r!3$!Ii"r`d"rJ!"E`!!!r`$rrke#rke!#3`!""MFRP`G'pQEfaNCA*`BA4
 | 
			
		||||
S!""MFRP`G'p'EfaNCA*3BA4S$3(r!!&Y!!!$r`3#!J!-!J!!#`!&1QKYB@-!!J!
 | 
			
		||||
!$3(p!!&[!!!!!!!!rV3,rV3!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!)"q`!#!J%
 | 
			
		||||
#!Jd#!3!$53!#"!J%-[kcrV)#!`VqX`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'j
 | 
			
		||||
eE'`"rV)!!!B#!`!$rV%#"!)&#[ka!!3+DfpME!d#"!!"E3!!"!`%$rk`#[k`!!3
 | 
			
		||||
+B@aTB3B#"3!$rUm#"J)(#[k[!!3+D@jcD!d#"J!#0!!!"")%'[kZ!JJ+rUi!"!T
 | 
			
		||||
MCQpX$3))!!&[!!!%&J3CrUd,rUd!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&
 | 
			
		||||
dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J)(!!2qV!)*rUX+rU`!"!TdEb!
 | 
			
		||||
J$3)*!!*Z!!!%(33X!JS##`d##J!#0!!!"#8%,2kU!J`+rUS!"!TQD@aP$3)-!!&
 | 
			
		||||
Y!!!%+!3V!Jd-!Jd!$!!'D'eKBbjS!!)!!!d##`!#0!!!""d%*IkT!Ji+rUN!"!T
 | 
			
		||||
MCQpX$3)1!!&[!!!%)33NrUJ,rUJ!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!EqU`!
 | 
			
		||||
!!J)#!!)#$`)3$3)2!!*X!!)%-`3crUIqTJ(qT`!!!IkQ!!!#!K!!!J)4!K)0!K%
 | 
			
		||||
!!R)!!!3c"$i#%`)8$3)6!!*L!!!%-`3k!K8#&Jd#&3!"E`!!"$-%0[kP#rkP!#3
 | 
			
		||||
`!""MFRP`G'pQEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S$3)@!!&Y!!!%0J3
 | 
			
		||||
j!KF-!KF!#`!&1QPNC@%!!J!!$3)8!!&[!!!!!!!!rU3,rU3!&$!!#(4PEA"`BA4
 | 
			
		||||
S!!KdC@e`8'&dD!)#%J!#!KJ#'3d#'!!$53!#"$m%DIkMrU)#'JVqS`!B,Q0[FQ9
 | 
			
		||||
MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"rU)!!!B#'J!$rU%#'`)F#[kK!!3+DfpME!d
 | 
			
		||||
#'`!"E3!!"%-%4[kJ#[kJ!!3+B@aTB3B#(!!$rTm#(3)H#[kI!!3+D@jcD!d#(3!
 | 
			
		||||
#0!!!"%N%8IkH!Km+rTi!"!TMCQpX$3)I!!&[!!!%6343rTd,rTd!0$!!''p`C@j
 | 
			
		||||
cFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J)
 | 
			
		||||
H!!2qR!)JrTX+rT`!"!TdEb!J$3)J!!*Z!!!%9!4M!L%#)Jd#)3!#0!!!"&`%Brk
 | 
			
		||||
D!L-+rTS!"!TQD@aP$3)M!!&Y!!!%A`4L!L3-!L3!$!!'D@4PB5jS!!)!!!d#)J!
 | 
			
		||||
#0!!!"&3%A2kC!L8+rTN!"!TMCQpX$3)P!!&[!!!%@!4ErTJ,rTJ!&$!!#(4PEA"
 | 
			
		||||
`BA4S!!KdC@e`8'&dD!EqQ`!!!J)C!!)#*J)R$3)Q!!*X!!)%DJ4UrTIqPJ(qP`!
 | 
			
		||||
!!Ik@!!!#!LF!!J)S!LN0!LJ!!R)!!!4U"(8#+J)V$3)U!!*L!!!%DJ4a!L`#,3d
 | 
			
		||||
#,!!"E`!!"'S%EIk9#rk9!#3`!""MFRP`G'pQEfaNCA*`BA4S!""MFRP`G'p'Efa
 | 
			
		||||
NCA*3BA4S$3)Y!!&Y!!!%E34`!Li-!Li!$!!'1QaSBA0S!!)!!!d#+`!"E`!!!!!
 | 
			
		||||
!!2k8#rk8!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J#!LN!!J)[!M!0!Lm!!dN!!J4
 | 
			
		||||
f"+$qNrk5!M%+rT-!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!Ik5!!!'!M%
 | 
			
		||||
!!rk4!M)#-`VqN3!%#QY[Bf`0!M)!!@d!!!4k"(hqN!!+rT!!!!3+B@aTB3B#-`!
 | 
			
		||||
$rSm#0!)e#[k2!!3+D@jcD!d#0!!#0!!!")!%L2k1!MB+rSi!"!TMCQpX$3)f!!&
 | 
			
		||||
[!!!%K!5(rSd,rSd!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP0
 | 
			
		||||
66%PZBfaeC'9'EfaNCA*3BA4S"J)e!!2qM!)hrSX+rS`!"!TdEb!J$3)h!!*Z!!!
 | 
			
		||||
%L`5D!MJ#13d#1!!#0!!!"*-%Q[k+!MS+rSS!"!TQD@aP$3)k!!&Y!!!%PJ5C!MX
 | 
			
		||||
-!MX!$3!(E'KKFfJZD!!#!!!0!MN!!M3!!!5,"*2qL3)m#[k*!!3+BfC[E!d#2!!
 | 
			
		||||
"E`!!")m%N[k)#rk)!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J'rSX!!!)#-!!#!Md
 | 
			
		||||
#2Jd#23!#E!!#"+%%SIk(rSB"rSF!!!(qKJ!!!J)q!!)#2`*!$3)r!!*b!!!%S35
 | 
			
		||||
X!N%#3Jd#33!#BJ!!"+%%U!*$!N30!N-!!@m!!!5K"+6qK3[qK3!N-!!3Bh*jF(4
 | 
			
		||||
[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d#4!!"E3!!"+3%T`*&$!*&!!S
 | 
			
		||||
!"$TYC$)!!J!!$3*#!!&[!!!!!!!!rS3,rS3!&$!!#(4PEA"`BA4S!!KdC@e`8'&
 | 
			
		||||
dD!)#3!!#!NB#4`d#4J!$53!#"+d%erk$rS)#5!VqJ`!B,Q0[FQ9MFQ9X+LSU+J!
 | 
			
		||||
!!!!!!*!!!'jeE'`"rS)!!!B#5!!$rS%#53*+#[k"!!3+DfpME!d#53!"E3!!",%
 | 
			
		||||
%Y2k!#[k!!!3+B@aTB3B#5J!$rRm#5`*-#[jr!!3+D@jcD!d#5`!#0!!!",F%[rj
 | 
			
		||||
q!Nd+rRi!"!TMCQpX$3*0!!&[!!!%Z`5qrRd,rRd!0$!!''p`C@jcFfaTEQ0XG@4
 | 
			
		||||
PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J*-!!2qI!*1rRX
 | 
			
		||||
+rR`!"!TdEb!J$3*1!!*Z!!!%`J64!Nm#8!d#6`!#0!!!"-S%dIjk!P%+rRS!"!T
 | 
			
		||||
QD@aP$3*4!!&Y!!!%c363!P)-!P)!#`!&E@3b,QJ!!J!!$3*3!!)d!!!%`J6+rRN
 | 
			
		||||
#8`VqH3!%#Q0QEf`0!P-!!@m!!!6'"-RqH![qH!!8-!!)G'9YF("KG'J!#(4PEA"
 | 
			
		||||
3BA4S"[jl!!!#!NF!!J*8!P80!P3!!Q`!!J6B"0MqGrjf!Ijh!!!"rRB!!!)#93!
 | 
			
		||||
#!PB#9`d#9J!#FJ!!"0J%i`*B!PN0!PJ!!Q)!!!6B"0m#@J*E$3*D!!&[!!!%f!6
 | 
			
		||||
ErR8,rR8!*$!!%'0bHA"dEfC[E'4PFR"KG'J!%'0bHA"dEdC[E'4PFP"KG'J0!PX
 | 
			
		||||
!!@d!!!6E"0i#A!`#A!!+!!3kE@3e!!)!!!d#@3!"E`!!!!!!!2jd#rjd!"3`!!K
 | 
			
		||||
dC@e`F'&dD!!)G'9YF&"KG'J#!PF!!J*G!Pi0!Pd!!dN!!J6N"3lqFrjb!Pm+rR-
 | 
			
		||||
!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!Ijb!!!'!Pm!!rja!Q!#B3VqF3!
 | 
			
		||||
%#QY[Bf`0!Q!!!@d!!!6S"1[qF!VqF!!%#Q&XD@%'!Q%!!rj[!Q)#B`VqE`!%#QP
 | 
			
		||||
ZFfJ0!Q)!!M3!!!6Z"2EqEJ*N#[jZ!!3+BfC[E!d#C!!"E`!!"2)%pIjY#rjY!$3
 | 
			
		||||
`!"K[F'9ZFh0XD@jME(9NC@C[E'4PFR"KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9
 | 
			
		||||
b8'&dD!B#B`!$rQ`#CIjV#[jX!!3+G'mJ)!d#C3!#EJ!!"2N&#!*Q!QF0!QB!!M3
 | 
			
		||||
!!!8""3MqDJ*S#[jU!!3+CQPXC3d#D!!"E3!!"33&"`*T$!*T!!X!"@eN05jS!!)
 | 
			
		||||
!!!d#C`!#0!!!"2N&!IjT!QS+rQN!"!TMCQpX$3*U!!&[!!!%r38!rQJ,rQJ!&$!
 | 
			
		||||
!#(4PEA"`BA4S!!KdC@e`8'&dD!EqD`!!!J*H!!)#D`*X$3*V!!*X!!)&$`82rQI
 | 
			
		||||
qCJ(qC`!!!IjQ!!!#!Q`!!J*Y!Qi0!Qd!!R)!!!82"4S#E`*`$3*[!!*L!!!&$`8
 | 
			
		||||
@!R%#FJd#F3!"E`!!"3m&%[jP#rjP!#3`!""MFRP`G'pQEfaNCA*`BA4S!""MFRP
 | 
			
		||||
`G'p'EfaNCA*3BA4S$3*b!!&Y!!!&%J89!R--!R-!#`!&1QeNBc)!!J!!$3*`!!&
 | 
			
		||||
[!!!!!!!!rQ3,rQ3!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!)#EJ!#!R3#G3d#G!!
 | 
			
		||||
$53!#"4X&4IjMrQ)#GJVqB`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"rQ)
 | 
			
		||||
!!!B#GJ!$rQ%#G`*i#[jK!!3+DfpME!d#G`!"E3!!"4m&)[jJ#[jJ!!3+B@aTB3B
 | 
			
		||||
#H!!$rPm#H3*k#[jI!!3+D@jcD!d#H3!#0!!!"58&,IjH!RX+rPi!"!TMCQpX$3*
 | 
			
		||||
l!!&[!!!&+38XrPd,rPd!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"
 | 
			
		||||
PEP066%PZBfaeC'9'EfaNCA*3BA4S"J*k!!2qA!*mrPX+rP`!"!TdEb!J$3*m!!*
 | 
			
		||||
Z!!!&-!8r!Rd#IJd#I3!#0!!!"6J&2rjD!Rm+rPS!"!TQD@aP$3*r!!&Y!!!&1`8
 | 
			
		||||
q!S!-!S!!$!!'E@4M-LjS!!)!!!d#IJ!#0!!!"6!&12jC!S%+rPN!"!TMCQpX$3+
 | 
			
		||||
"!!&[!!!&0!8hrPJ,rPJ!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!Eq@`!!!J*e!!)
 | 
			
		||||
#JJ+$$3+#!!*X!!)&4J9'rPIq9J(q9`!!!Ij@!!!#!S-!!J+%!S80!S3!!R)!!!9
 | 
			
		||||
'"9%#KJ+($3+'!!*L!!!&4J90!SJ#L3d#L!!"E`!!"8B&5Ij9#rj9!#3`!""MFRP
 | 
			
		||||
`G'pQEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S$3+*!!&Y!!!&539-!SS-!SS
 | 
			
		||||
!$J!)1QpLDQ9MG(-!!J!!$3+(!!&[!!!!!!!!rP3,rP3!&$!!#(4PEA"`BA4S!!K
 | 
			
		||||
dC@e`8'&dD!)#K3!#!SX#M!d#L`!$53!#"9)&I2j6rP)#M3Vq8`!B,Q0[FQ9MFQ9
 | 
			
		||||
X+LSU+J!!!!!!!*!!!'jeE'`"rP)!!!B#M3!$rP%#MJ+2#[j4!!3+DfpME!d#MJ!
 | 
			
		||||
"E3!!"9B&@Ij3#[j3!!3+B@aTB3B#M`!$rNm#N!!#N3Vq6`!%#QPZFfJ0!T!!!!)
 | 
			
		||||
d!!!&A!9NrNi#NJVq6J!%#Q0QEf`0!T)!!@m!!!9J"@2q63[q63!d-!!BEh"PER0
 | 
			
		||||
cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!T%
 | 
			
		||||
!!rj-!T2q5`Vq6!!%#R4[)#!0!T-!!Qi!!!9R"AB#P!+9$3+8!!)d!!!&E`9frNS
 | 
			
		||||
#PJVq5J!%#QCTE'80!TB!!@d!!!9b"A8#P``#P`!2!!P[BQTPBh4c,QJ!!J!!$3+
 | 
			
		||||
9!!)d!!!&C`9[rNN#Q!Vq53!%#Q0QEf`0!TJ!!@m!!!9V"@lq5![q5!!8-!!)G'9
 | 
			
		||||
YF("KG'J!#(4PEA"3BA4S"[j,!!!#!S`!!J+C!TS0!TN!!Q`!!J9p"Ahq4rj'!Ij
 | 
			
		||||
(!!!"rNB!!!)#QJ!#!TX#R!d#Q`!#FJ!!"Ad&L!+G!Ti0!Td!!Q)!!!9p"B3#R`+
 | 
			
		||||
J$3+I!!&[!!!&I3@!rN8,rN8!*$!!%'0bHA"dEfC[E'4PFR"KG'J!%'0bHA"dEdC
 | 
			
		||||
[E'4PFP"KG'J0!U!!!@d!!!@!"B-#S3`#S3!+!!3kF'9Y!!)!!!d#RJ!"E`!!!!!
 | 
			
		||||
!!2j%#rj%!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J#!T`!!J+L!U-0!U)!!dN!!J@
 | 
			
		||||
*"E2q3rj#!U3+rN-!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!Ij#!!!'!U3
 | 
			
		||||
!!rj"!U8#TJVq33!%#QY[Bf`0!U8!!@d!!!@0"C!!rN!+rN!!"!TKE'PK"J+Q!!2
 | 
			
		||||
q2`+R!UJ+rMm!"!TTER0S$3+R!!)d!!!&N`@ErMi#U3Vq2J!%#Q0QEf`0!UN!!@m
 | 
			
		||||
!!!@A"CVq23[q23!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0
 | 
			
		||||
-5@jME(9NC8C[E'4PFP"KG'J'!UJ!!rim!UVq1`Vq2!!%#R4[)#!0!US!!Qi!!!@
 | 
			
		||||
H"Dd#U`+X$3+V!!)d!!!&TJ@YrMS#V3Vq1J!%#QCTE'80!Ud!!@d!!!@T"D`#VJ`
 | 
			
		||||
#VJ!,!!9`C@dZD!!#!!!0!U`!!M3!!!@H"DEq13+[#[ij!!3+BfC[E!d#V`!"E`!
 | 
			
		||||
!"D)&TIii#rii!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J'rMX!!!)#S`!#!V!#X3d
 | 
			
		||||
#X!!$53!#"E3&h[ihrMB#XJVq0`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`
 | 
			
		||||
"rMB!!!B#XJ!$rM8#X`+d#[ie!!3+DfpME!d#X`!"E3!!"EJ&Zrid#[id!!3+B@a
 | 
			
		||||
TB3B#Y!!$rM-#Y3+f#[ic!!3+D@jcD!d#Y3!#0!!!"Ei&a[ib!VF+rM)!"!TMCQp
 | 
			
		||||
X$3+h!!&[!!!&`JA&rM%,rM%!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!
 | 
			
		||||
BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J+f!!2q-!+irLm+rM!!"!TdEb!J$3+
 | 
			
		||||
i!!*Z!!!&b3AB!VN#ZJd#Z3!#0!!!"G%&f2iZ!VX+rLi!"!TQD@aP$3+l!!&Y!!!
 | 
			
		||||
&e!AA!V`-!V`!$!!'F'9Y-LjS!!)!!!d#ZJ!#0!!!"FN&dIiY!Vd+rLd!"!TMCQp
 | 
			
		||||
X$3+p!!&[!!!&c3A3rL`,rL`!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!Eq,`!!!J+
 | 
			
		||||
a!!)#[J+r$3+q!!*X!!)&h`AIrL[q+J(q+`!!!IiU!!!#!Vm!!J,!!X%0!X!!!R)
 | 
			
		||||
!!!AI"HS#`J,$$3,#!!*L!!!&h`AQ!X3#a3d#a!!"E`!!"Gm&i[iT#riT!#3`!""
 | 
			
		||||
MFRP`G'pQEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S$3,&!!&Y!!!&iJAP!XB
 | 
			
		||||
-!XB!$3!(1R"VBh-a-J!#!!!0!X-!!@m!!!!!!!$q+![q+!!8-!!)G'9YF("KG'J
 | 
			
		||||
!#(4PEA"3BA4S!J,"!!)#a`,)$3,(!!0*!!)&k`B9rLIq*J,*#[iR!"JZBfpbC@0
 | 
			
		||||
bC@`U+LSU!!!!!!!!N!!!ER9XE!(q*J!!"J,*!!2q*3,+!XX+rL8!"!TVEf0X$3,
 | 
			
		||||
+!!&Y!!!&l`AbrL3+rL3!"!TKE'PK"J,,!!2q)`,-!Xd+rL-!"!TTER0S$3,-!!)
 | 
			
		||||
d!!!&p3AprL)#cJVq)J!%#Q0QEf`0!Xi!!@m!!!Aj"Icq)3[q)3!d-!!BEh"PER0
 | 
			
		||||
cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!Xd
 | 
			
		||||
!!riJ!Xrq(`Vq)!!%#R4[)#!0!Xm!!Qi!!!B!"Jm#d!,4$3,3!!)d!!!'#!B2rKi
 | 
			
		||||
#dJVq(J!%#QCTE'80!Y)!!@d!!!B,"Ji#d``#d`!1!!K`Df0c-6)ZD!!#!!!0!Y%
 | 
			
		||||
!!M3!!!B!"JMq(3,8#[iG!!3+BfC[E!d#e!!"E`!!"J3'"riF#riF!"3`!!KdC@e
 | 
			
		||||
`F'&dD!!)G'9YF&"KG'J'rKm!!!)#b!!#!Y8#eJd#e3!#E!!#"KB'&[iErKS"rKX
 | 
			
		||||
!!!(q'J!!!J,@!!)#e`,B$3,A!!*b!!!'&JBK!YN#fJd#f3!#BJ!!"KB'(3,E!Y`
 | 
			
		||||
0!YX!!@m!!!B@"KRq'3[q'3!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4Qp
 | 
			
		||||
XC'9b8'&dD!d#h!!"E3!!"KN'(!,G$!,G!!`!"MT`Df0c0`!#!!!0!YS!!@m!!!!
 | 
			
		||||
!!!$q'![q'!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S!J,B!!)#hJ,I$3,H!!0*!!)
 | 
			
		||||
')JC-rKIq&J,J#[iA!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9XE!(q&J!!"J,
 | 
			
		||||
J!!2q&3,K!Z)+rK8!"!TVEf0X$3,K!!&Y!!!'*JBTrK3+rK3!"!TKE'PK"J,L!!2
 | 
			
		||||
q%`,M!Z3+rK-!"!TTER0S$3,M!!)d!!!',!BdrK)#j3Vq%J!%#Q0QEf`0!Z8!!@m
 | 
			
		||||
!!!B`"M2q%3[q%3!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0
 | 
			
		||||
-5@jME(9NC8C[E'4PFP"KG'J'!Z3!!ri3!ZEq$`Vq%!!%#R4[)#!0!ZB!!Qi!!!B
 | 
			
		||||
h"NB#j`,S$3,R!!)d!!!'2`C'rJi#k3Vq$J!%#QCTE'80!ZN!!@d!!!C#"N8#kJ`
 | 
			
		||||
#kJ!0!!G`Df0c0bjS!!)!!!d#k!!#0!!!"MF'2ri0!ZX+rJd!"!TMCQpX$3,V!!&
 | 
			
		||||
[!!!'1`BqrJ`,rJ`!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!Eq$`!!!J,I!!)#l!,
 | 
			
		||||
Y$3,X!!*X!!)'63C0rJ[q#J(q#`!!!Ii+!!!#!Zd!!J,Z!Zm0!Zi!!R)!!!C0"PJ
 | 
			
		||||
#m!,a$3,`!!*L!!!'63C8![)#m`d#mJ!"E`!!"Nd'82i*#ri*!#3`!""MFRP`G'p
 | 
			
		||||
QEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S$3,c!!&Y!!!'8!C6![3-![3!#`!
 | 
			
		||||
&1R*KEQ3!!J!!$3,a!!&[!!!!!!!!rJJ,rJJ!&$!!#(4PEA"`BA4S!!KdC@e`8'&
 | 
			
		||||
dD!)#l`!#![8#pJd#p3!$53!#"PN'Jri(rJB#p`Vq"`!B,Q0[FQ9MFQ9X+LSU+J!
 | 
			
		||||
!!!!!!*!!!'jeE'`"rJB!!!B#p`!$rJ8#q!,j#[i&!!3+DfpME!d#q!!"E3!!"Pd
 | 
			
		||||
'B2i%#[i%!!3+B@aTB3B#q3!$rJ-#qJ,l#[i$!!3+D@jcD!d#qJ!#0!!!"Q-'Dri
 | 
			
		||||
#![`+rJ)!"!TMCQpX$3,m!!&[!!!'C`CUrJ%,rJ%!0$!!''p`C@jcFfaTEQ0XG@4
 | 
			
		||||
PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J,l!!2q!!,prIm
 | 
			
		||||
+rJ!!"!TdEb!J$3,p!!*Z!!!'EJCp![i#r`d#rJ!#0!!!"RB'IIhq!`!+rIi!"!T
 | 
			
		||||
QD@aP$3-!!!&Y!!!'H3Cm!`%-!`%!$!!'FQ&ZC#jS!!)!!!d#r`!#0!!!"Qi'G[h
 | 
			
		||||
p!`)+rId!"!TMCQpX$3-#!!&[!!!'FJCerI`,rI`!&$!!#(4PEA"`BA4S!!KdC@e
 | 
			
		||||
`8'&dD!Epr`!!!J,f!!)$!`-%$3-$!!*X!!)'K!D%rI[pqJ(pq`!!!Ihk!!!#!`3
 | 
			
		||||
!!J-&!`B0!`8!!R)!!!D%"Sm$"`-)$3-(!!*L!!!'K!D,!`N$#Jd$#3!"E`!!"S3
 | 
			
		||||
'Krhj#rhj!#3`!""MFRP`G'pQEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S$3-
 | 
			
		||||
+!!&Y!!!'K`D+!`X-!`X!#J!%1R*M-J!#!!!0!`J!!@m!!!!!!!$pq![pq!!8-!!
 | 
			
		||||
)G'9YF("KG'J!#(4PEA"3BA4S!J-'!!)$$!-0$3--!!0*!!)'N!!'Z[hhrIB$$JV
 | 
			
		||||
pp`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"rIB!!!B$$J!$rI8$$`-3#[h
 | 
			
		||||
e!!3+DfpME!d$$`!"E3!!"T3'Prhd#[hd!!3+B@aTB3B$%!!$rI-$%3-5#[hc!!3
 | 
			
		||||
+D@jcD!d$%3!#0!!!"TS'S[hb!a-+rI)!"!TMCQpX$3-6!!&[!!!'RJDKrI%,rI%
 | 
			
		||||
!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'Efa
 | 
			
		||||
NCA*3BA4S"J-5!!2pm!-8rHm+rI!!"!TdEb!J$3-8!!*Z!!!'T3Dd!a8$&Jd$&3!
 | 
			
		||||
#0!!!"Ud'Y2hZ!aF+rHi!"!TQD@aP$3-A!!&Y!!!'X!Dc!aJ-!aJ!#`!&FQ-b,QJ
 | 
			
		||||
!!J!!$3-@!!)d!!!'T3DYrHd$'3Vpl3!%#Q0QEf`0!aN!!@m!!!DT"Ucpl![pl!!
 | 
			
		||||
8-!!)G'9YF("KG'J!#(4PEA"3BA4S"[h[!!!#!`d!!J-D!aX0!aS!!Q`!!JDl"V[
 | 
			
		||||
pkrhU!IhV!!!"rHS!!!)$'`!#!a`$(3d$(!!#FJ!!"VX'aJ-H!am0!ai!!Q)!!!D
 | 
			
		||||
l"X)$)!-K$3-J!!&[!!!'Z`DqrHN,rHN!*$!!%'0bHA"dEfC[E'4PFR"KG'J!%'0
 | 
			
		||||
bHA"dEdC[E'4PFP"KG'J0!b%!!@d!!!Dq"X%$)J`$)J!+!!3kFQ-d!!)!!!d$(`!
 | 
			
		||||
"E`!!!!!!!2hS#rhS!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J#!ad!!J-M!b30!b-
 | 
			
		||||
!!dN!!JE("[(pjrhQ!b8+rHF!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"ZG@aX!Ih
 | 
			
		||||
Q!!!'!b8!!rhP!bB$*`Vpj3!%#QY[Bf`0!bB!!@d!!!E,"Xlpj!Vpj!!%#Q&XD@%
 | 
			
		||||
'!bF!!rhM!bJ$+3Vpi`!%#QPZFfJ0!bJ!!M3!!!E4"YRpiJ-U#[hL!!3+BfC[E!d
 | 
			
		||||
$+J!"E`!!"Y8'f2hK#rhK!$3`!"K[F'9ZFh0XD@jME(9NC@C[E'4PFR"KG'J!''p
 | 
			
		||||
`C@j68da*EQ0XG@4P4QpXC'9b8'&dD!B$+3!$rH!$+rhI#[hJ!!3+G'mJ)!d$+`!
 | 
			
		||||
#EJ!!"Y`'k`-X!bd0!b`!!M3!!!EN"Z[phJ-Z#[hH!!3+CQPXC3d$,J!"E3!!"ZF
 | 
			
		||||
'kJ-[$!-[!!X!"A*M0#jS!!)!!!d$,3!#0!!!"Y`'j2hG!c!+rGd!"!TMCQpX$3-
 | 
			
		||||
`!!&[!!!'i!EMrG`,rG`!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!Eph`!!!J-N!!)
 | 
			
		||||
$-3-b$3-a!!*X!!)'mJEbrG[pfJ(pf`!!!IhD!!!#!c)!!J-c!c30!c-!!R)!!!E
 | 
			
		||||
b"[d$03-f$3-e!!*L!!!'mJEj!cF$1!d$0`!"E`!!"[)'pIhC#rhC!#3`!""MFRP
 | 
			
		||||
`G'pQEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S$3-i!!&Y!!!'p3Ei!cN-!cN
 | 
			
		||||
!#J!%1R*M03!#!!!0!cB!!@m!!!!!!!$pf![pf!!8-!!)G'9YF("KG'J!#(4PEA"
 | 
			
		||||
3BA4S!J-d!!)$1J-l$3-k!!0*!!)'rJFSrGIpeJ-m#[hA!"JZBfpbC@0bC@`U+LS
 | 
			
		||||
U!!!!!!!!N!!!ER9XE!(peJ!!"J-m!!2pe3-p!ci+rG8!"!TVEf0X$3-p!!&Y!!!
 | 
			
		||||
(!JF&rG3+rG3!"!TKE'PK"J-q!!2pd`-r!d!+rG-!"!TTER0S$3-r!!)d!!!(#!F
 | 
			
		||||
3rG)$33VpdJ!%#Q0QEf`0!d%!!@m!!!F-"`rpd3[pd3!d-!!BEh"PER0cE'PZBfa
 | 
			
		||||
eC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!d!!!rh3!d,
 | 
			
		||||
pc`Vpd!!%#R4[)#!0!d)!!Qi!!!F6"b)$3`0%$30$!!)d!!!('`FLrFi$43VpcJ!
 | 
			
		||||
%#QCTE'80!d8!!@d!!!FH"b%$4J`$4J!,!!9bBc8ZD!!#!!!0!d3!!M3!!!F6"a[
 | 
			
		||||
pc30(#[h0!!3+BfC[E!d$4`!"E`!!"aF('[h-#rh-!"3`!!KdC@e`F'&dD!!)G'9
 | 
			
		||||
YF&"KG'J'rFm!!!)$1`!#!dJ$53d$5!!#E!!#"bN(+Ih,rFS"rFX!!!(pbJ!!!J0
 | 
			
		||||
*!!)$5J0,$30+!!*b!!!(+3Fd!d`$63d$6!!#BJ!!"bN(-!01!dm0!di!!@m!!!F
 | 
			
		||||
T"bcpb3[pb3!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d
 | 
			
		||||
$6`!"E3!!"b`(,`03$!03!!d!"cTbDA"PE@3!!J!!$300!!&[!!!!!!!!rFJ,rFJ
 | 
			
		||||
!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!)$5`!#!e%$8Jd$83!$53!#"c8(Arh(rFB
 | 
			
		||||
$8`Vpa`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"rFB!!!B$8`!$rF8$9!0
 | 
			
		||||
9#[h&!!3+DfpME!d$9!!"E3!!"cN(22h%#[h%!!3+B@aTB3B$93!$rF-$9J0A#[h
 | 
			
		||||
$!!3+D@jcD!d$9J!#0!!!"cm(4rh#!eJ+rF)!"!TMCQpX$30B!!&[!!!(3`G'rF%
 | 
			
		||||
,rF%!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9
 | 
			
		||||
'EfaNCA*3BA4S"J0A!!2p`!0CrEm+rF!!"!TdEb!J$30C!!*Z!!!(5JGC!eS$@`d
 | 
			
		||||
$@J!#0!!!"e)(@Ifq!e`+rEi!"!TQD@aP$30F!!&Y!!!(93GB!ed-!ed!$J!)FQP
 | 
			
		||||
`C@eN,QJ!!J!!$30E!!)d!!!(5JG5rEd$AJVp[3!%#Q0QEf`0!ei!!@m!!!G1"e(
 | 
			
		||||
p[![p[!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S"[fr!!!#!e)!!J0I!f!0!em!!Q`
 | 
			
		||||
!!JGJ"f$pZrfk!Ifl!!!"rES!!!)$B!!#!f%$BJd$B3!#FJ!!"f!(D`0M!f30!f-
 | 
			
		||||
!!Q)!!!GJ"fF$C30Q$30P!!&[!!!(B!GMrEN,rEN!*$!!%'0bHA"dEfC[E'4PFR"
 | 
			
		||||
KG'J!%'0bHA"dEdC[E'4PFP"KG'J0!fB!!@d!!!GM"fB$C``$C`!+!!3kFR0K!!)
 | 
			
		||||
!!!d$C!!"E`!!!!!!!2fi#rfi!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J#!f)!!J0
 | 
			
		||||
S!fN0!fJ!!dN!!JGX"jEpYrff!fS+rEF!'#jMEh*PBh*PE#SU+LS!!!!!!!#3!!"
 | 
			
		||||
ZG@aX!Iff!!!'!fS!!rfe!fX$E!VpY3!%#QY[Bf`0!fX!!@d!!!G`"h2pY!VpY!!
 | 
			
		||||
%#Q&XD@%'!f`!!rfc!fd$EJVpX`!%#QPZFfJ0!fd!!M3!!!Gf"hlpXJ0[#[fb!!3
 | 
			
		||||
+BfC[E!d$E`!"E`!!"hS(IIfa#rfa!$3`!"K[F'9ZFh0XD@jME(9NC@C[E'4PFR"
 | 
			
		||||
KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&dD!B$EJ!$rE!$F2f[#[f`!!3+G'm
 | 
			
		||||
J)!d$F!!#EJ!!"i%(N!!$F30b$30a!!)d!!!(L3H3!2fZ!h-+rDi!"!TQD@aP$30
 | 
			
		||||
c!!&Y!!!(M!H2!h3-!h3!#`!&FR0K,QJ!!J!!$30b!!)d!!!(J3H*rDd$G3VpV3!
 | 
			
		||||
%#Q0QEf`0!h8!!@m!!!H&"iMpV![pV!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S"[f
 | 
			
		||||
[!!!#!fN!!J0f!hF0!hB!!Q`!!JHA"jIpUrfU!IfV!!!"rDS!!!)$G`!#!hJ$H3d
 | 
			
		||||
$H!!#FJ!!"jF(SJ0k!hX0!hS!!Q)!!!HA"ji$I!0p$30m!!&[!!!(P`HDrDN,rDN
 | 
			
		||||
!*$!!%'0bHA"dEfC[E'4PFR"KG'J!%'0bHA"dEdC[E'4PFP"KG'J0!hd!!@d!!!H
 | 
			
		||||
D"jd$IJ`$IJ!-!!BkFh4KBfX!!J!!$30l!!&[!!!!!!!!rDJ,rDJ!&$!!#(4PEA"
 | 
			
		||||
`BA4S!!KdC@e`8'&dD!)$H3!#!hm$J!d$I`!$53!#"k-(cIfRrDB$J3VpT`!B,Q0
 | 
			
		||||
[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"rDB!!!B$J3!$rD8$JJ1$#[fP!!3+Dfp
 | 
			
		||||
ME!d$JJ!"E3!!"kF(U[fN#[fN!!3+B@aTB3B$J`!$rD-$K!1&#[fM!!3+D@jcD!d
 | 
			
		||||
$K!!#0!!!"kd(YIfL!iB+rD)!"!TMCQpX$31'!!&[!!!(X3HdrD%,rD%!0$!!''p
 | 
			
		||||
`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4
 | 
			
		||||
S"J1&!!2pS!1(rCm+rD!!"!TdEb!J$31(!!*Z!!!(Z!I(!iJ$L3d$L!!#0!!!"m!
 | 
			
		||||
(arfH!iS+rCi!"!TQD@aP$31+!!&Y!!!(``I'!iX-!iX!$3!(Fh4KBfXZD!!#!!!
 | 
			
		||||
0!iN!!M3!!!Hi"m$pR31-#[fG!!3+BfC[E!d$M!!"E`!!"l`([rfF#rfF!"3`!!K
 | 
			
		||||
dC@e`F'&dD!!)G'9YF&"KG'J'rCm!!!)$J!!#!id$MJd$M3!$53!#"mi(q2fErCS
 | 
			
		||||
$M`VpQ`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"rCS!!!B$M`!$rCN$N!!
 | 
			
		||||
$N3VpQ3!%#QY[Bf`0!j!!!!&Y!!!(dJI9rCJ+rCJ!"!TKE'PK"J14!!2pP`15!j-
 | 
			
		||||
+rCF!"!TTER0S$315!!)d!!!(f!IJrCB$P!VpPJ!%#Q0QEf`0!j3!!@m!!!IF"pr
 | 
			
		||||
pP3[pP3!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9
 | 
			
		||||
NC8C[E'4PFP"KG'J'!j-!!rf8!jApN`VpP!!%#R4[)#!0!j8!!Qi!!!IM"r)$PJ1
 | 
			
		||||
A$31@!!)d!!!(k`IbrC)$Q!VpNJ!%#QCTE'80!jJ!!@d!!!IZ"r%$Q3`$Q3!4!!Y
 | 
			
		||||
cB@CPFh4KBfXZD!!#!!!0!jF!!M3!!!IM"q[pN31D#[f4!!3+BfC[E!d$QJ!"E`!
 | 
			
		||||
!"qF(k[f3!![pN!!!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!EpN`!!!J11!!)$Q`1
 | 
			
		||||
F$31E!!*X!!)(q3IjrBrpMJ(pM`!!!If1!!!#!j`!!J1G!ji0!jd!!R)!!!Ij#!3
 | 
			
		||||
$R`1J$31I!!*L!!!(q3J!!k%$SJd$S3!"E`!!"rN(r2f0#rf0!#3`!""MFRP`G'p
 | 
			
		||||
QEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S$31L!!&Y!!!(r!Ir!k--!k-!#J!
 | 
			
		||||
%1R0SB3!#!!!0!k!!!@m!!!!!!!$pM![pM!!8-!!)G'9YF("KG'J!#(4PEA"3BA4
 | 
			
		||||
S!J1H!!)$T!1P$31N!!0*!!))"3J[rB[pLJ1Q#[f,!"JZBfpbC@0bC@`U+LSU!!!
 | 
			
		||||
!!!!!N!!!ER9XE!(pLJ!!"J1Q!!2pL31R!kJ+rBN!"!TVEf0X$31R!!&Y!!!)#3J
 | 
			
		||||
-rBJ+rBJ!"!TKE'PK"J1S!!2pK`1T!kS+rBF!"!TTER0S$31T!!)d!!!)$`JArBB
 | 
			
		||||
$U`VpKJ!%#Q0QEf`0!kX!!@m!!!J6#"EpK3[pK3!d-!!BEh"PER0cE'PZBfaeC'9
 | 
			
		||||
QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!kS!!rf%!kcpJ`V
 | 
			
		||||
pK!!%#R4[)#!0!k`!!Qi!!!JD##N$V31Z$31Y!!)d!!!))JJTrB)$V`VpJJ!%#QC
 | 
			
		||||
TE'80!km!!@d!!!JP##J$X!`$X!!,!!9cD'%ZD!!#!!!0!ki!!M3!!!JD##,pJ31
 | 
			
		||||
a#[f"!!3+BfC[E!d$X3!"E`!!#"i))If!#rf!!"3`!!KdC@e`F'&dD!!)G'9YF&"
 | 
			
		||||
KG'J'rB-!!!)$T3!#!l)$X`d$XJ!#E!!##$!)-2errAi"rAm!!!(pIJ!!!J1c!!)
 | 
			
		||||
$Y!1e$31d!!*b!!!)-!Jl!lB$Y`d$YJ!#BJ!!#$!)0`1i!lN0!lJ!!@m!!!J`#$2
 | 
			
		||||
pI3[pI3!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD!d$Z3!
 | 
			
		||||
"E3!!#$-)0J1k$!1k!!d!"cTdH(4IC')!!J!!$31h!!&[!!!!!!!!rA`,rA`!&$!
 | 
			
		||||
!#(4PEA"`BA4S!!KdC@e`8'&dD!)$Y3!#!lX$[!d$Z`!$53!##$`)C[elrAS$[3V
 | 
			
		||||
pH`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"rAS!!!B$[3!$rAN$[J1r#[e
 | 
			
		||||
j!!3+DfpME!d$[J!"E3!!#%!)3rei#[ei!!3+B@aTB3B$[`!$rAF$`!2"#[eh!!3
 | 
			
		||||
+D@jcD!d$`!!#0!!!#%B)6[ef!m)+rAB!"!TMCQpX$32#!!&[!!!)5JK0rA8,rA8
 | 
			
		||||
!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'Efa
 | 
			
		||||
NCA*3BA4S"J2"!!2pG!2$rA-+rA3!"!TdEb!J$32$!!*Z!!!)83KJ!m3$a3d$a!!
 | 
			
		||||
#0!!!#&N)B2eb!mB+rA)!"!TQD@aP$32'!!&Y!!!)A!KI!mF-!mF!$J!)G(KdAf4
 | 
			
		||||
L,QJ!!J!!$32&!!)d!!!)83KCrA%$b!VpF3!%#Q0QEf`0!mJ!!@m!!!K9#&MpF![
 | 
			
		||||
pF!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S"[ec!!!#!l`!!J2*!mS0!mN!!Q`!!JK
 | 
			
		||||
R#'IpEreZ!Ie[!!!"r@i!!!)$bJ!#!mX$c!d$b`!#FJ!!#'F)FJ20!mi0!md!!Q)
 | 
			
		||||
!!!KR#'i$c`23$322!!&[!!!)C`KUr@d,r@d!*$!!%'0bHA"dEfC[E'4PFR"KG'J
 | 
			
		||||
!%'0bHA"dEdC[E'4PFP"KG'J0!p!!!@d!!!KU#'d$d3`$d3!,!!8kH$8`13!#!!!
 | 
			
		||||
0!mi!!@m!!!!!!!$pE![pE!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S!J2-!!)$dJ2
 | 
			
		||||
6$325!!0*!!))F`LGr@[pDJ28#[eV!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9
 | 
			
		||||
XE!(pDJ!!"J28!!2pD329!pB+r@N!"!TVEf0X$329!!&Y!!!)G`Kkr@J+r@J!"!T
 | 
			
		||||
KE'PK"J2@!!2pC`2A!pJ+r@F!"!TTER0S$32A!!)d!!!)I3L&r@B$f3VpCJ!%#Q0
 | 
			
		||||
QEf`0!pN!!@m!!!L"#)6pC3[pC3!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4
 | 
			
		||||
S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'!pJ!!reN!pVpB`VpC!!%#R4[)#!
 | 
			
		||||
0!pS!!Qi!!!L)#*F$f`2F$32E!!)d!!!)N!!)PreL!pd+r@)!"!TQD@aP$32G!!&
 | 
			
		||||
Y!!!)N`L@!pi-!pi!$!!'H$8`15jS!!)!!!d$h!!#0!!!#)J)N!$pB32I#[eK!!3
 | 
			
		||||
+BfC[E!d$h`!"E`!!#)`)MreJ#reJ!"3`!!KdC@e`F'&dD!!)G'9YF&"KG'J'r@-
 | 
			
		||||
!!!)$d`!#!q!$i3d$i!!$53!##*i)b2eIr9i$iJVpA`!B,Q0[FQ9MFQ9X+LSU+J!
 | 
			
		||||
!!!!!!*!!!'jeE'`"r9i!!!B$iJ!$r9d$i`2N#[eG!!3+DfpME!d$i`!"E3!!#+)
 | 
			
		||||
)TIeF#[eF!!3+B@aTB3B$j!!$r9X$j32Q#[eE!!3+D@jcD!d$j3!#0!!!#+J)X2e
 | 
			
		||||
D!qF+r9S!"!TMCQpX$32R!!&[!!!)V!L[r9N,r9N!0$!!''p`C@jcFfaTEQ0XG@4
 | 
			
		||||
PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J2Q!!2p@!2Sr9F
 | 
			
		||||
+r9J!"!TdEb!J$32S!!*Z!!!)X`M#!qN$kJd$k3!#0!!!#,X)`[e@!qX+r9B!"!T
 | 
			
		||||
QD@aP$32V!!&Y!!!)[JM"!q`-!q`!%!!+H$8`19pfCRNZD!!#!!!0!qS!!M3!!!L
 | 
			
		||||
c#,[p932Y#[e9!!3+BfC[E!d$l3!"E`!!#,F)Z[e8#re8!"3`!!KdC@e`F'&dD!!
 | 
			
		||||
)G'9YF&"KG'J'r9F!!!)$i3!#!qi$l`d$lJ!#E!!##-N)bIe6r9)"r9-!!!(p8J!
 | 
			
		||||
!!J2[!!)$m!2a$32`!!*b!!!)b3M8!r)$m`d$mJ!#BJ!!#-N)d!2d!r80!r3!!@m
 | 
			
		||||
!!!M*#-cp83[p83!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&
 | 
			
		||||
dD!d$p3!"E3!!#-`)c`2f$!2f!!d!"cTi06!jGM-!!J!!$32c!!&[!!!!!!!!r9!
 | 
			
		||||
,r9!!&$!!#(4PEA"`BA4S!!KdC@e`8'&dD!)$m3!#!rF$q!d$p`!$53!##08)rre
 | 
			
		||||
2r8i$q3Vp6`!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"r8i!!!B$q3!$r8d
 | 
			
		||||
$qJ2l#[e0!!3+DfpME!d$qJ!"E3!!#0N)h2e-#[e-!!3+B@aTB3B$q`!$r8X$r!2
 | 
			
		||||
p#[e,!!3+D@jcD!d$r!!#0!!!#0m)jre+!ri+r8S!"!TMCQpX$32q!!&[!!!)i`M
 | 
			
		||||
Qr8N,r8N!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfa
 | 
			
		||||
eC'9'EfaNCA*3BA4S"J2p!!2p5!2rr8F+r8J!"!TdEb!J$32r!!*Z!!!)kJMj"!!
 | 
			
		||||
%!3d%!!!#0!!!#2))qIe'"!)+r8B!"!TQD@aP$33#!!&Y!!!)p3Mi"!--"!-!$J!
 | 
			
		||||
)H$8`1ABc,QJ!!J!!$33"!!)d!!!)kJMbr88%"!Vp43!%#Q0QEf`0"!3!!@m!!!M
 | 
			
		||||
Z#2(p4![p4!!8-!!)G'9YF("KG'J!#(4PEA"3BA4S"[e(!!!#!rJ!!J3&"!B0"!8
 | 
			
		||||
!!Q`!!JN!#3$p3re#!Ie$!!!"r8)!!!)%"J!#"!F%#!d%"`!$53!##3!*+[e"r8!
 | 
			
		||||
%#3Vp33!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"r8!!!!B%#3!$r6m%#J3
 | 
			
		||||
,#[dr!!3+DfpME!d%#J!"E3!!#33*"rdq#[dq!!3+B@aTB3B%#`!$r6d%$!30#[d
 | 
			
		||||
p!!3+D@jcD!d%$!!#0!!!#3S*%[dm"!i+r6`!"!TMCQpX$331!!&[!!!*$JN4r6X
 | 
			
		||||
,r6X!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9
 | 
			
		||||
'EfaNCA*3BA4S"J30!!2p1J32r6N+r6S!"!TdEb!J$332!!*Z!!!*&3NN""!%%3d
 | 
			
		||||
%%!!#0!!!#4d**2di"")+r6J!"!TQD@aP$335!!&Y!!!*)!NM""--""-!#`!&Fh0
 | 
			
		||||
X,QJ!!J!!$334!!)d!!!*&3NGr6F%&!Vp0`!%#Q0QEf`0""3!!@m!!!NC#4cp0J[
 | 
			
		||||
p0J!H-!!0Fh0XCQpXC'9bF'&dD!!0Fh0X4QpXC'9b8'&dD!Ep13!!!J3)!!)%&33
 | 
			
		||||
@$339!!0*!!)*+`P9r6Ap0!3A#[de!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9
 | 
			
		||||
XE!(p0!!!"J3A!!2p-`3B""N+r6-!"!TVEf0X$33B!!&Y!!!*,`Nbr6)+r6)!"!T
 | 
			
		||||
KE'PK"J3C!!2p-33D""X+r6%!"!TTER0S$33D!!)d!!!*03Npr6!%(!Vp-!!%#Q0
 | 
			
		||||
QEf`0""`!!@m!!!Nj#6cp,`[p,`!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4
 | 
			
		||||
S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'""X!!rdZ""hp,3Vp,J!%#R4[)#!
 | 
			
		||||
0""d!!Qi!!!P!#8m%(J3I$33H!!)d!!!*5!P2r5`%)!Vp,!!%#QCTE'80"#!!!@d
 | 
			
		||||
!!!P,#8i%)3`%)3!-!!CcFf`b,QJ!!J!!$33I!!)d!!!*3!P)r5X%)JVp+`!%#Q0
 | 
			
		||||
QEf`0"#)!!@m!!!P%#8Ip+J[p+J!H-!!0Fh0XCQpXC'9bF'&dD!!0Fh0X4QpXC'9
 | 
			
		||||
b8'&dD!Ep,3!!!J3@!!)%)`3N$33M!!0*!!)*9JQ!r5Rp+!3P#[dT!"JZBfpbC@0
 | 
			
		||||
bC@`U+LSU!!!!!!!!N!!!ER9XE!(p+!!!"J3P!!2p*`3Q"#F+r5F!"!TVEf0X$33
 | 
			
		||||
Q!!&Y!!!*@JPGr5B+r5B!"!TKE'PK"J3R!!2p*33S"#N+r58!"!TTER0S$33S!!)
 | 
			
		||||
d!!!*B!PSr53%+JVp*!!%#Q0QEf`0"#S!!@m!!!PN#@Ip)`[p)`!d-!!BEh"PER0
 | 
			
		||||
cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'"#N
 | 
			
		||||
!!rdL"#[p)3Vp)J!%#R4[)#!0"#X!!Qi!!!PV#AS%,!3Y$33X!!)d!!!*F`Pkr5!
 | 
			
		||||
%,JVp)!!%#QCTE'80"#i!!@d!!!Pf#AN%,``%,`!0!!GcFf`b-bjS!!)!!!d%,3!
 | 
			
		||||
#0!!!#@X*FrdI"$!+r4m!"!TMCQpX$33`!!&[!!!*E`Pbr4i,r4i!(M!!$A0cE'C
 | 
			
		||||
[E'4PFR"KG'J!$A0cE%C[E'4PFP"KG'J'r5%!!!)%*!!#"$%%-Jd%-3!$53!##B%
 | 
			
		||||
*UrdGr4`%-`Vp(3!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"r4`!!!B%-`!
 | 
			
		||||
$r4X%0!3e#[dE!!3+DfpME!d%0!!"E3!!#B8*L2dD#[dD!!3+B@aTB3B%03!$r4N
 | 
			
		||||
%0J3h#[dC!!3+D@jcD!d%0J!#0!!!#BX*NrdB"$J+r4J!"!TMCQpX$33i!!&[!!!
 | 
			
		||||
*M`Q5r4F,r4F!0$!!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%P
 | 
			
		||||
ZBfaeC'9'EfaNCA*3BA4S"J3h!!2p&J3jr48+r4B!"!TdEb!J$33j!!*Z!!!*PJQ
 | 
			
		||||
P"$S%1`d%1J!#0!!!#Ci*TId8"$`+r43!"!TQD@aP$33m!!&Y!!!*S3QN"$d-"$d
 | 
			
		||||
!$!!'Fh0X-bjS!!)!!!d%1`!#0!!!#CB*R[d6"$i+r4-!"!TMCQpX$33q!!&[!!!
 | 
			
		||||
*QJQGr4),r4)!(M!!$A0cE'C[E'4PFR"KG'J!$A0cE%C[E'4PFP"KG'J'r48!!!)
 | 
			
		||||
%-J!#"$m%3!d%2`!$53!##D`*e[d4r4!%33Vp%3!B,Q0[FQ9MFQ9X+LSU+J!!!!!
 | 
			
		||||
!!*!!!'jeE'`"r4!!!!B%33!$r3m%3J4$#[d2!!3+DfpME!d%3J!"E3!!#E!*Xrd
 | 
			
		||||
1#[d1!!3+B@aTB3B%3`!$r3d%4!4&#[d0!!3+D@jcD!d%4!!#0!!!#EB*[[d-"%B
 | 
			
		||||
+r3`!"!TMCQpX$34'!!&[!!!*ZJQpr3X,r3X!0$!!''p`C@jcFfaTEQ0XG@4PCQp
 | 
			
		||||
XC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*3BA4S"J4&!!2p#J4(r3N+r3S
 | 
			
		||||
!"!TdEb!J$34(!!*Z!!!*`3R3"%J%53d%5!!#0!!!#FN*d2d)"%S+r3J!"!TQD@a
 | 
			
		||||
P$34+!!&Y!!!*c!R2"%X-"%X!$!!'G'ac-5jS!!)!!!d%53!#0!!!#F%*bId("%`
 | 
			
		||||
+r3F!"!TMCQpX$34-!!&[!!!*a3R)r3B,r3B!(M!!$A0cE'C[E'4PFR"KG'J!$A0
 | 
			
		||||
cE%C[E'4PFP"KG'J'r3N!!!)%3!!#"%d%6Jd%63!#E!!##GF*erd&r33"r38!!!(
 | 
			
		||||
p"!!!!J41!!)%6`43$342!!0*!!)*e`S"r32p!J44#[d$!"JZBfpbC@0bC@`U+LS
 | 
			
		||||
U!!!!!!!!N!!!ER9XE!(p!J!!"J44!!2p!345"&-+r3%!"!TVEf0X$345!!&Y!!!
 | 
			
		||||
*f`RHr3!+r3!!"!TKE'PK"J46!!2mr`48"&8+r2m!"!TTER0S$348!!)d!!!*i3R
 | 
			
		||||
Tr2i%9JVmrJ!%#Q0QEf`0"&B!!@m!!!RP#HMmr3[mr3!d-!!BEh"PER0cE'PZBfa
 | 
			
		||||
eC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9NC8C[E'4PFP"KG'J'"&8!!rcm"&I
 | 
			
		||||
mq`Vmr!!%#R4[)#!0"&F!!Qi!!!RX#IX%@!4C$34B!!)d!!!*p!Rlr2S%@JVmqJ!
 | 
			
		||||
%#QCTE'80"&S!!@d!!!Rh#IS%@``%@`!1!!KMFRP`G'mZD!!#!!!0"&N!!M3!!!R
 | 
			
		||||
X#I6mq34F#[cj!!3+BfC[E!d%A!!"E`!!#I!*mrci#rci!#3`!""MFRP`G'pQEfa
 | 
			
		||||
NCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S"[cl!!!#"&!!!J4G"&i0"&d!!Q`!!JS
 | 
			
		||||
##J,mprcf!Ich!!!"r2B!!!)%AJ!#"&m%B!d%A`!$53!##J)+,2cer23%B3Vmp3!
 | 
			
		||||
B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"r23!!!B%B3!$r2-%BJ4M#[cc!!3
 | 
			
		||||
+DfpME!d%BJ!"E3!!#JB+#Icb#[cb!!3+B@aTB3B%B`!$r2%%C!4P#[ca!!3+D@j
 | 
			
		||||
cD!d%C!!#0!!!#J`+&2c`"'B+r2!!"!TMCQpX$34Q!!&[!!!+%!S6r1m,r1m!0$!
 | 
			
		||||
!''p`C@jcFfaTEQ0XG@4PCQpXC'9bF'&dD!!BEh"PEP066%PZBfaeC'9'EfaNCA*
 | 
			
		||||
3BA4S"J4P!!2mlJ4Rr1d+r1i!"!TdEb!J$34R!!*Z!!!+&`SQ"'J%D3d%D!!#0!!
 | 
			
		||||
!#Km+*[cX"'S+r1`!"!TQD@aP$34U!!&Y!!!+)JSP"'X-"'X!%!!+Eh"PER0cE(B
 | 
			
		||||
ZD!!#!!!0"'N!!M3!!!SA#Krmk`4X#[cV!!3+BfC[E!d%E!!"E`!!#KX+([cU#rc
 | 
			
		||||
U!#3`!""MFRP`G'pQEfaNCA*`BA4S!""MFRP`G'p'EfaNCA*3BA4S"[cY!!!#"'!
 | 
			
		||||
!!J4Y"'i0"'d!!dN!!JSY#PImkIcS"'m+r1N!'#jMEh*PBh*PE#SU+LS!!!!!!!#
 | 
			
		||||
3!!"ZG@aX!IcS!!!'"'m!!rcR"(!%F3Vmj`!%#QY[Bf`0"(!!!@d!!!Sa#M6mjJV
 | 
			
		||||
mjJ!%#Q&XD@%'"(%!!rcP"()%F`Vmj3!%#QPZFfJ0"()!!M3!!!Sh#Mrmj!4d#[c
 | 
			
		||||
N!!3+BfC[E!d%G!!"E`!!#MX+2[cM#rcM!$3`!"K[F'9ZFh0XD@jME(9NC@C[E'4
 | 
			
		||||
PFR"KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&dD!B%F`!$r1)%GIcK#[cL!!3
 | 
			
		||||
+G'mJ)!d%G3!#EJ!!#N)+834f"(F0"(B!!M3!!!T+#P(mi!4i#[cJ!!3+CQPXC3d
 | 
			
		||||
%H!!"E3!!#Nd+8!4j$!4j!!i!#(4YC'PQCLjS!!)!!!d%G`!#0!!!#N)+5[cI"(S
 | 
			
		||||
+r0m!"!TMCQpX$34k!!&[!!!+4JT*r0i,r0i!*$!!%'0bHA"dEfC[E'4PFR"KG'J
 | 
			
		||||
!%'0bHA"dEdC[E'4PFP"KG'J'r1%!!!)%EJ!#"(X%I!d%H`!#E!!##PJ+@2cGr0`
 | 
			
		||||
"r0d!!!(mh!!!!J4m!!)%I34q$34p!!*X!!)+@!TBr0[mfJ(mf`!!!IcD!!!#"(i
 | 
			
		||||
!!J4r")!0"(m!!dN!!JTB#S,mfIcB")%+r0N!'#jMEh*PBh*PE#SU+LS!!!!!!!#
 | 
			
		||||
3!!"ZG@aX!IcB!!!'")%!!rcA"))%J`Vme`!%#QY[Bf`0"))!!@d!!!TF#PrmeJV
 | 
			
		||||
meJ!%#Q&XD@%'")-!!rc9")3%K3Vme3!%#QPZFfJ0")3!!M3!!!TL#QVme!5'#[c
 | 
			
		||||
8!!3+BfC[E!d%KJ!"E`!!#QB+DIc6#rc6!$3`!"K[F'9ZFh0XD@jME(9NC@C[E'4
 | 
			
		||||
PFR"KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&dD!B%K3!$r0)%Krc4#[c5!!3
 | 
			
		||||
+G'mJ)!d%K`!#EJ!!#Qd+I!5)")N0")J!!M3!!!Te#Rcmd!5+#[c3!!3+CQPXC3d
 | 
			
		||||
%LJ!"E3!!#RJ+H`5,$!5,!!`!"Q9IEh-ZD!!#!!!0")N!!M3!!!TY#RAmc`5-#[c
 | 
			
		||||
2!!3+BfC[E!d%M!!"E`!!#R%+G2c1#rc1!#B`!"&[F'9ZFh0XCQpXC'9bF'&dD!!
 | 
			
		||||
4Eh"PER0cE%C[E'4PFP"KG'J'r0%!!!)%J!!#")d%MJd%M3!$53!##S-+VIc0r-`
 | 
			
		||||
%M`Vmc3!B,Q0[FQ9MFQ9X+LSU+J!!!!!!!*!!!'jeE'`"r-`!!!B%M`!$r-X%N!!
 | 
			
		||||
%N3Vmb`!%#QY[Bf`0"*!!!!&Y!!!+K`U+r-S+r-S!"!TKE'PK"J54!!2mb355"*-
 | 
			
		||||
+r-N!"!TTER0S$355!!)d!!!+M3U9r-J%P!Vmb!!%#Q0QEf`0"*3!!@m!!!U4#T6
 | 
			
		||||
ma`[ma`!d-!!BEh"PER0cE'PZBfaeC'9QEfaNCA*`BA4S!"K[F'9Z8e0-5@jME(9
 | 
			
		||||
NC8C[E'4PFP"KG'J'"*-!!rc'"*Ama3VmaJ!%#R4[)#!0"*8!!Qi!!!UB#UF%PJ5
 | 
			
		||||
A$35@!!)d!!!+S!URr-3%Q!Vma!!%#QCTE'80"*J!!@d!!!UM#UB%Q3`%Q3!0!!G
 | 
			
		||||
PAfpc-LjS!!)!!!d%P`!#0!!!#TJ+S2c$"*S+r--!"!TMCQpX$35D!!&[!!!+R!U
 | 
			
		||||
Ir-),r-)!*M!!%@p`C@jcFfaQEfaNCA*`BA4S!"&[F'9ZFh0X4QpXC'9b8'&dD!E
 | 
			
		||||
ma3!!!J51!!)%Qrc"$35E!!*X!!)+VJUZr-$m[`(m`!!!!Ibr!!!#r-%!!!d!#3!
 | 
			
		||||
"E3!!!!!!!3!I!Irq!!!#!!B!!J5F"*d0"*`!!Q`!!J!!!!$m[[bp!Ibq!!!"r,d
 | 
			
		||||
!!!)%R3!#"*i%R`d%RJ!#E!!##V%+b!5Jr,`0"+!!!dN!!JUa#XMmZ`5K"+)+r,X
 | 
			
		||||
!'#jcHA0[C'a[Cf&cDh)!!!!!!!!!!&4&@&30"+%!!@d!!!Ua#V3%S``%S`!'!!!
 | 
			
		||||
!!J!!"J5L!!2mZJ5N"+8+r,S!"!TLG'jc$35N!!&+!!!+Y`Um"+B#"+B!!J5Rr,N
 | 
			
		||||
0"+F!!@d!!!Uh#VS%U!`%U!!+!!4%EfjP!!)!!!,mZ3!!"J5P!!2mZ!5Tr,F+r,J
 | 
			
		||||
!"!TRDACe$35T!!&Y!!!+[`V#r,B$r,B!"3EmY`!!!Ibm!!!#"*m!!J5Ur,80"+S
 | 
			
		||||
!!Q`!!J!!!!$mY2bc!Ibd!!!"r,-!!!,mY3!!$J!#!!!2%!!$!",mXJ5V"+`%V35
 | 
			
		||||
Z"+m%X!5a",)%X`5d",8%YJ5hr,(mX2b[r+i"r,)!!"!%U`!3r+hmV2bVr+VmUIb
 | 
			
		||||
Sr+ImT[bPr+6mSrbLr+(mS2bIr*i+r+d!'#jKCACdEf&`F'jeE'`!!)!!!!#3!!!
 | 
			
		||||
U+LSU#rbX!")`!!GdD'9`BA4S!!GdD'93BA4S#rbV!"``!!adD'9[E'4NC@aTEA-
 | 
			
		||||
!$(4SC8pXC%4PE'PYF`[mUJ!J-!!1G'KPF(*[DQ9MG("KG'J!$R4SC9"bEfTPBh4
 | 
			
		||||
3BA4S#rbT!"B`!!PdD'9YCA"KG'J!#A4SC8eP8'&dD![mU!!Q-!!4D@jME(9NC@C
 | 
			
		||||
[E'4PFR"KG'J!%@PZBfaeC'9'EfaNCA*3BA4S#rbR!$3`!"K[F'9ZFh0XD@jME(9
 | 
			
		||||
NC@C[E'4PFR"KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&dD![mTJ!N-!!3Bh*
 | 
			
		||||
jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD![mT3!H-!!0Fh0XCQpXC'9
 | 
			
		||||
bF'&dD!!0Fh0X4QpXC'9b8'&dD![mT!!Q-!!4Eh"PER0cE'C[E'4PFR"KG'J!%@p
 | 
			
		||||
`C@jcFfa'EfaNCA*3BA4S#rbM!#i`!"9dD'9ZCAGQEfaNCA*bC@CPFQ9ZBf8!&A4
 | 
			
		||||
SC8jPGdC[E'4PFP*PCQ9bC@jMC3[mSJ!8-!!)G'9YF("KG'J!#(4PEA"3BA4S!Ib
 | 
			
		||||
K!!!"r+!!!!(mR`!!!IbH!!!1"+`!"a$mR35ir*cmQ`5j",VmQJVmR3!B,Q&PGR4
 | 
			
		||||
[BA"`ER9XE!!!J!!!!*!!!#SU+LS0",J!!@X!!!!!#XJ%Z`)%Z`!#!!8%[!)%[!!
 | 
			
		||||
#"*lmQ3,mQ3!!!IbF!!!#r*X!!"!%Z3!!%!5k!)B!(rbBr*ImP[b9r*6mNrb5!#c
 | 
			
		||||
mNIb3!2b2r)lmMIb-!%rmL`"D!&[mLJ"Nr)N!EIb)r)ImKJ#2r)AmK2b$r),mJIb
 | 
			
		||||
!r(rmI[apr(cmH`#Tr(VmHIair(F![Iaf!-ImG3$8!1)!l!$j!3-"%!%D!5F"-3%
 | 
			
		||||
q!8J"93&I!@`"GJ'$!Bd"QJ'N!E%"Z`()!G)"h`(T!IB#!!)0!KF#*!)Z!MX#43*
 | 
			
		||||
5!P`#D3*c!S!#LJ+A!U%#VJ+m!XB#d`,G!ZS#p!-"!`X$'!-L!bm$130'!e!$A30
 | 
			
		||||
R!h3$IJ1,!jN$S`1`!lS$a`24!pi$l!2f"!-%%`3K"#m%234,"&X%D`4j")X%Q35
 | 
			
		||||
Mr(3%U2acr(,mF3VmQ!!%#Q0[BQS+r*F!'#jPBA*cCQCNFQ&XDA-!!!!!!!!J!'&
 | 
			
		||||
QC()+r*B!"!TMG(Kd#rb9!")`!!GdD'9`BA4S!!GdD'93BA4S#[b8!!3+BA0MFJV
 | 
			
		||||
mN`!%#R4iC'`,r*)!($!!$(4SC@pXC'4PE'PYF`!-G'KP6faN4'9XD@ec#[b4!!3
 | 
			
		||||
+BfPdE32mN!$rr3[mM`!J-!!1G'KPF(*[DQ9MG("KG'J!$R4SC9"bEfTPBh43BA4
 | 
			
		||||
S!rb1rri+r)d!"!T849K8#rb-!"B`!!PdD'9YCA"KG'J!#A4SC8eP8'&dD![mL`!
 | 
			
		||||
Q-!!4D@jME(9NC@C[E'4PFR"KG'J!%@PZBfaeC'9'EfaNCA*3BA4S#rb+!$3`!"K
 | 
			
		||||
[F'9ZFh0XD@jME(9NC@C[E'4PFR"KG'J!''p`C@j68da*EQ0XG@4P4QpXC'9b8'&
 | 
			
		||||
dD![mL3!N-!!3Bh*jF(4[CQpXC'9bF'&dD!!3Bh*jF(4[4QpXC'9b8'&dD![mL!!
 | 
			
		||||
H-!!0Fh0XCQpXC'9bF'&dD!!0Fh0X4QpXC'9b8'&dD![mK`!Q-!!4Eh"PER0cE'C
 | 
			
		||||
[E'4PFR"KG'J!%@p`C@jcFfa'EfaNCA*3BA4S#[b'!!3+BfC[E!VmK3!B,QeTFf0
 | 
			
		||||
cE'0d+LSU+J!!!!!!!*!!!#SU+LS+r)3!"!TcC@aP#[b$!"JZBfpbC@4PE'mU+LS
 | 
			
		||||
U!!!!!!!!N!!!+LSU+J(mJJ!!![b"!!!+r)!!"!TVEf0X#[ar!!3+D@jcD!2mIJ!
 | 
			
		||||
%#[ap!"JZBfpbC@0bC@`U+LSU!!!!!!!!N!!!ER9XE!VmI!!%#R*cE(3,r(X!,M!
 | 
			
		||||
!&A4SC@jPGfC[E'4PFR*PCQ9bC@jMC3!9G'KP6Q9h4QpXC'9b8Q9QCA*PEQ0P#[a
 | 
			
		||||
k!!3+F'jKE3VmH3!%#Q&XD@%+r(J!"!TdEb!J#[ah!!3+CQPXC32mGJ!'#rae!"3
 | 
			
		||||
`!!KdC@e`F'&dD!!)G'9YF&"KG'J+r(3!"!TLG'jc#[ac!!3+CfPfG32mFJ!&#[a
 | 
			
		||||
a!"JZFhPcEf4XEfGKFfYb!!!!!!!!!!"849K8%IbD#XRJ%JUYi1%TDJ`!!LrM*N9
 | 
			
		||||
4e%r&jLa&edrSaHBX4Nr%@qPF@eTVA&VU-NAE6m4Ek9aE@QYF@Z`bl5C&hNr,lbA
 | 
			
		||||
Y*N9J!""2bf%!%59K!")Pl5C&B!!66mYK!"3Pl5C&B!!96mYK!"BPl5C&B!!A6m[
 | 
			
		||||
Y*N9J!"K2amAQ,%C2&!!L+Q%!'9m!%#pK!"PK!"S[DJ`!'dmUB3!F,'S-!"eA!!K
 | 
			
		||||
B!"i!(fK2+Q%!)'%!'@%!)5TK!"PI!"![B3!L$!!M6em!*%9J!#92A`!PDJ`!'dp
 | 
			
		||||
K!#BUB3!F,'%!*ba'6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"R1,f%!+Q%!+bp
 | 
			
		||||
K!#`-!#02A`!9B3!Y*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!,Lp
 | 
			
		||||
K!#TK!#m[B3!X$!!M6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!#i[B3!UB3!
 | 
			
		||||
`,f%!,!`!)dpI!"9K!$%P4@!!,NmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!
 | 
			
		||||
Z,f%!+Q%!-LpK!#`-!#02A`!9B3!c*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!
 | 
			
		||||
T+Q%!'9m!,LpK!#TK!$3[B3!X$!!M6em!&@%!059&B!!Z6bTK!#"K!#KK!#%UB3!
 | 
			
		||||
CA`!6,f%!+5TK!"PI!#i[B3!UB3!f,f%!,!`!)dpI!"9K!$FP4@!!,NmUB3!JB3!
 | 
			
		||||
SB3!K+Q%!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%!1#pK!#`-!#02A`!9B3!j*89J!#j
 | 
			
		||||
2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!,LpK!#TK!$S[B3!X$!!M6em!&@%
 | 
			
		||||
!1b9&B!!Z6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!#i[B3!UB3!m,f%!,!`
 | 
			
		||||
!)dpI!"9K!$dP4@!!,NmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%
 | 
			
		||||
!2LpK!#`-!#02A`!9B3!r*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m
 | 
			
		||||
!,LpK!#TK!%![B3!X$!!M6em!&@%!359&B!!Z6bTK!#"K!#KK!#%UB3!CA`!6,f%
 | 
			
		||||
!+5TK!"PI!#i[B3!UB3"#,f%!,!`!)dpI!"9K!%-P4@!!,NmUB3!JB3!SB3!K+Q%
 | 
			
		||||
!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%!4#pK!#`-!#02A`!9B3"&*89J!#j2+Q%!)'%
 | 
			
		||||
!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!,LpK!#TK!%B[B3!X$!!M6em!&@%!4b9&B!!
 | 
			
		||||
Z6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!#i[B3!UB3"),f%!,!`!)dpI!"9
 | 
			
		||||
K!%NP4@!!,NmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%!5LpK!#`
 | 
			
		||||
-!#02A`!9B3",*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!,LpK!#T
 | 
			
		||||
K!%`[B3!X$!!M6em!&@%!659&B!!Z6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"P
 | 
			
		||||
I!#i[B3!UB3"1,f%!,!`!)dpI!"9K!%mP4@!!,NmUB3!JB3!SB3!K+Q%!'9m!%bp
 | 
			
		||||
K!#NUB3!CA`!Z,f%!+Q%!8#pK!#`-!#02A`!9B3"4*89J!#j2+Q%!)'%!+'%!)5T
 | 
			
		||||
K!"PI!"-[B3!T+Q%!'9m!,LpK!#TK!&)[B3!X$!!M6em!&@%!8b9&B!!Z6bTK!#"
 | 
			
		||||
K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!#i[B3!UB3"8,f%!,!`!)dpI!"9K!&8P4@!
 | 
			
		||||
!,NmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%!9LpK!#`-!#02A`!
 | 
			
		||||
9B3"A*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!,LpK!#TK!&J[B3!
 | 
			
		||||
X$!!M6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!#i[B3!UB3"C,f%!,!`!)dp
 | 
			
		||||
I!"9K!&SP4@!!,NmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%!@bp
 | 
			
		||||
K!#`-!#02A`!9B3"F*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!,Lp
 | 
			
		||||
K!#TK!&d[B3!X$!!M6em!&@%!AL9&B!!Z6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5T
 | 
			
		||||
K!"PI!#i[B3!UB3"I,f%!,!`!)dpI!"9K!'!P4@!!,NmUB3!JB3!SB3!K+Q%!'9m
 | 
			
		||||
!%bpK!#NUB3!CA`!Z,f%!+Q%!B5pK!#`-!#02A`!9B3"L*89J!#j2+Q%!)'%!+'%
 | 
			
		||||
!)5TK!"PI!"-[B3!T+Q%!'9m!,LpK!#TK!'-[B3!X$!!M6em!&@%!C#9&B!!Z6bT
 | 
			
		||||
K!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!#i[B3!UB3"P,f%!,!`!)dpI!"9K!'B
 | 
			
		||||
P4@!!,NmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%!CbpK!#`-!#0
 | 
			
		||||
2A`!9B3"S*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!,LpK!#TK!'N
 | 
			
		||||
[B3!X$!!M6em!&@%!DL9&B!!Z6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!#i
 | 
			
		||||
[B3!UB3"V,f%!,!`!)dmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%
 | 
			
		||||
!E#pK!#`-!#02A`!9B3"Y*89J!#j2+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m
 | 
			
		||||
!,LpK!#TK!'i[B3!X$!!M6em!&@%!Eb9&B!!Z6bTK!#"K!#KK!#%UB3!CA`!6,f%
 | 
			
		||||
!+5TK!"PI!#i[B3!UB3"`,f%!,!`!)dpI!"9K!(%P4@!!,NmUB3!JB3!SB3!K+Q%
 | 
			
		||||
!'9m!%bpK!#NUB3!CA`!Z,f%!+Q%!FLpK!#`-!#02+Q%!)'%!+'%!)5TK!"PI!"-
 | 
			
		||||
[B3!T+Q%!'9m!,LpK!#TK!(-[B3!X$!!M6em!&@%!G#9&B!!Z6bTK!#"K!#KK!#%
 | 
			
		||||
UB3!CA`!6,f%!+5TK!"PI!#i[B3!UB3"e,f%!,!`!)dmUB3!JB3!SB3!K+Q%!'9m
 | 
			
		||||
!%bpK!#NUB3!CA`!A,f%!+Q%!GLpK!#`-!#02+Q%!)'%!+'%!)5TK!"PI!"-[B3!
 | 
			
		||||
T+Q%!'9m!&bpK!#TK!(F[B3!X$!!M6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"P
 | 
			
		||||
I!"F[B3!UB3"i,f%!,!`!)dmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!A,f%
 | 
			
		||||
!+Q%!H5pK!#`-!#02+Q%!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!&bpK!#TK!(S
 | 
			
		||||
[B3!X$!!M6bTK!#"K!#KK!#%UB3!CA`!6,f%!+5TK!"PI!"8[B3!UB3"l,f%!,!`
 | 
			
		||||
!)dmUB3!JB3!SB3!K+Q%!'9m!%bpK!#NUB3!CA`!9,f%!+Q%!I#pK!#`-!#02+Q%
 | 
			
		||||
!)'%!+'%!)5TK!"PI!"-[B3!T+Q%!'9m!&5pK!#TK!(d[B3!X$!!M6bTK!#"K!#K
 | 
			
		||||
K!#%UB3!CA`!6,f%!+5TK!"PI!"J[B3!UB3"q,f%!,!`!)dmUB3!JB3!SB3!K+Q%
 | 
			
		||||
!'9m!%bpK!#NUB3!CA`!B,f%!+Q%!IbpK!#`-!#028&92B3#!B3#"B3##DhCK!)0
 | 
			
		||||
K!)4K!#)-!)82$!5Y!&%!5deKBfPZG'pcD#")4$T%CA0VG'p`)%C[E'4PFMT*EQ0
 | 
			
		||||
[E@PZCcT[F'9ZFh0X,90139!Y-6Nj16%b-6%k6@&M6e-kE@YXD@jVFbjKF`!#!!!
 | 
			
		||||
1"+i!!J6mF!5p!ra`!!%1",d!!3!%[J`%[J!'!!!!!J!!$J5[!!)%r'm%[`2mE`!
 | 
			
		||||
%$J5r!!3!"-!%`36#"---"-!!%J!-6@&MD@jdEh0S)%K%!!)!!!`%`3!8!!j%CA0
 | 
			
		||||
VG'p`)%C[E'4PFJ!#!!!-"-)!$J!)5@jMEfeTEQF!!J!!$!6$!"X!&@p`C@jcFf`
 | 
			
		||||
Y8dj"8#da16Nj-6)a-3!#!!!-",!!4J"!6@&MD@jdEh0S)%K%1N4PFfYdEh!J4Qp
 | 
			
		||||
XC'9b1NPZBfpYD@jR1Qp`C@jcFf`Y8dj"8#da16Nj-6)a-6T0B@028`!#!!!-",%
 | 
			
		||||
!5!"#6@&MD@jdEh0S)%K%1N4PFfYdEh!J4QpXC'9b1NPZBfpYD@jR1Qp`C@jcFf`
 | 
			
		||||
Y8dj"8#da16Nj-6)a-6TTEQ0XG@4P!!)!!!`%XJ"3!%T0B@0TER4[FfJJ5%3k4'9
 | 
			
		||||
cDh4[F#"'EfaNCA)k5@jMEfeTEQFkEh"PER0cE#e66N&3,6%j16Na-M%a1QPZBfa
 | 
			
		||||
eC'8kEh"PER0cE!!#!!!-",-!4`""6@&MD@jdEh0S)%K%1N4PFfYdEh!J4QpXC'9
 | 
			
		||||
b1NPZBfpYD@jR1Qp`C@jcFf`Y8dj"8#da16Nj-6)a-6TMFRP`G'm!!J!!$!5d!%3
 | 
			
		||||
!2NeKBfPZG'pcD#")4$T%CA0VG'p`)%C[E'4PFMT*EQ0[E@PZCcT[F'9ZFh0X,90
 | 
			
		||||
139!Y-6Nj16%b-6%kFh0X!!)!!!`%Y3"!!$T0B@0TER4[FfJJ5%3k4'9cDh4[F#"
 | 
			
		||||
'EfaNCA)k5@jMEfeTEQFkEh"PER0cE#e66N&3,6%j16Na-M%a!!)!!!i%YJ!"&!6
 | 
			
		||||
%$J6%!!-B"-AmEJ6'$J6&!!-B"-ImE36)$J6(!!-B"-RmE!6+$J6*!!-B!"rmD`6
 | 
			
		||||
,#[aV!!3+BfC[E!`%b`!1!!K*EQ0[E@PZC`!#!!!+r'`!"!TMCQpX$!6+!"X!&@p
 | 
			
		||||
`C@jcFf`Y8dj"8#da16Nj-6)a-3!#!!!+r'd!"!TMCQpX$!6)!!d!"fPZBfaeC'8
 | 
			
		||||
!!J!!#[aZ!!3+BfC[E!`%aJ!9!!peER4TG'aPC#"QEfaNCA)!!J!!$!5h!%i!5%e
 | 
			
		||||
KBfPZG'pcD#")4$T%CA0VG'p`)%C[E'4PFMT*EQ0[E@PZCcT[F'9ZFh0X,90139!
 | 
			
		||||
Y-6Nj16%b-6%kBh*jF(4[1RJe-$Pf-`!#!!!"r,%!!!(mX!!!!Ib[!!!"r+i!!'&
 | 
			
		||||
cBh)!!3!-qYlHV3!!!3!!!*G#!!#@3J!!!AB!!$-8-0J!!!!F!AB!$h0MFhS!!!#
 | 
			
		||||
#6Np853!!!)jcBh"d!!!!QP4&@&3!!3#QFh4jE!!!!,j$6d4&!!%!bN*14%`!!!$
 | 
			
		||||
LBA"XG!!!!1j'8N9'!!!!qNP$6L-!!!%'D@0X0!!!!4*TBh-M!!!"(QPMFc3!!!%
 | 
			
		||||
UD'CNFJ!!!6C659T&!!!"3PG3Eh-!!!&1!!$rr`!!!!!!!!!!!)$rre!!!"i!!!!
 | 
			
		||||
!!)$rr`!!"cJ#DH#m"'Mrr`!!!*S!!!!!%iRrr`!!"Pi!!!!!"'Mrr`!!!53!!!!
 | 
			
		||||
!!!$rrb!!!9)!!!!!!!(rra3!!@i#DG`%!)$rr`!!!Pi#DH"X!!$rr`!!!Ri!!!!
 | 
			
		||||
!!)$rr`!!!S-#DH"d!*Err`!!!Si!!!!!!*Err`!!!j)!!!!!!*Err`!!"CB#DH%
 | 
			
		||||
i!*Err`!!"GS#DH%dkF$rr`!!"[`!!!!!rrrrr`!!"a)!!!!!!)$rr`!!"b!!!!!
 | 
			
		||||
!*4S:
 | 
			
		||||
							
								
								
									
										126
									
								
								MacOS/opensslconf.h
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										126
									
								
								MacOS/opensslconf.h
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,126 @@
 | 
			
		||||
/* MacOS/opensslconf.h */
 | 
			
		||||
 | 
			
		||||
#if !(defined(VMS) || defined(__VMS)) /* VMS uses logical names instead */
 | 
			
		||||
# if defined(HEADER_CRYPTLIB_H) && !defined(OPENSSLDIR)
 | 
			
		||||
#  define OPENSSLDIR "/usr/local/ssl"
 | 
			
		||||
# endif
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_IDEA_H) && !defined(IDEA_INT)
 | 
			
		||||
# define IDEA_INT unsigned int
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_MD2_H) && !defined(MD2_INT)
 | 
			
		||||
# define MD2_INT unsigned int
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_RC2_H) && !defined(RC2_INT)
 | 
			
		||||
/* I need to put in a mod for the alpha - eay */
 | 
			
		||||
# define RC2_INT unsigned int
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_RC4_H)
 | 
			
		||||
# if !defined(RC4_INT)
 | 
			
		||||
/*
 | 
			
		||||
 * using int types make the structure larger but make the code faster on most
 | 
			
		||||
 * boxes I have tested - up to %20 faster.
 | 
			
		||||
 */
 | 
			
		||||
/*-
 | 
			
		||||
 * I don't know what does "most" mean, but declaring "int" is a must on:
 | 
			
		||||
 * - Intel P6 because partial register stalls are very expensive;
 | 
			
		||||
 * - elder Alpha because it lacks byte load/store instructions;
 | 
			
		||||
 */
 | 
			
		||||
#  define RC4_INT unsigned char
 | 
			
		||||
# endif
 | 
			
		||||
# if !defined(RC4_CHUNK)
 | 
			
		||||
/*
 | 
			
		||||
 * This enables code handling data aligned at natural CPU word
 | 
			
		||||
 * boundary. See crypto/rc4/rc4_enc.c for further details.
 | 
			
		||||
 */
 | 
			
		||||
#  define RC4_CHUNK unsigned long
 | 
			
		||||
# endif
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_DES_H) && !defined(DES_LONG)
 | 
			
		||||
/*
 | 
			
		||||
 * If this is set to 'unsigned int' on a DEC Alpha, this gives about a %20
 | 
			
		||||
 * speed up (longs are 8 bytes, int's are 4).
 | 
			
		||||
 */
 | 
			
		||||
# ifndef DES_LONG
 | 
			
		||||
#  define DES_LONG unsigned long
 | 
			
		||||
# endif
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_BN_H) && !defined(CONFIG_HEADER_BN_H)
 | 
			
		||||
# define CONFIG_HEADER_BN_H
 | 
			
		||||
# if __option(longlong)
 | 
			
		||||
#  define BN_LLONG
 | 
			
		||||
# else
 | 
			
		||||
#  undef BN_LLONG
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
/* Should we define BN_DIV2W here? */
 | 
			
		||||
 | 
			
		||||
/* Only one for the following should be defined */
 | 
			
		||||
/*
 | 
			
		||||
 * The prime number generation stuff may not work when EIGHT_BIT but I don't
 | 
			
		||||
 * care since I've only used this mode for debuging the bignum libraries
 | 
			
		||||
 */
 | 
			
		||||
# undef SIXTY_FOUR_BIT_LONG
 | 
			
		||||
# undef SIXTY_FOUR_BIT
 | 
			
		||||
# define THIRTY_TWO_BIT
 | 
			
		||||
# undef SIXTEEN_BIT
 | 
			
		||||
# undef EIGHT_BIT
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_RC4_LOCL_H) && !defined(CONFIG_HEADER_RC4_LOCL_H)
 | 
			
		||||
# define CONFIG_HEADER_RC4_LOCL_H
 | 
			
		||||
/*
 | 
			
		||||
 * if this is defined data[i] is used instead of *data, this is a %20 speedup
 | 
			
		||||
 * on x86
 | 
			
		||||
 */
 | 
			
		||||
# undef RC4_INDEX
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_BF_LOCL_H) && !defined(CONFIG_HEADER_BF_LOCL_H)
 | 
			
		||||
# define CONFIG_HEADER_BF_LOCL_H
 | 
			
		||||
# define BF_PTR
 | 
			
		||||
#endif                          /* HEADER_BF_LOCL_H */
 | 
			
		||||
 | 
			
		||||
#if defined(HEADER_DES_LOCL_H) && !defined(CONFIG_HEADER_DES_LOCL_H)
 | 
			
		||||
# define CONFIG_HEADER_DES_LOCL_H
 | 
			
		||||
/*
 | 
			
		||||
 * the following is tweaked from a config script, that is why it is a
 | 
			
		||||
 * protected undef/define
 | 
			
		||||
 */
 | 
			
		||||
# ifndef DES_PTR
 | 
			
		||||
#  define DES_PTR
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * This helps C compiler generate the correct code for multiple functional
 | 
			
		||||
 * units.  It reduces register dependancies at the expense of 2 more
 | 
			
		||||
 * registers
 | 
			
		||||
 */
 | 
			
		||||
# ifndef DES_RISC1
 | 
			
		||||
#  define DES_RISC1
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# ifndef DES_RISC2
 | 
			
		||||
#  undef DES_RISC2
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# if defined(DES_RISC1) && defined(DES_RISC2)
 | 
			
		||||
YOU SHOULD NOT HAVE BOTH DES_RISC1 AND DES_RISC2 DEFINED ! !!!!
 | 
			
		||||
# endif
 | 
			
		||||
/*
 | 
			
		||||
 * Unroll the inner loop, this sometimes helps, sometimes hinders. Very mucy
 | 
			
		||||
 * CPU dependant
 | 
			
		||||
 */
 | 
			
		||||
# ifndef DES_UNROLL
 | 
			
		||||
#  define DES_UNROLL
 | 
			
		||||
# endif
 | 
			
		||||
#endif                          /* HEADER_DES_LOCL_H */
 | 
			
		||||
#ifndef __POWERPC__
 | 
			
		||||
# define MD32_XARRAY
 | 
			
		||||
#endif
 | 
			
		||||
							
								
								
									
										465
									
								
								Makefile.org
									
									
									
									
									
								
							
							
						
						
									
										465
									
								
								Makefile.org
									
									
									
									
									
								
							@@ -65,13 +65,11 @@ EX_LIBS=
 | 
			
		||||
EXE_EXT= 
 | 
			
		||||
ARFLAGS=
 | 
			
		||||
AR=ar $(ARFLAGS) r
 | 
			
		||||
ARD=ar $(ARFLAGS) d
 | 
			
		||||
RANLIB= ranlib
 | 
			
		||||
NM= nm
 | 
			
		||||
PERL= perl
 | 
			
		||||
#RM= echo --
 | 
			
		||||
RM= rm -f
 | 
			
		||||
TAR= tar
 | 
			
		||||
TARFLAGS= --no-recursion
 | 
			
		||||
TARFLAGS= --no-recursion --record-size=10240
 | 
			
		||||
MAKEDEPPROG=makedepend
 | 
			
		||||
LIBDIR=lib
 | 
			
		||||
 | 
			
		||||
@@ -90,9 +88,8 @@ PROCESSOR=
 | 
			
		||||
# CPUID module collects small commonly used assembler snippets
 | 
			
		||||
CPUID_OBJ= 
 | 
			
		||||
BN_ASM= bn_asm.o
 | 
			
		||||
EC_ASM=
 | 
			
		||||
DES_ENC= des_enc.o fcrypt_b.o
 | 
			
		||||
AES_ENC= aes_core.o aes_cbc.o
 | 
			
		||||
AES_ASM_OBJ=aes_core.o aes_cbc.o
 | 
			
		||||
BF_ENC= bf_enc.o
 | 
			
		||||
CAST_ENC= c_enc.o
 | 
			
		||||
RC4_ENC= rc4_enc.o
 | 
			
		||||
@@ -100,11 +97,6 @@ RC5_ENC= rc5_enc.o
 | 
			
		||||
MD5_ASM_OBJ= 
 | 
			
		||||
SHA1_ASM_OBJ= 
 | 
			
		||||
RMD160_ASM_OBJ= 
 | 
			
		||||
WP_ASM_OBJ=
 | 
			
		||||
CMLL_ENC=
 | 
			
		||||
MODES_ASM_OBJ=
 | 
			
		||||
ENGINES_ASM_OBJ=
 | 
			
		||||
PERLASM_SCHEME=
 | 
			
		||||
 | 
			
		||||
# KRB5 stuff
 | 
			
		||||
KRB5_INCLUDES=
 | 
			
		||||
@@ -118,14 +110,20 @@ LIBZLIB=
 | 
			
		||||
# The FIPS module build will place it $(INSTALLTOP)/lib
 | 
			
		||||
# but since $(INSTALLTOP) can only take the default value
 | 
			
		||||
# when the module is built it will be in /usr/local/ssl/lib
 | 
			
		||||
# $(INSTALLTOP) for this build may be different so hard
 | 
			
		||||
# $(INSTALLTOP) for this build make be different so hard
 | 
			
		||||
# code the path.
 | 
			
		||||
 | 
			
		||||
FIPSLIBDIR=/usr/local/ssl/$(LIBDIR)/
 | 
			
		||||
 | 
			
		||||
# This is set to "y" if fipscanister.o is compiled internally as
 | 
			
		||||
# opposed to coming from an external validated location.
 | 
			
		||||
 | 
			
		||||
FIPSCANISTERINTERNAL=n
 | 
			
		||||
 | 
			
		||||
# The location of the library which contains fipscanister.o
 | 
			
		||||
# normally it will be libcrypto. If not compiling in FIPS mode
 | 
			
		||||
# at all this is empty making it a useful test for a FIPS compile.
 | 
			
		||||
# normally it will be libcrypto unless fipsdso is set in which
 | 
			
		||||
# case it will be libfips. If not compiling in FIPS mode at all
 | 
			
		||||
# this is empty making it a useful test for a FIPS compile.
 | 
			
		||||
 | 
			
		||||
FIPSCANLIB=
 | 
			
		||||
 | 
			
		||||
@@ -134,19 +132,18 @@ FIPSCANLIB=
 | 
			
		||||
 | 
			
		||||
BASEADDR=
 | 
			
		||||
 | 
			
		||||
DIRS=   crypto ssl engines apps test tools
 | 
			
		||||
ENGDIRS= ccgost
 | 
			
		||||
SHLIBDIRS= crypto ssl
 | 
			
		||||
DIRS=   crypto fips ssl engines apps test tools
 | 
			
		||||
SHLIBDIRS= crypto ssl fips
 | 
			
		||||
 | 
			
		||||
# dirs in crypto to build
 | 
			
		||||
SDIRS=  \
 | 
			
		||||
	objects \
 | 
			
		||||
	md2 md4 md5 sha mdc2 hmac ripemd whrlpool \
 | 
			
		||||
	des aes rc2 rc4 rc5 idea bf cast camellia seed modes \
 | 
			
		||||
	md2 md4 md5 sha mdc2 hmac ripemd \
 | 
			
		||||
	des aes rc2 rc4 rc5 idea bf cast camellia seed \
 | 
			
		||||
	bn ec rsa dsa ecdsa dh ecdh dso engine \
 | 
			
		||||
	buffer bio stack lhash rand err \
 | 
			
		||||
	evp asn1 pem x509 x509v3 conf txt_db pkcs7 pkcs12 comp ocsp ui krb5 \
 | 
			
		||||
	cms pqueue ts jpake srp store cmac
 | 
			
		||||
	store cms pqueue jpake
 | 
			
		||||
# keep in mind that the above list is adjusted by ./Configure
 | 
			
		||||
# according to no-xxx arguments...
 | 
			
		||||
 | 
			
		||||
@@ -160,8 +157,6 @@ MANDIR=$(OPENSSLDIR)/man
 | 
			
		||||
MAN1=1
 | 
			
		||||
MAN3=3
 | 
			
		||||
MANSUFFIX=
 | 
			
		||||
HTMLSUFFIX=html
 | 
			
		||||
HTMLDIR=$(OPENSSLDIR)/html
 | 
			
		||||
SHELL=/bin/sh
 | 
			
		||||
 | 
			
		||||
TOP=    .
 | 
			
		||||
@@ -171,6 +166,7 @@ WDIRS=  windows
 | 
			
		||||
LIBS=   libcrypto.a libssl.a
 | 
			
		||||
SHARED_CRYPTO=libcrypto$(SHLIB_EXT)
 | 
			
		||||
SHARED_SSL=libssl$(SHLIB_EXT)
 | 
			
		||||
SHARED_FIPS=
 | 
			
		||||
SHARED_LIBS=
 | 
			
		||||
SHARED_LIBS_LINK_EXTS=
 | 
			
		||||
SHARED_LDFLAGS=
 | 
			
		||||
@@ -183,17 +179,6 @@ WTARFILE=       $(NAME)-win.tar
 | 
			
		||||
EXHEADER=       e_os2.h
 | 
			
		||||
HEADER=         e_os.h
 | 
			
		||||
 | 
			
		||||
# Directories created on install if they don't exist.
 | 
			
		||||
INSTALLDIRS=	\
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/bin \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR) \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/engines \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/include/openssl \
 | 
			
		||||
		$(INSTALL_PREFIX)$(OPENSSLDIR)/misc \
 | 
			
		||||
		$(INSTALL_PREFIX)$(OPENSSLDIR)/certs \
 | 
			
		||||
		$(INSTALL_PREFIX)$(OPENSSLDIR)/private
 | 
			
		||||
 | 
			
		||||
all: Makefile build_all openssl.pc libssl.pc libcrypto.pc
 | 
			
		||||
 | 
			
		||||
# as we stick to -e, CLEARENV ensures that local variables in lower
 | 
			
		||||
@@ -208,43 +193,37 @@ CLEARENV=	TOP= && unset TOP $${LIB+LIB} $${LIBS+LIBS}	\
 | 
			
		||||
		$${EXHEADER+EXHEADER} $${HEADER+HEADER}		\
 | 
			
		||||
		$${GENERAL+GENERAL} $${CFLAGS+CFLAGS}		\
 | 
			
		||||
		$${ASFLAGS+ASFLAGS} $${AFLAGS+AFLAGS}		\
 | 
			
		||||
		$${LDCMD+LDCMD} $${LDFLAGS+LDFLAGS} $${SCRIPTS+SCRIPTS}	\
 | 
			
		||||
		$${LDCMD+LDCMD} $${LDFLAGS+LDFLAGS}		\
 | 
			
		||||
		$${SHAREDCMD+SHAREDCMD} $${SHAREDFLAGS+SHAREDFLAGS}	\
 | 
			
		||||
		$${SHARED_LIB+SHARED_LIB} $${LIBEXTRAS+LIBEXTRAS}
 | 
			
		||||
 | 
			
		||||
BUILDENV=	PLATFORM='$(PLATFORM)' PROCESSOR='$(PROCESSOR)' \
 | 
			
		||||
		CC='$(CC)' CFLAG='$(CFLAG)' 			\
 | 
			
		||||
		AS='$(CC)' ASFLAG='$(CFLAG) -c'			\
 | 
			
		||||
		AR='$(AR)' NM='$(NM)' RANLIB='$(RANLIB)'	\
 | 
			
		||||
		CROSS_COMPILE='$(CROSS_COMPILE)'	\
 | 
			
		||||
		PERL='$(PERL)' ENGDIRS='$(ENGDIRS)'		\
 | 
			
		||||
		SDIRS='$(SDIRS)' LIBRPATH='$(INSTALLTOP)/$(LIBDIR)'	\
 | 
			
		||||
		INSTALL_PREFIX='$(INSTALL_PREFIX)'		\
 | 
			
		||||
		INSTALLTOP='$(INSTALLTOP)' OPENSSLDIR='$(OPENSSLDIR)'	\
 | 
			
		||||
		LIBDIR='$(LIBDIR)'				\
 | 
			
		||||
		MAKEDEPEND='$$$${TOP}/util/domd $$$${TOP} -MD $(MAKEDEPPROG)' \
 | 
			
		||||
		DEPFLAG='-DOPENSSL_NO_DEPRECATED $(DEPFLAG)'	\
 | 
			
		||||
		MAKEDEPPROG='$(MAKEDEPPROG)'			\
 | 
			
		||||
		SHARED_LDFLAGS='$(SHARED_LDFLAGS)'		\
 | 
			
		||||
		KRB5_INCLUDES='$(KRB5_INCLUDES)' LIBKRB5='$(LIBKRB5)'	\
 | 
			
		||||
		ZLIB_INCLUDE='$(ZLIB_INCLUDE)' LIBZLIB='$(LIBZLIB)'	\
 | 
			
		||||
		EXE_EXT='$(EXE_EXT)' SHARED_LIBS='$(SHARED_LIBS)'	\
 | 
			
		||||
		SHLIB_EXT='$(SHLIB_EXT)' SHLIB_TARGET='$(SHLIB_TARGET)'	\
 | 
			
		||||
		PEX_LIBS='$(PEX_LIBS)' EX_LIBS='$(EX_LIBS)'	\
 | 
			
		||||
		CPUID_OBJ='$(CPUID_OBJ)' BN_ASM='$(BN_ASM)'	\
 | 
			
		||||
		EC_ASM='$(EC_ASM)' DES_ENC='$(DES_ENC)'		\
 | 
			
		||||
		AES_ENC='$(AES_ENC)' CMLL_ENC='$(CMLL_ENC)'	\
 | 
			
		||||
		BF_ENC='$(BF_ENC)' CAST_ENC='$(CAST_ENC)'	\
 | 
			
		||||
		RC4_ENC='$(RC4_ENC)' RC5_ENC='$(RC5_ENC)'	\
 | 
			
		||||
		SHA1_ASM_OBJ='$(SHA1_ASM_OBJ)'			\
 | 
			
		||||
		MD5_ASM_OBJ='$(MD5_ASM_OBJ)'			\
 | 
			
		||||
		RMD160_ASM_OBJ='$(RMD160_ASM_OBJ)'		\
 | 
			
		||||
		WP_ASM_OBJ='$(WP_ASM_OBJ)'			\
 | 
			
		||||
		MODES_ASM_OBJ='$(MODES_ASM_OBJ)'		\
 | 
			
		||||
		ENGINES_ASM_OBJ='$(ENGINES_ASM_OBJ)'		\
 | 
			
		||||
		PERLASM_SCHEME='$(PERLASM_SCHEME)'		\
 | 
			
		||||
BUILDENV=	PLATFORM='${PLATFORM}' PROCESSOR='${PROCESSOR}' \
 | 
			
		||||
		CC='${CC}' CFLAG='${CFLAG}' 			\
 | 
			
		||||
		AS='${CC}' ASFLAG='${CFLAG} -c'			\
 | 
			
		||||
		AR='${AR}' PERL='${PERL}' RANLIB='${RANLIB}'	\
 | 
			
		||||
		SDIRS='${SDIRS}' LIBRPATH='${INSTALLTOP}/$(LIBDIR)'	\
 | 
			
		||||
		INSTALL_PREFIX='${INSTALL_PREFIX}'		\
 | 
			
		||||
		INSTALLTOP='${INSTALLTOP}' OPENSSLDIR='${OPENSSLDIR}'	\
 | 
			
		||||
		LIBDIR='${LIBDIR}' \
 | 
			
		||||
		MAKEDEPEND='$$$${TOP}/util/domd $$$${TOP} -MD ${MAKEDEPPROG}' \
 | 
			
		||||
		DEPFLAG='-DOPENSSL_NO_DEPRECATED ${DEPFLAG}'	\
 | 
			
		||||
		MAKEDEPPROG='${MAKEDEPPROG}'			\
 | 
			
		||||
		SHARED_LDFLAGS='${SHARED_LDFLAGS}'		\
 | 
			
		||||
		KRB5_INCLUDES='${KRB5_INCLUDES}' LIBKRB5='${LIBKRB5}'	\
 | 
			
		||||
		EXE_EXT='${EXE_EXT}' SHARED_LIBS='${SHARED_LIBS}'	\
 | 
			
		||||
		SHLIB_EXT='${SHLIB_EXT}' SHLIB_TARGET='${SHLIB_TARGET}'	\
 | 
			
		||||
		PEX_LIBS='${PEX_LIBS}' EX_LIBS='${EX_LIBS}'	\
 | 
			
		||||
		CPUID_OBJ='${CPUID_OBJ}'			\
 | 
			
		||||
		BN_ASM='${BN_ASM}' DES_ENC='${DES_ENC}' 	\
 | 
			
		||||
		AES_ASM_OBJ='${AES_ASM_OBJ}'			\
 | 
			
		||||
		BF_ENC='${BF_ENC}' CAST_ENC='${CAST_ENC}'	\
 | 
			
		||||
		RC4_ENC='${RC4_ENC}' RC5_ENC='${RC5_ENC}'	\
 | 
			
		||||
		SHA1_ASM_OBJ='${SHA1_ASM_OBJ}'			\
 | 
			
		||||
		MD5_ASM_OBJ='${MD5_ASM_OBJ}'			\
 | 
			
		||||
		RMD160_ASM_OBJ='${RMD160_ASM_OBJ}'		\
 | 
			
		||||
		FIPSLIBDIR='${FIPSLIBDIR}'			\
 | 
			
		||||
		FIPSCANLIB="$${FIPSCANLIB:-$(FIPSCANLIB)}"	\
 | 
			
		||||
		FIPSCANISTERINTERNAL='${FIPSCANISTERINTERNAL}'	\
 | 
			
		||||
		FIPS_EX_OBJ='${FIPS_EX_OBJ}'	\
 | 
			
		||||
		THIS=$${THIS:-$@} MAKEFILE=Makefile MAKEOVERRIDES=
 | 
			
		||||
# MAKEOVERRIDES= effectively "equalizes" GNU-ish and SysV-ish make flavors,
 | 
			
		||||
@@ -256,21 +235,22 @@ BUILDENV=	PLATFORM='$(PLATFORM)' PROCESSOR='$(PROCESSOR)' \
 | 
			
		||||
# This macro shouldn't be used directly, use RECURSIVE_BUILD_CMD or
 | 
			
		||||
# BUILD_ONE_CMD instead.
 | 
			
		||||
#
 | 
			
		||||
# RECURSIVE_BUILD_CMD is a macro to build a given target in all
 | 
			
		||||
# subdirectories defined in $(DIRS).  It requires that the target
 | 
			
		||||
# is given through the shell variable `target'.
 | 
			
		||||
#
 | 
			
		||||
# BUILD_ONE_CMD is a macro to build a given target in a given
 | 
			
		||||
# subdirectory if that subdirectory is part of $(DIRS).  It requires
 | 
			
		||||
# exactly the same shell variables as BUILD_CMD.
 | 
			
		||||
#
 | 
			
		||||
# RECURSIVE_BUILD_CMD is a macro to build a given target in all
 | 
			
		||||
# subdirectories defined in $(DIRS).  It requires that the target
 | 
			
		||||
# is given through the shell variable `target'.
 | 
			
		||||
BUILD_CMD=  if [ -d "$$dir" ]; then \
 | 
			
		||||
	    (	cd $$dir && echo "making $$target in $$dir..." && \
 | 
			
		||||
	    (	[ $$target != all -a -z "$(FIPSCANLIB)" ] && FIPSCANLIB=/dev/null; \
 | 
			
		||||
		cd $$dir && echo "making $$target in $$dir..." && \
 | 
			
		||||
		$(CLEARENV) && $(MAKE) -e $(BUILDENV) TOP=.. DIR=$$dir $$target \
 | 
			
		||||
	    ) || exit 1; \
 | 
			
		||||
	    fi
 | 
			
		||||
RECURSIVE_BUILD_CMD=for dir in $(DIRS); do $(BUILD_CMD); done
 | 
			
		||||
BUILD_ONE_CMD=\
 | 
			
		||||
	if expr " $(DIRS) " : ".* $$dir " >/dev/null 2>&1; then \
 | 
			
		||||
	if echo " $(DIRS) " | grep " $$dir " >/dev/null 2>/dev/null; then \
 | 
			
		||||
		$(BUILD_CMD); \
 | 
			
		||||
	fi
 | 
			
		||||
 | 
			
		||||
@@ -287,12 +267,10 @@ FIPS_EX_OBJ= ../crypto/aes/aes_cfb.o \
 | 
			
		||||
	../crypto/bn/bn_exp2.o \
 | 
			
		||||
	../crypto/bn/bn_exp.o \
 | 
			
		||||
	../crypto/bn/bn_gcd.o \
 | 
			
		||||
	../crypto/bn/bn_gf2m.o \
 | 
			
		||||
	../crypto/bn/bn_lib.o \
 | 
			
		||||
	../crypto/bn/bn_mod.o \
 | 
			
		||||
	../crypto/bn/bn_mont.o \
 | 
			
		||||
	../crypto/bn/bn_mul.o \
 | 
			
		||||
	../crypto/bn/bn_nist.o \
 | 
			
		||||
	../crypto/bn/bn_prime.o \
 | 
			
		||||
	../crypto/bn/bn_rand.o \
 | 
			
		||||
	../crypto/bn/bn_recp.o \
 | 
			
		||||
@@ -301,78 +279,66 @@ FIPS_EX_OBJ= ../crypto/aes/aes_cfb.o \
 | 
			
		||||
	../crypto/bn/bn_word.o \
 | 
			
		||||
	../crypto/bn/bn_x931p.o \
 | 
			
		||||
	../crypto/buffer/buf_str.o \
 | 
			
		||||
	../crypto/cmac/cmac.o \
 | 
			
		||||
	../crypto/cryptlib.o \
 | 
			
		||||
	../crypto/des/cfb64ede.o \
 | 
			
		||||
	../crypto/des/cfb64enc.o \
 | 
			
		||||
	../crypto/des/cfb_enc.o \
 | 
			
		||||
	../crypto/des/ecb3_enc.o \
 | 
			
		||||
	../crypto/des/ecb_enc.o \
 | 
			
		||||
	../crypto/des/ofb64ede.o \
 | 
			
		||||
	../crypto/des/ofb64enc.o \
 | 
			
		||||
	../crypto/des/fcrypt.o \
 | 
			
		||||
	../crypto/des/set_key.o \
 | 
			
		||||
	../crypto/dh/dh_check.o \
 | 
			
		||||
	../crypto/dh/dh_gen.o \
 | 
			
		||||
	../crypto/dh/dh_key.o \
 | 
			
		||||
	../crypto/dsa/dsa_gen.o \
 | 
			
		||||
	../crypto/dsa/dsa_key.o \
 | 
			
		||||
	../crypto/dsa/dsa_ossl.o \
 | 
			
		||||
	../crypto/ec/ec_curve.o \
 | 
			
		||||
	../crypto/ec/ec_cvt.o \
 | 
			
		||||
	../crypto/ec/ec_key.o \
 | 
			
		||||
	../crypto/ec/ec_lib.o \
 | 
			
		||||
	../crypto/ec/ecp_mont.o \
 | 
			
		||||
	../crypto/ec/ec_mult.o \
 | 
			
		||||
	../crypto/ec/ecp_nist.o \
 | 
			
		||||
	../crypto/ec/ecp_smpl.o \
 | 
			
		||||
	../crypto/ec/ec2_mult.o \
 | 
			
		||||
	../crypto/ec/ec2_smpl.o \
 | 
			
		||||
	../crypto/ecdh/ech_key.o \
 | 
			
		||||
	../crypto/ecdh/ech_ossl.o \
 | 
			
		||||
	../crypto/ecdsa/ecs_ossl.o \
 | 
			
		||||
	../crypto/dsa/dsa_utl.o \
 | 
			
		||||
	../crypto/dsa/dsa_sign.o \
 | 
			
		||||
	../crypto/dsa/dsa_vrf.o \
 | 
			
		||||
	../crypto/err/err.o \
 | 
			
		||||
	../crypto/evp/digest.o \
 | 
			
		||||
	../crypto/evp/enc_min.o \
 | 
			
		||||
	../crypto/evp/e_aes.o \
 | 
			
		||||
	../crypto/evp/e_des3.o \
 | 
			
		||||
	../crypto/evp/e_null.o \
 | 
			
		||||
	../crypto/evp/m_sha1.o \
 | 
			
		||||
	../crypto/evp/m_dss1.o \
 | 
			
		||||
	../crypto/evp/m_dss.o \
 | 
			
		||||
	../crypto/evp/m_ecdsa.o \
 | 
			
		||||
	../crypto/hmac/hmac.o \
 | 
			
		||||
	../crypto/modes/cbc128.o \
 | 
			
		||||
	../crypto/modes/ccm128.o \
 | 
			
		||||
	../crypto/modes/cfb128.o \
 | 
			
		||||
	../crypto/modes/ctr128.o \
 | 
			
		||||
	../crypto/modes/gcm128.o \
 | 
			
		||||
	../crypto/modes/ofb128.o \
 | 
			
		||||
	../crypto/modes/xts128.o \
 | 
			
		||||
	../crypto/rsa/rsa_eay.o \
 | 
			
		||||
	../crypto/rsa/rsa_gen.o \
 | 
			
		||||
	../crypto/rsa/rsa_crpt.o \
 | 
			
		||||
	../crypto/evp/p_sign.o \
 | 
			
		||||
	../crypto/evp/p_verify.o \
 | 
			
		||||
	../crypto/mem_clr.o \
 | 
			
		||||
	../crypto/mem.o \
 | 
			
		||||
	../crypto/rand/md_rand.o \
 | 
			
		||||
	../crypto/rand/rand_egd.o \
 | 
			
		||||
	../crypto/rand/randfile.o \
 | 
			
		||||
	../crypto/rand/rand_lib.o \
 | 
			
		||||
	../crypto/rand/rand_os2.o \
 | 
			
		||||
	../crypto/rand/rand_unix.o \
 | 
			
		||||
	../crypto/rand/rand_win.o \
 | 
			
		||||
	../crypto/rsa/rsa_lib.o \
 | 
			
		||||
	../crypto/rsa/rsa_none.o \
 | 
			
		||||
	../crypto/rsa/rsa_oaep.o \
 | 
			
		||||
	../crypto/rsa/rsa_pk1.o \
 | 
			
		||||
	../crypto/rsa/rsa_pss.o \
 | 
			
		||||
	../crypto/rsa/rsa_ssl.o \
 | 
			
		||||
	../crypto/rsa/rsa_x931.o \
 | 
			
		||||
	../crypto/rsa/rsa_x931g.o \
 | 
			
		||||
	../crypto/sha/sha1dgst.o \
 | 
			
		||||
	../crypto/sha/sha256.o \
 | 
			
		||||
	../crypto/sha/sha512.o \
 | 
			
		||||
	../crypto/thr_id.o \
 | 
			
		||||
	../crypto/uid.o
 | 
			
		||||
 | 
			
		||||
sub_all: build_all
 | 
			
		||||
 | 
			
		||||
build_all: build_libs build_apps build_tests build_tools
 | 
			
		||||
 | 
			
		||||
build_libs: build_crypto build_ssl build_engines
 | 
			
		||||
build_libs: build_crypto build_fips build_ssl build_shared build_engines
 | 
			
		||||
 | 
			
		||||
build_crypto:
 | 
			
		||||
	@dir=crypto; target=all; $(BUILD_ONE_CMD)
 | 
			
		||||
	if [ -n "$(FIPSCANLIB)" ]; then \
 | 
			
		||||
		EXCL_OBJ='$(AES_ASM_OBJ) $(BN_ASM) $(DES_ENC) $(CPUID_OBJ) $(SHA1_ASM_OBJ) $(FIPS_EX_OBJ)' ; export EXCL_OBJ ; \
 | 
			
		||||
		ARX='$(PERL) $${TOP}/util/arx.pl $(AR)' ; \
 | 
			
		||||
	else \
 | 
			
		||||
		ARX='${AR}' ; \
 | 
			
		||||
	fi ; export ARX ; \
 | 
			
		||||
		dir=crypto; target=all; $(BUILD_ONE_CMD)
 | 
			
		||||
build_fips:
 | 
			
		||||
	@dir=fips; target=all; [ -z "$(FIPSCANLIB)" ] || $(BUILD_ONE_CMD)
 | 
			
		||||
build_ssl: build_crypto
 | 
			
		||||
	@dir=ssl; target=all; $(BUILD_ONE_CMD)
 | 
			
		||||
build_engines: build_crypto
 | 
			
		||||
	@dir=engines; target=all; AS='$(CC) -c'; export AS; $(BUILD_ONE_CMD)
 | 
			
		||||
 | 
			
		||||
	@dir=engines; target=all; $(BUILD_ONE_CMD)
 | 
			
		||||
build_apps: build_libs
 | 
			
		||||
	@dir=apps; target=all; $(BUILD_ONE_CMD)
 | 
			
		||||
build_tests: build_libs
 | 
			
		||||
@@ -384,13 +350,20 @@ all_testapps: build_libs build_testapps
 | 
			
		||||
build_testapps:
 | 
			
		||||
	@dir=crypto; target=testapps; $(BUILD_ONE_CMD)
 | 
			
		||||
 | 
			
		||||
libcrypto$(SHLIB_EXT): libcrypto.a
 | 
			
		||||
build_shared:	$(SHARED_LIBS)
 | 
			
		||||
libcrypto$(SHLIB_EXT): libcrypto.a $(SHARED_FIPS)
 | 
			
		||||
	@if [ "$(SHLIB_TARGET)" != "" ]; then \
 | 
			
		||||
		if [ "$(FIPSCANLIB)" = "libfips" ]; then \
 | 
			
		||||
			$(ARD) libcrypto.a fipscanister.o ; \
 | 
			
		||||
			$(MAKE) SHLIBDIRS='crypto' SHLIBDEPS='-lfips' build-shared; \
 | 
			
		||||
			$(AR) libcrypto.a fips/fipscanister.o ; \
 | 
			
		||||
		else \
 | 
			
		||||
			if [ "$(FIPSCANLIB)" = "libcrypto" ]; then \
 | 
			
		||||
				FIPSLD_CC="$(CC)"; CC=fips/fipsld; \
 | 
			
		||||
				export CC FIPSLD_CC; \
 | 
			
		||||
			fi; \
 | 
			
		||||
		$(MAKE) -e SHLIBDIRS=crypto CC="$${CC:-$(CC)}" build-shared; \
 | 
			
		||||
			$(MAKE) -e SHLIBDIRS='crypto' build-shared; \
 | 
			
		||||
		fi \
 | 
			
		||||
	else \
 | 
			
		||||
		echo "There's no support for shared libraries on this platform" >&2; \
 | 
			
		||||
		exit 1; \
 | 
			
		||||
@@ -398,12 +371,32 @@ libcrypto$(SHLIB_EXT): libcrypto.a
 | 
			
		||||
 | 
			
		||||
libssl$(SHLIB_EXT): libcrypto$(SHLIB_EXT) libssl.a
 | 
			
		||||
	@if [ "$(SHLIB_TARGET)" != "" ]; then \
 | 
			
		||||
		$(MAKE) SHLIBDIRS=ssl SHLIBDEPS='-lcrypto' build-shared; \
 | 
			
		||||
		shlibdeps=-lcrypto; \
 | 
			
		||||
		[ "$(FIPSCANLIB)" = "libfips" ] && shlibdeps="$$shlibdeps -lfips"; \
 | 
			
		||||
		$(MAKE) SHLIBDIRS=ssl SHLIBDEPS="$$shlibdeps" build-shared; \
 | 
			
		||||
	else \
 | 
			
		||||
		echo "There's no support for shared libraries on this platform" >&2 ; \
 | 
			
		||||
		exit 1; \
 | 
			
		||||
	fi
 | 
			
		||||
 | 
			
		||||
fips/fipscanister.o:	build_fips
 | 
			
		||||
libfips$(SHLIB_EXT):		fips/fipscanister.o
 | 
			
		||||
	@if [ "$(SHLIB_TARGET)" != "" ]; then \
 | 
			
		||||
		FIPSLD_CC="$(CC)"; CC=fips/fipsld; export CC FIPSLD_CC; \
 | 
			
		||||
		$(MAKE) -f Makefile.shared -e $(BUILDENV) \
 | 
			
		||||
			CC=$${CC} LIBNAME=fips THIS=$@ \
 | 
			
		||||
			LIBEXTRAS=fips/fipscanister.o \
 | 
			
		||||
			LIBDEPS="$(EX_LIBS)" \
 | 
			
		||||
			LIBVERSION=${SHLIB_MAJOR}.${SHLIB_MINOR} \
 | 
			
		||||
			link_o.$(SHLIB_TARGET) || { rm -f $@; exit 1; } \
 | 
			
		||||
	else \
 | 
			
		||||
		echo "There's no support for shared libraries on this platform" >&2; \
 | 
			
		||||
		exit 1; \
 | 
			
		||||
	fi
 | 
			
		||||
 | 
			
		||||
libfips.a:
 | 
			
		||||
	dir=fips; target=all; $(BUILD_ONE_CMD)
 | 
			
		||||
 | 
			
		||||
clean-shared:
 | 
			
		||||
	@set -e; for i in $(SHLIBDIRS); do \
 | 
			
		||||
		if [ -n "$(SHARED_LIBS_LINK_EXTS)" ]; then \
 | 
			
		||||
@@ -413,16 +406,16 @@ clean-shared:
 | 
			
		||||
			done; \
 | 
			
		||||
		fi; \
 | 
			
		||||
		( set -x; rm -f lib$$i$(SHLIB_EXT) ); \
 | 
			
		||||
		if expr "$(PLATFORM)" : "Cygwin" >/dev/null; then \
 | 
			
		||||
		if [ "$(PLATFORM)" = "Cygwin" ]; then \
 | 
			
		||||
			( set -x; rm -f cyg$$i$(SHLIB_EXT) lib$$i$(SHLIB_EXT).a ); \
 | 
			
		||||
		fi; \
 | 
			
		||||
	done
 | 
			
		||||
 | 
			
		||||
link-shared:
 | 
			
		||||
	@ set -e; for i in $(SHLIBDIRS); do \
 | 
			
		||||
	@ set -e; for i in ${SHLIBDIRS}; do \
 | 
			
		||||
		$(MAKE) -f $(HERE)/Makefile.shared -e $(BUILDENV) \
 | 
			
		||||
			LIBNAME=$$i LIBVERSION=$(SHLIB_MAJOR).$(SHLIB_MINOR) \
 | 
			
		||||
			LIBCOMPATVERSIONS=";$(SHLIB_VERSION_HISTORY)" \
 | 
			
		||||
			LIBNAME=$$i LIBVERSION=${SHLIB_MAJOR}.${SHLIB_MINOR} \
 | 
			
		||||
			LIBCOMPATVERSIONS=";${SHLIB_VERSION_HISTORY}" \
 | 
			
		||||
			symlink.$(SHLIB_TARGET); \
 | 
			
		||||
		libs="$$libs -l$$i"; \
 | 
			
		||||
	done
 | 
			
		||||
@@ -430,13 +423,13 @@ link-shared:
 | 
			
		||||
build-shared: do_$(SHLIB_TARGET) link-shared
 | 
			
		||||
 | 
			
		||||
do_$(SHLIB_TARGET):
 | 
			
		||||
	@ set -e; libs='-L. $(SHLIBDEPS)'; for i in $(SHLIBDIRS); do \
 | 
			
		||||
		if [ "$$i" = "ssl" -a -n "$(LIBKRB5)" ]; then \
 | 
			
		||||
	@ set -e; libs='-L. ${SHLIBDEPS}'; for i in ${SHLIBDIRS}; do \
 | 
			
		||||
		if [ "${SHLIBDIRS}" = "ssl" -a -n "$(LIBKRB5)" ]; then \
 | 
			
		||||
			libs="$(LIBKRB5) $$libs"; \
 | 
			
		||||
		fi; \
 | 
			
		||||
		$(CLEARENV) && $(MAKE) -f Makefile.shared -e $(BUILDENV) \
 | 
			
		||||
			LIBNAME=$$i LIBVERSION=$(SHLIB_MAJOR).$(SHLIB_MINOR) \
 | 
			
		||||
			LIBCOMPATVERSIONS=";$(SHLIB_VERSION_HISTORY)" \
 | 
			
		||||
			LIBNAME=$$i LIBVERSION=${SHLIB_MAJOR}.${SHLIB_MINOR} \
 | 
			
		||||
			LIBCOMPATVERSIONS=";${SHLIB_VERSION_HISTORY}" \
 | 
			
		||||
			LIBDEPS="$$libs $(EX_LIBS)" \
 | 
			
		||||
			link_a.$(SHLIB_TARGET); \
 | 
			
		||||
		libs="-l$$i $$libs"; \
 | 
			
		||||
@@ -452,8 +445,7 @@ libcrypto.pc: Makefile
 | 
			
		||||
	    echo 'Description: OpenSSL cryptography library'; \
 | 
			
		||||
	    echo 'Version: '$(VERSION); \
 | 
			
		||||
	    echo 'Requires: '; \
 | 
			
		||||
	    echo 'Libs: -L$${libdir} -lcrypto'; \
 | 
			
		||||
	    echo 'Libs.private: $(EX_LIBS)'; \
 | 
			
		||||
	    echo 'Libs: -L$${libdir} -lcrypto $(EX_LIBS)'; \
 | 
			
		||||
	    echo 'Cflags: -I$${includedir} $(KRB5_INCLUDES)' ) > libcrypto.pc
 | 
			
		||||
 | 
			
		||||
libssl.pc: Makefile
 | 
			
		||||
@@ -462,12 +454,11 @@ libssl.pc: Makefile
 | 
			
		||||
	    echo 'libdir=$${exec_prefix}/$(LIBDIR)'; \
 | 
			
		||||
	    echo 'includedir=$${prefix}/include'; \
 | 
			
		||||
	    echo ''; \
 | 
			
		||||
	    echo 'Name: OpenSSL-libssl'; \
 | 
			
		||||
	    echo 'Name: OpenSSL'; \
 | 
			
		||||
	    echo 'Description: Secure Sockets Layer and cryptography libraries'; \
 | 
			
		||||
	    echo 'Version: '$(VERSION); \
 | 
			
		||||
	    echo 'Requires.private: libcrypto'; \
 | 
			
		||||
	    echo 'Libs: -L$${libdir} -lssl'; \
 | 
			
		||||
	    echo 'Libs.private: $(EX_LIBS)'; \
 | 
			
		||||
	    echo 'Requires: '; \
 | 
			
		||||
	    echo 'Libs: -L$${libdir} -lssl -lcrypto $(EX_LIBS)'; \
 | 
			
		||||
	    echo 'Cflags: -I$${includedir} $(KRB5_INCLUDES)' ) > libssl.pc
 | 
			
		||||
 | 
			
		||||
openssl.pc: Makefile
 | 
			
		||||
@@ -479,7 +470,9 @@ openssl.pc: Makefile
 | 
			
		||||
	    echo 'Name: OpenSSL'; \
 | 
			
		||||
	    echo 'Description: Secure Sockets Layer and cryptography libraries and tools'; \
 | 
			
		||||
	    echo 'Version: '$(VERSION); \
 | 
			
		||||
	    echo 'Requires: libssl libcrypto' ) > openssl.pc
 | 
			
		||||
	    echo 'Requires: '; \
 | 
			
		||||
	    echo 'Libs: -L$${libdir} -lssl -lcrypto $(EX_LIBS)'; \
 | 
			
		||||
	    echo 'Cflags: -I$${includedir} $(KRB5_INCLUDES)' ) > openssl.pc
 | 
			
		||||
 | 
			
		||||
Makefile: Makefile.org Configure config
 | 
			
		||||
	@echo "Makefile is older than Makefile.org, Configure or config."
 | 
			
		||||
@@ -487,13 +480,12 @@ Makefile: Makefile.org Configure config
 | 
			
		||||
	@false
 | 
			
		||||
 | 
			
		||||
libclean:
 | 
			
		||||
	rm -f *.map *.so *.so.* *.dylib *.dll engines/*.so engines/*.dll engines/*.dylib *.a engines/*.a */lib */*/lib
 | 
			
		||||
	rm -f *.map *.so *.so.* *.dll engines/*.so engines/*.dll *.a engines/*.a */lib */*/lib
 | 
			
		||||
 | 
			
		||||
clean:	libclean
 | 
			
		||||
	rm -f shlib/*.o *.o core a.out fluff rehash.time testlog make.log cctest cctest.c
 | 
			
		||||
	rm -rf *.bak certs/.0
 | 
			
		||||
	@set -e; target=clean; $(RECURSIVE_BUILD_CMD)
 | 
			
		||||
	rm -f $(LIBS) tags TAGS
 | 
			
		||||
	rm -f $(LIBS)
 | 
			
		||||
	rm -f openssl.pc libssl.pc libcrypto.pc
 | 
			
		||||
	rm -f speed.* .pure
 | 
			
		||||
	rm -f $(TARFILE)
 | 
			
		||||
@@ -514,31 +506,34 @@ links:
 | 
			
		||||
	@$(PERL) $(TOP)/util/mkdir-p.pl include/openssl
 | 
			
		||||
	@$(PERL) $(TOP)/util/mklink.pl include/openssl $(EXHEADER)
 | 
			
		||||
	@set -e; target=links; $(RECURSIVE_BUILD_CMD)
 | 
			
		||||
	@if [ -z "$(FIPSCANLIB)" ]; then \
 | 
			
		||||
		set -e; target=links; dir=fips ; $(BUILD_CMD) ; \
 | 
			
		||||
	fi
 | 
			
		||||
 | 
			
		||||
gentests:
 | 
			
		||||
	@(cd test && echo "generating dummy tests (if needed)..." && \
 | 
			
		||||
	$(CLEARENV) && $(MAKE) -e $(BUILDENV) TESTS='$(TESTS)' OPENSSL_DEBUG_MEMORY=on generate );
 | 
			
		||||
	$(CLEARENV) && $(MAKE) -e $(BUILDENV) TESTS='${TESTS}' OPENSSL_DEBUG_MEMORY=on generate );
 | 
			
		||||
 | 
			
		||||
dclean:
 | 
			
		||||
	rm -f *.bak
 | 
			
		||||
	@set -e; target=dclean; $(RECURSIVE_BUILD_CMD)
 | 
			
		||||
 | 
			
		||||
rehash: rehash.time
 | 
			
		||||
rehash.time: certs apps
 | 
			
		||||
	@if [ -z "$(CROSS_COMPILE)" ]; then \
 | 
			
		||||
		(OPENSSL="`pwd`/util/opensslwrap.sh"; \
 | 
			
		||||
		[ -x "apps/openssl.exe" ] && OPENSSL="apps/openssl.exe" || :; \
 | 
			
		||||
		OPENSSL_DEBUG_MEMORY=on; \
 | 
			
		||||
		export OPENSSL OPENSSL_DEBUG_MEMORY; \
 | 
			
		||||
		$(PERL) tools/c_rehash certs/demo) && \
 | 
			
		||||
		$(PERL) tools/c_rehash certs) && \
 | 
			
		||||
		touch rehash.time; \
 | 
			
		||||
	else :; fi
 | 
			
		||||
	fi
 | 
			
		||||
 | 
			
		||||
test:   tests
 | 
			
		||||
 | 
			
		||||
tests: rehash
 | 
			
		||||
	@(cd test && echo "testing..." && \
 | 
			
		||||
	$(CLEARENV) && $(MAKE) -e $(BUILDENV) TOP=.. TESTS='$(TESTS)' OPENSSL_DEBUG_MEMORY=on OPENSSL_CONF=../apps/openssl.cnf tests );
 | 
			
		||||
	OPENSSL_CONF=apps/openssl.cnf util/opensslwrap.sh version -a
 | 
			
		||||
	$(CLEARENV) && $(MAKE) -e $(BUILDENV) TOP=.. TESTS='${TESTS}' OPENSSL_DEBUG_MEMORY=on tests );
 | 
			
		||||
	util/opensslwrap.sh version -a
 | 
			
		||||
 | 
			
		||||
report:
 | 
			
		||||
	@$(PERL) util/selftest.pl
 | 
			
		||||
@@ -549,17 +544,14 @@ depend:
 | 
			
		||||
lint:
 | 
			
		||||
	@set -e; target=lint; $(RECURSIVE_BUILD_CMD)
 | 
			
		||||
 | 
			
		||||
tags TAGS: FORCE
 | 
			
		||||
	rm -f TAGS tags
 | 
			
		||||
	-ctags -R .
 | 
			
		||||
	-etags -R .
 | 
			
		||||
 | 
			
		||||
FORCE:
 | 
			
		||||
tags:
 | 
			
		||||
	rm -f TAGS
 | 
			
		||||
	find . -name '[^.]*.[ch]' | xargs etags -a
 | 
			
		||||
 | 
			
		||||
errors:
 | 
			
		||||
	$(PERL) util/ck_errf.pl -strict */*.c */*/*.c
 | 
			
		||||
	$(PERL) util/mkerr.pl -recurse -write
 | 
			
		||||
	(cd engines; $(MAKE) PERL=$(PERL) errors)
 | 
			
		||||
	$(PERL) util/ck_errf.pl */*.c */*/*.c
 | 
			
		||||
 | 
			
		||||
stacks:
 | 
			
		||||
	$(PERL) util/mkstack.pl -write
 | 
			
		||||
@@ -574,8 +566,6 @@ crypto/objects/obj_dat.h: crypto/objects/obj_dat.pl crypto/objects/obj_mac.h
 | 
			
		||||
	$(PERL) crypto/objects/obj_dat.pl crypto/objects/obj_mac.h crypto/objects/obj_dat.h
 | 
			
		||||
crypto/objects/obj_mac.h: crypto/objects/objects.pl crypto/objects/objects.txt crypto/objects/obj_mac.num
 | 
			
		||||
	$(PERL) crypto/objects/objects.pl crypto/objects/objects.txt crypto/objects/obj_mac.num crypto/objects/obj_mac.h
 | 
			
		||||
crypto/objects/obj_xref.h: crypto/objects/objxref.pl crypto/objects/obj_xref.txt crypto/objects/obj_mac.num
 | 
			
		||||
	$(PERL) crypto/objects/objxref.pl crypto/objects/obj_mac.num crypto/objects/obj_xref.txt >crypto/objects/obj_xref.h
 | 
			
		||||
 | 
			
		||||
apps/openssl-vms.cnf: apps/openssl.cnf
 | 
			
		||||
	$(PERL) VMS/VMSify-conf.pl < apps/openssl.cnf > apps/openssl-vms.cnf
 | 
			
		||||
@@ -588,7 +578,7 @@ TABLE: Configure
 | 
			
		||||
	(echo 'Output of `Configure TABLE'"':"; \
 | 
			
		||||
	$(PERL) Configure TABLE) > TABLE
 | 
			
		||||
 | 
			
		||||
update: errors stacks util/libeay.num util/ssleay.num crypto/objects/obj_dat.h crypto/objects/obj_xref.h apps/openssl-vms.cnf crypto/bn/bn_prime.h TABLE depend
 | 
			
		||||
update: errors stacks util/libeay.num util/ssleay.num crypto/objects/obj_dat.h apps/openssl-vms.cnf crypto/bn/bn_prime.h TABLE depend
 | 
			
		||||
 | 
			
		||||
# Build distribution tar-file. As the list of files returned by "find" is
 | 
			
		||||
# pretty long, on several platforms a "too many arguments" error or similar
 | 
			
		||||
@@ -619,25 +609,30 @@ tar-snap:
 | 
			
		||||
dist:   
 | 
			
		||||
	$(PERL) Configure dist
 | 
			
		||||
	@$(MAKE) dist_pem_h
 | 
			
		||||
	@$(MAKE) SDIRS='$(SDIRS)' clean
 | 
			
		||||
	@$(MAKE) TAR='$(TAR)' TARFLAGS='$(TARFLAGS)' tar
 | 
			
		||||
	@$(MAKE) SDIRS='${SDIRS}' clean
 | 
			
		||||
	@$(MAKE) TAR='${TAR}' TARFLAGS='${TARFLAGS}' tar
 | 
			
		||||
 | 
			
		||||
dist_pem_h:
 | 
			
		||||
	(cd crypto/pem; $(MAKE) -e $(BUILDENV) pem.h; $(MAKE) clean)
 | 
			
		||||
 | 
			
		||||
install: all install_docs install_sw
 | 
			
		||||
 | 
			
		||||
uninstall: uninstall_sw uninstall_docs
 | 
			
		||||
 | 
			
		||||
install_sw:
 | 
			
		||||
	@$(PERL) $(TOP)/util/mkdir-p.pl $(INSTALLDIRS)
 | 
			
		||||
	@$(PERL) $(TOP)/util/mkdir-p.pl $(INSTALL_PREFIX)$(INSTALLTOP)/bin \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR) \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/engines \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig \
 | 
			
		||||
		$(INSTALL_PREFIX)$(INSTALLTOP)/include/openssl \
 | 
			
		||||
		$(INSTALL_PREFIX)$(OPENSSLDIR)/misc \
 | 
			
		||||
		$(INSTALL_PREFIX)$(OPENSSLDIR)/certs \
 | 
			
		||||
		$(INSTALL_PREFIX)$(OPENSSLDIR)/private
 | 
			
		||||
	@set -e; headerlist="$(EXHEADER)"; for i in $$headerlist;\
 | 
			
		||||
	do \
 | 
			
		||||
	(cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/include/openssl/$$i; \
 | 
			
		||||
	chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/include/openssl/$$i ); \
 | 
			
		||||
	done;
 | 
			
		||||
	@set -e; target=install; $(RECURSIVE_BUILD_CMD)
 | 
			
		||||
	@set -e; liblist="$(LIBS)"; for i in $$liblist ;\
 | 
			
		||||
	@set -e; for i in $(LIBS) ;\
 | 
			
		||||
	do \
 | 
			
		||||
		if [ -f "$$i" ]; then \
 | 
			
		||||
		(       echo installing $$i; \
 | 
			
		||||
@@ -653,7 +648,11 @@ install_sw:
 | 
			
		||||
		do \
 | 
			
		||||
			if [ -f "$$i" -o -f "$$i.a" ]; then \
 | 
			
		||||
			(       echo installing $$i; \
 | 
			
		||||
				if expr "$(PLATFORM)" : "Cygwin" >/dev/null; then \
 | 
			
		||||
				if [ "$(PLATFORM)" != "Cygwin" ]; then \
 | 
			
		||||
					cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
 | 
			
		||||
					chmod 555 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
 | 
			
		||||
					mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
				else \
 | 
			
		||||
					c=`echo $$i | sed 's/^lib\(.*\)\.dll\.a/cyg\1-$(SHLIB_VERSION_NUMBER).dll/'`; \
 | 
			
		||||
					cp $$c $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new; \
 | 
			
		||||
					chmod 755 $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new; \
 | 
			
		||||
@@ -661,21 +660,7 @@ install_sw:
 | 
			
		||||
					cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
 | 
			
		||||
					chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
 | 
			
		||||
					mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
				else \
 | 
			
		||||
					cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
 | 
			
		||||
					chmod 555 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
 | 
			
		||||
					mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
				fi ); \
 | 
			
		||||
				if expr $(PLATFORM) : 'mingw' > /dev/null; then \
 | 
			
		||||
				(	case $$i in \
 | 
			
		||||
						*crypto*) i=libeay32.dll;; \
 | 
			
		||||
						*ssl*)    i=ssleay32.dll;; \
 | 
			
		||||
					esac; \
 | 
			
		||||
					echo installing $$i; \
 | 
			
		||||
					cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$i.new; \
 | 
			
		||||
					chmod 755 $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$i.new; \
 | 
			
		||||
					mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$i ); \
 | 
			
		||||
				fi; \
 | 
			
		||||
			fi; \
 | 
			
		||||
		done; \
 | 
			
		||||
		(	here="`pwd`"; \
 | 
			
		||||
@@ -695,114 +680,33 @@ install_sw:
 | 
			
		||||
	cp openssl.pc $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig
 | 
			
		||||
	chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig/openssl.pc
 | 
			
		||||
 | 
			
		||||
uninstall_sw:
 | 
			
		||||
	cd include/openssl && files=* && cd $(INSTALL_PREFIX)$(INSTALLTOP)/include/openssl && $(RM) $$files
 | 
			
		||||
	@for i in $(LIBS) ;\
 | 
			
		||||
	do \
 | 
			
		||||
		test -f "$$i" && \
 | 
			
		||||
		echo $(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i && \
 | 
			
		||||
		$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
	done;
 | 
			
		||||
	@if [ -n "$(SHARED_LIBS)" ]; then \
 | 
			
		||||
		tmp="$(SHARED_LIBS)"; \
 | 
			
		||||
		for i in $${tmp:-x}; \
 | 
			
		||||
		do \
 | 
			
		||||
			if [ -f "$$i" -o -f "$$i.a" ]; then \
 | 
			
		||||
				if expr "$(PLATFORM)" : "Cygwin" >/dev/null; then \
 | 
			
		||||
					c=`echo $$i | sed 's/^lib\(.*\)\.dll\.a/cyg\1-$(SHLIB_VERSION_NUMBER).dll/'`; \
 | 
			
		||||
					echo $(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c; \
 | 
			
		||||
					$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c; \
 | 
			
		||||
					echo $(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
					$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
				else \
 | 
			
		||||
					echo $(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
					$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
 | 
			
		||||
				fi; \
 | 
			
		||||
				if expr $(PLATFORM) : 'mingw' > /dev/null; then \
 | 
			
		||||
					case $$i in \
 | 
			
		||||
						*crypto*) i=libeay32.dll;; \
 | 
			
		||||
						*ssl*)    i=ssleay32.dll;; \
 | 
			
		||||
					esac; \
 | 
			
		||||
					echo $(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$i; \
 | 
			
		||||
					$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$i; \
 | 
			
		||||
				fi; \
 | 
			
		||||
			fi; \
 | 
			
		||||
		done; \
 | 
			
		||||
	fi
 | 
			
		||||
	$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig/libcrypto.pc
 | 
			
		||||
	$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig/libssl.pc
 | 
			
		||||
	$(RM) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig/openssl.pc
 | 
			
		||||
	@target=uninstall; $(RECURSIVE_BUILD_CMD)
 | 
			
		||||
 | 
			
		||||
install_html_docs:
 | 
			
		||||
	here="`pwd`"; \
 | 
			
		||||
	filecase=; \
 | 
			
		||||
	case "$(PLATFORM)" in DJGPP|Cygwin*|mingw*|darwin*-*-cc) \
 | 
			
		||||
		filecase=-i; \
 | 
			
		||||
	esac; \
 | 
			
		||||
	for subdir in apps crypto ssl; do \
 | 
			
		||||
		$(PERL) $(TOP)/util/mkdir-p $(INSTALL_PREFIX)$(HTMLDIR)/$$subdir; \
 | 
			
		||||
		for i in doc/$$subdir/*.pod; do \
 | 
			
		||||
			fn=`basename $$i .pod`; \
 | 
			
		||||
			echo "installing html/$$fn.$(HTMLSUFFIX)"; \
 | 
			
		||||
			cat $$i \
 | 
			
		||||
			| sed -r 's/L<([^)]*)(\([0-9]\))?\|([^)]*)(\([0-9]\))?>/L<\1|\3>/g' \
 | 
			
		||||
			| pod2html --podroot=doc --htmlroot=.. --podpath=$$subdir:apps:crypto:ssl \
 | 
			
		||||
			| sed -r 's/<!DOCTYPE.*//g' \
 | 
			
		||||
			> $(INSTALL_PREFIX)$(HTMLDIR)/$$subdir/$$fn.$(HTMLSUFFIX); \
 | 
			
		||||
			$(PERL) util/extract-names.pl < $$i | \
 | 
			
		||||
				grep -v $$filecase "^$$fn\$$" | \
 | 
			
		||||
				(cd $(INSTALL_PREFIX)$(HTMLDIR)/$$subdir; \
 | 
			
		||||
				 while read n; do \
 | 
			
		||||
					PLATFORM=$(PLATFORM) $$here/util/point.sh $$fn.$(HTMLSUFFIX) "$$n".$(HTMLSUFFIX); \
 | 
			
		||||
				 done); \
 | 
			
		||||
		done; \
 | 
			
		||||
	done
 | 
			
		||||
 | 
			
		||||
uninstall_html_docs:
 | 
			
		||||
	here="`pwd`"; \
 | 
			
		||||
	filecase=; \
 | 
			
		||||
	case "$(PLATFORM)" in DJGPP|Cygwin*|mingw*|darwin*-*-cc) \
 | 
			
		||||
		filecase=-i; \
 | 
			
		||||
	esac; \
 | 
			
		||||
	for subdir in apps crypto ssl; do \
 | 
			
		||||
		for i in doc/$$subdir/*.pod; do \
 | 
			
		||||
			fn=`basename $$i .pod`; \
 | 
			
		||||
			$(RM) $(INSTALL_PREFIX)$(HTMLDIR)/$$subdir/$$fn.$(HTMLSUFFIX); \
 | 
			
		||||
			$(PERL) util/extract-names.pl < $$i | \
 | 
			
		||||
				grep -v $$filecase "^$$fn\$$" | \
 | 
			
		||||
				while read n; do \
 | 
			
		||||
					$(RM) $(INSTALL_PREFIX)$(HTMLDIR)/$$subdir/"$$n".$(HTMLSUFFIX); \
 | 
			
		||||
				done; \
 | 
			
		||||
		done; \
 | 
			
		||||
	done
 | 
			
		||||
 | 
			
		||||
install_docs:
 | 
			
		||||
	@$(PERL) $(TOP)/util/mkdir-p.pl \
 | 
			
		||||
		$(INSTALL_PREFIX)$(MANDIR)/man1 \
 | 
			
		||||
		$(INSTALL_PREFIX)$(MANDIR)/man3 \
 | 
			
		||||
		$(INSTALL_PREFIX)$(MANDIR)/man5 \
 | 
			
		||||
		$(INSTALL_PREFIX)$(MANDIR)/man7
 | 
			
		||||
	@pod2man="`cd ./util; ./pod2mantest $(PERL)`"; \
 | 
			
		||||
	here="`pwd`"; \
 | 
			
		||||
	filecase=; \
 | 
			
		||||
	case "$(PLATFORM)" in DJGPP|Cygwin*|mingw*|darwin*-*-cc) \
 | 
			
		||||
	if [ "$(PLATFORM)" = "DJGPP" -o "$(PLATFORM)" = "Cygwin" -o "$(PLATFORM)" = "mingw" ]; then \
 | 
			
		||||
		filecase=-i; \
 | 
			
		||||
	esac; \
 | 
			
		||||
	fi; \
 | 
			
		||||
	set -e; for i in doc/apps/*.pod; do \
 | 
			
		||||
		fn=`basename $$i .pod`; \
 | 
			
		||||
		sec=`$(PERL) util/extract-section.pl 1 < $$i`; \
 | 
			
		||||
		echo "installing man$$sec/$$fn.$${sec}$(MANSUFFIX)"; \
 | 
			
		||||
		(cd `$(PERL) util/dirname.pl $$i`; \
 | 
			
		||||
		pod2man \
 | 
			
		||||
		sh -c "$$pod2man \
 | 
			
		||||
			--section=$$sec --center=OpenSSL \
 | 
			
		||||
			--release=$(VERSION) `basename $$i`) \
 | 
			
		||||
			--release=$(VERSION) `basename $$i`") \
 | 
			
		||||
			>  $(INSTALL_PREFIX)$(MANDIR)/man$$sec/$$fn.$${sec}$(MANSUFFIX); \
 | 
			
		||||
		$(PERL) util/extract-names.pl < $$i | \
 | 
			
		||||
			(grep -v $$filecase "^$$fn\$$"; true) | \
 | 
			
		||||
			(grep -v "[	]"; true) | \
 | 
			
		||||
			(cd $(INSTALL_PREFIX)$(MANDIR)/man$$sec/; \
 | 
			
		||||
			 while read n; do \
 | 
			
		||||
				PLATFORM=$(PLATFORM) $$here/util/point.sh $$fn.$${sec}$(MANSUFFIX) "$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
				$$here/util/point.sh $$fn.$${sec}$(MANSUFFIX) "$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
			 done); \
 | 
			
		||||
	done; \
 | 
			
		||||
	set -e; for i in doc/crypto/*.pod doc/ssl/*.pod; do \
 | 
			
		||||
@@ -810,50 +714,17 @@ install_docs:
 | 
			
		||||
		sec=`$(PERL) util/extract-section.pl 3 < $$i`; \
 | 
			
		||||
		echo "installing man$$sec/$$fn.$${sec}$(MANSUFFIX)"; \
 | 
			
		||||
		(cd `$(PERL) util/dirname.pl $$i`; \
 | 
			
		||||
		pod2man \
 | 
			
		||||
		sh -c "$$pod2man \
 | 
			
		||||
			--section=$$sec --center=OpenSSL \
 | 
			
		||||
			--release=$(VERSION) `basename $$i`) \
 | 
			
		||||
			--release=$(VERSION) `basename $$i`") \
 | 
			
		||||
			>  $(INSTALL_PREFIX)$(MANDIR)/man$$sec/$$fn.$${sec}$(MANSUFFIX); \
 | 
			
		||||
		$(PERL) util/extract-names.pl < $$i | \
 | 
			
		||||
			(grep -v $$filecase "^$$fn\$$"; true) | \
 | 
			
		||||
			(grep -v "[	]"; true) | \
 | 
			
		||||
			(cd $(INSTALL_PREFIX)$(MANDIR)/man$$sec/; \
 | 
			
		||||
			 while read n; do \
 | 
			
		||||
				PLATFORM=$(PLATFORM) $$here/util/point.sh $$fn.$${sec}$(MANSUFFIX) "$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
				$$here/util/point.sh $$fn.$${sec}$(MANSUFFIX) "$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
			 done); \
 | 
			
		||||
	done
 | 
			
		||||
 | 
			
		||||
uninstall_docs:
 | 
			
		||||
	@here="`pwd`"; \
 | 
			
		||||
	filecase=; \
 | 
			
		||||
	case "$(PLATFORM)" in DJGPP|Cygwin*|mingw*) \
 | 
			
		||||
		filecase=-i; \
 | 
			
		||||
	esac; \
 | 
			
		||||
	for i in doc/apps/*.pod; do \
 | 
			
		||||
		fn=`basename $$i .pod`; \
 | 
			
		||||
		sec=`$(PERL) util/extract-section.pl 1 < $$i`; \
 | 
			
		||||
		echo $(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/$$fn.$${sec}$(MANSUFFIX); \
 | 
			
		||||
		$(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/$$fn.$${sec}$(MANSUFFIX); \
 | 
			
		||||
		$(PERL) util/extract-names.pl < $$i | \
 | 
			
		||||
			(grep -v $$filecase "^$$fn\$$"; true) | \
 | 
			
		||||
			(grep -v "[	]"; true) | \
 | 
			
		||||
			while read n; do \
 | 
			
		||||
				echo $(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/"$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
				$(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/"$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
			done; \
 | 
			
		||||
	done; \
 | 
			
		||||
	for i in doc/crypto/*.pod doc/ssl/*.pod; do \
 | 
			
		||||
		fn=`basename $$i .pod`; \
 | 
			
		||||
		sec=`$(PERL) util/extract-section.pl 3 < $$i`; \
 | 
			
		||||
		echo $(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/$$fn.$${sec}$(MANSUFFIX); \
 | 
			
		||||
		$(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/$$fn.$${sec}$(MANSUFFIX); \
 | 
			
		||||
		$(PERL) util/extract-names.pl < $$i | \
 | 
			
		||||
			(grep -v $$filecase "^$$fn\$$"; true) | \
 | 
			
		||||
			(grep -v "[	]"; true) | \
 | 
			
		||||
			while read n; do \
 | 
			
		||||
				echo $(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/"$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
				$(RM) $(INSTALL_PREFIX)$(MANDIR)/man$$sec/"$$n".$${sec}$(MANSUFFIX); \
 | 
			
		||||
			done; \
 | 
			
		||||
	done
 | 
			
		||||
 | 
			
		||||
# DO NOT DELETE THIS LINE -- make depend depends on it.
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										147
									
								
								Makefile.shared
									
									
									
									
									
								
							
							
						
						
									
										147
									
								
								Makefile.shared
									
									
									
									
									
								
							@@ -14,8 +14,6 @@ CFLAGS=$(CFLAG)
 | 
			
		||||
LDFLAGS=
 | 
			
		||||
SHARED_LDFLAGS=
 | 
			
		||||
 | 
			
		||||
NM=nm
 | 
			
		||||
 | 
			
		||||
# LIBNAME contains just the name of the library, without prefix ("lib"
 | 
			
		||||
# on Unix, "cyg" for certain forms under Cygwin...) or suffix (.a, .so,
 | 
			
		||||
# .dll, ...).  This one MUST have a value when using this makefile to
 | 
			
		||||
@@ -93,7 +91,7 @@ LINK_APP=	\
 | 
			
		||||
  ( $(SET_X);   \
 | 
			
		||||
    LIBDEPS="$${LIBDEPS:-$(LIBDEPS)}"; \
 | 
			
		||||
    LDCMD="$${LDCMD:-$(CC)}"; LDFLAGS="$${LDFLAGS:-$(CFLAGS)}"; \
 | 
			
		||||
    LIBPATH=`for x in $$LIBDEPS; do echo $$x; done | sed -e 's/^ *-L//;t' -e d | uniq`; \
 | 
			
		||||
    LIBPATH=`for x in $$LIBDEPS; do if echo $$x | grep '^ *-L' > /dev/null 2>&1; then echo $$x | sed -e 's/^ *-L//'; fi; done | uniq`; \
 | 
			
		||||
    LIBPATH=`echo $$LIBPATH | sed -e 's/ /:/g'`; \
 | 
			
		||||
    LD_LIBRARY_PATH=$$LIBPATH:$$LD_LIBRARY_PATH \
 | 
			
		||||
    $${LDCMD} $${LDFLAGS} -o $${APPNAME:=$(APPNAME)} $(OBJECTS) $${LIBDEPS} )
 | 
			
		||||
@@ -103,7 +101,7 @@ LINK_SO=	\
 | 
			
		||||
    LIBDEPS="$${LIBDEPS:-$(LIBDEPS)}"; \
 | 
			
		||||
    SHAREDCMD="$${SHAREDCMD:-$(CC)}"; \
 | 
			
		||||
    SHAREDFLAGS="$${SHAREDFLAGS:-$(CFLAGS) $(SHARED_LDFLAGS)}"; \
 | 
			
		||||
    LIBPATH=`for x in $$LIBDEPS; do echo $$x; done | sed -e 's/^ *-L//;t' -e d | uniq`; \
 | 
			
		||||
    LIBPATH=`for x in $$LIBDEPS; do if echo $$x | grep '^ *-L' > /dev/null 2>&1; then echo $$x | sed -e 's/^ *-L//'; fi; done | uniq`; \
 | 
			
		||||
    LIBPATH=`echo $$LIBPATH | sed -e 's/ /:/g'`; \
 | 
			
		||||
    LD_LIBRARY_PATH=$$LIBPATH:$$LD_LIBRARY_PATH \
 | 
			
		||||
    $${SHAREDCMD} $${SHAREDFLAGS} \
 | 
			
		||||
@@ -135,7 +133,7 @@ LINK_SO_A_VIA_O=	\
 | 
			
		||||
  ALL=$$ALLSYMSFLAGS; ALLSYMSFLAGS=; NOALLSYMSFLAGS=; \
 | 
			
		||||
  ( $(SET_X); \
 | 
			
		||||
    ld $(LDFLAGS) -r -o lib$(LIBNAME).o $$ALL lib$(LIBNAME).a $(LIBEXTRAS) ); \
 | 
			
		||||
  $(LINK_SO) && rm -f lib$(LIBNAME).o
 | 
			
		||||
  $(LINK_SO) && rm -f $(LIBNAME).o
 | 
			
		||||
 | 
			
		||||
LINK_SO_A_UNPACKED=	\
 | 
			
		||||
  UNPACKDIR=link_tmp.$$$$; rm -rf $$UNPACKDIR; mkdir $$UNPACKDIR; \
 | 
			
		||||
@@ -144,7 +142,7 @@ LINK_SO_A_UNPACKED=	\
 | 
			
		||||
  SHOBJECTS=$$UNPACKDIR/*.o; \
 | 
			
		||||
  $(LINK_SO) && rm -rf $$UNPACKDIR
 | 
			
		||||
 | 
			
		||||
DETECT_GNU_LD=($(CC) -Wl,-V /dev/null 2>&1 | grep '^GNU ld' )>/dev/null
 | 
			
		||||
DETECT_GNU_LD=(${CC} -Wl,-V /dev/null 2>&1 | grep '^GNU ld' )>/dev/null
 | 
			
		||||
 | 
			
		||||
DO_GNU_SO=$(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
@@ -171,7 +169,7 @@ link_app.gnu:
 | 
			
		||||
	@ $(DO_GNU_APP); $(LINK_APP)
 | 
			
		||||
 | 
			
		||||
link_o.bsd:
 | 
			
		||||
	@if $(DETECT_GNU_LD); then $(DO_GNU_SO); else \
 | 
			
		||||
	@if ${DETECT_GNU_LD}; then $(DO_GNU_SO); else \
 | 
			
		||||
	$(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
	SHLIB_SUFFIX=; \
 | 
			
		||||
@@ -181,7 +179,7 @@ link_o.bsd:
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) $(SHARED_LDFLAGS) -shared -nostdlib"; \
 | 
			
		||||
	fi; $(LINK_SO_O)
 | 
			
		||||
link_a.bsd:
 | 
			
		||||
	@if $(DETECT_GNU_LD); then $(DO_GNU_SO); else \
 | 
			
		||||
	@if ${DETECT_GNU_LD}; then $(DO_GNU_SO); else \
 | 
			
		||||
	$(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
	SHLIB_SUFFIX=; \
 | 
			
		||||
@@ -191,34 +189,24 @@ link_a.bsd:
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) $(SHARED_LDFLAGS) -shared -nostdlib"; \
 | 
			
		||||
	fi; $(LINK_SO_A)
 | 
			
		||||
link_app.bsd:
 | 
			
		||||
	@if $(DETECT_GNU_LD); then $(DO_GNU_APP); else \
 | 
			
		||||
	@if ${DETECT_GNU_LD}; then $(DO_GNU_APP); else \
 | 
			
		||||
	LDFLAGS="$(CFLAGS) -Wl,-rpath,$(LIBPATH)"; \
 | 
			
		||||
	fi; $(LINK_APP)
 | 
			
		||||
 | 
			
		||||
# For Darwin AKA Mac OS/X (dyld)
 | 
			
		||||
# Originally link_o.darwin produced .so, because it was hard-coded
 | 
			
		||||
# in dso_dlfcn module. At later point dso_dlfcn switched to .dylib
 | 
			
		||||
# extension in order to allow for run-time linking with vendor-
 | 
			
		||||
# supplied shared libraries such as libz, so that link_o.darwin had
 | 
			
		||||
# to be harmonized with it. This caused minor controversy, because
 | 
			
		||||
# it was believed that dlopen can't be used to dynamically load
 | 
			
		||||
# .dylib-s, only so called bundle modules (ones linked with -bundle
 | 
			
		||||
# flag). The belief seems to be originating from pre-10.4 release,
 | 
			
		||||
# where dlfcn functionality was emulated by dlcompat add-on. In
 | 
			
		||||
# 10.4 dlopen was rewritten as native part of dyld and is documented
 | 
			
		||||
# to be capable of loading both dynamic libraries and bundles. In
 | 
			
		||||
# order to provide compatibility with pre-10.4 dlopen, modules are
 | 
			
		||||
# linked with -bundle flag, which makes .dylib extension misleading.
 | 
			
		||||
# It works, because dlopen is [and always was] extension-agnostic.
 | 
			
		||||
# Alternative to this heuristic approach is to develop specific
 | 
			
		||||
# MacOS X dso module relying on whichever "native" dyld interface.
 | 
			
		||||
# link_o.darwin produces .so, because we let it use dso_dlfcn module,
 | 
			
		||||
# which has .so extension hard-coded. One can argue that one should
 | 
			
		||||
# develop special dso module for MacOS X. At least manual encourages
 | 
			
		||||
# to use native NSModule(3) API and refers to dlfcn as termporary hack.
 | 
			
		||||
link_o.darwin:
 | 
			
		||||
	@ $(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME); \
 | 
			
		||||
	SHLIB_SUFFIX=.dylib; \
 | 
			
		||||
	SHLIB=`expr "$$THIS" : '.*/\([^/\.]*\)\.'`; \
 | 
			
		||||
	SHLIB=$${SHLIB:-lib$(LIBNAME)}; \
 | 
			
		||||
	SHLIB_SUFFIX=`expr "$$THIS" : '.*\(\.[^\.]*\)$$'`; \
 | 
			
		||||
	SHLIB_SUFFIX=$${SHLIB_SUFFIX:-.so}; \
 | 
			
		||||
	ALLSYMSFLAGS='-all_load'; \
 | 
			
		||||
	NOALLSYMSFLAGS=''; \
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) `echo $(SHARED_LDFLAGS) | sed s/dynamiclib/bundle/`"; \
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) $(SHARED_LDFLAGS)"; \
 | 
			
		||||
	if [ -n "$(LIBVERSION)" ]; then \
 | 
			
		||||
		SHAREDFLAGS="$$SHAREDFLAGS -current_version $(LIBVERSION)"; \
 | 
			
		||||
	fi; \
 | 
			
		||||
@@ -239,7 +227,7 @@ link_a.darwin:
 | 
			
		||||
	if [ -n "$$SHLIB_SOVER_NODOT" ]; then \
 | 
			
		||||
		SHAREDFLAGS="$$SHAREDFLAGS -compatibility_version $$SHLIB_SOVER_NODOT"; \
 | 
			
		||||
	fi; \
 | 
			
		||||
	SHAREDFLAGS="$$SHAREDFLAGS -install_name $(INSTALLTOP)/$(LIBDIR)/$$SHLIB$(SHLIB_EXT)"; \
 | 
			
		||||
	SHAREDFLAGS="$$SHAREDFLAGS -install_name ${INSTALLTOP}/lib/$$SHLIB${SHLIB_EXT}"; \
 | 
			
		||||
	$(LINK_SO_A)
 | 
			
		||||
link_app.darwin:	# is there run-path on darwin?
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
@@ -249,59 +237,40 @@ link_o.cygwin:
 | 
			
		||||
	INHIBIT_SYMLINKS=yes; \
 | 
			
		||||
	SHLIB=cyg$(LIBNAME); \
 | 
			
		||||
	base=-Wl,--enable-auto-image-base; \
 | 
			
		||||
	deffile=; \
 | 
			
		||||
	if expr $(PLATFORM) : 'mingw' > /dev/null; then \
 | 
			
		||||
		SHLIB=$(LIBNAME)eay32; base=; \
 | 
			
		||||
		if test -f $(LIBNAME)eay32.def; then \
 | 
			
		||||
			deffile=$(LIBNAME)eay32.def; \
 | 
			
		||||
		fi; \
 | 
			
		||||
	fi; \
 | 
			
		||||
	SHLIB_SUFFIX=.dll; \
 | 
			
		||||
	LIBVERSION="$(LIBVERSION)"; \
 | 
			
		||||
	SHLIB_SOVER=${LIBVERSION:+"-$(LIBVERSION)"}; \
 | 
			
		||||
	ALLSYMSFLAGS='-Wl,--whole-archive'; \
 | 
			
		||||
	NOALLSYMSFLAGS='-Wl,--no-whole-archive'; \
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) $(SHARED_LDFLAGS) -shared $$base $$deffile -Wl,-s,-Bsymbolic"; \
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) $(SHARED_LDFLAGS) -shared $$base -Wl,-Bsymbolic -Wl,--out-implib,lib$(LIBNAME).dll.a"; \
 | 
			
		||||
	$(LINK_SO_O)
 | 
			
		||||
#for mingw target if def-file is in use dll-name should match library-name
 | 
			
		||||
link_a.cygwin:
 | 
			
		||||
	@ $(CALC_VERSIONS); \
 | 
			
		||||
	INHIBIT_SYMLINKS=yes; \
 | 
			
		||||
	SHLIB=cyg$(LIBNAME); SHLIB_SOVER=-$(LIBVERSION); SHLIB_SUFFIX=.dll; \
 | 
			
		||||
	dll_name=$$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX; extras=; \
 | 
			
		||||
	SHLIB=cyg$(LIBNAME); \
 | 
			
		||||
	base=-Wl,--enable-auto-image-base; \
 | 
			
		||||
	if expr $(PLATFORM) : 'mingw' > /dev/null; then \
 | 
			
		||||
		case $(LIBNAME) in \
 | 
			
		||||
			crypto) SHLIB=libeay;; \
 | 
			
		||||
			ssl) SHLIB=ssleay;; \
 | 
			
		||||
		esac; \
 | 
			
		||||
		SHLIB_SOVER=32; \
 | 
			
		||||
		extras="$(LIBNAME).def"; \
 | 
			
		||||
		$(PERL) util/mkdef.pl 32 $$SHLIB > $$extras; \
 | 
			
		||||
		SHLIB=$(LIBNAME)eay32; \
 | 
			
		||||
		base=;  [ $(LIBNAME) = "crypto" ] && base=-Wl,--image-base,0x63000000; \
 | 
			
		||||
	fi; \
 | 
			
		||||
	dll_name=$$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX; \
 | 
			
		||||
	$(PERL) util/mkrc.pl $$dll_name | \
 | 
			
		||||
		$(CROSS_COMPILE)windres -o rc.o; \
 | 
			
		||||
	extras="$$extras rc.o"; \
 | 
			
		||||
	SHLIB_SUFFIX=.dll; \
 | 
			
		||||
	SHLIB_SOVER=-$(LIBVERSION); \
 | 
			
		||||
	ALLSYMSFLAGS='-Wl,--whole-archive'; \
 | 
			
		||||
	NOALLSYMSFLAGS='-Wl,--no-whole-archive'; \
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) $(SHARED_LDFLAGS) -shared $$base -Wl,-s,-Bsymbolic -Wl,--out-implib,lib$(LIBNAME).dll.a $$extras"; \
 | 
			
		||||
	[ -f apps/$$dll_name ] && rm apps/$$dll_name; \
 | 
			
		||||
	[ -f test/$$dll_name ] && rm test/$$dll_name; \
 | 
			
		||||
	SHAREDFLAGS="$(CFLAGS) $(SHARED_LDFLAGS) -shared $$base -Wl,-Bsymbolic -Wl,--out-implib,lib$(LIBNAME).dll.a"; \
 | 
			
		||||
	[ -f apps/$$SHLIB$$SHLIB_SUFFIX ] && rm apps/$$SHLIB$$SHLIB_SUFFIX; \
 | 
			
		||||
	[ -f test/$$SHLIB$$SHLIB_SUFFIX ] && rm test/$$SHLIB$$SHLIB_SUFFIX; \
 | 
			
		||||
	$(LINK_SO_A) || exit 1; \
 | 
			
		||||
	rm $$extras; \
 | 
			
		||||
	cp -p $$dll_name apps/; \
 | 
			
		||||
	cp -p $$dll_name test/
 | 
			
		||||
	cp -p $$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX apps/; \
 | 
			
		||||
	cp -p $$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX test/
 | 
			
		||||
link_app.cygwin:
 | 
			
		||||
	@if expr "$(CFLAGS)" : '.*OPENSSL_USE_APPLINK' > /dev/null; then \
 | 
			
		||||
		LIBDEPS="$(TOP)/crypto/applink.o $${LIBDEPS:-$(LIBDEPS)}"; \
 | 
			
		||||
		export LIBDEPS; \
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
 | 
			
		||||
link_o.alpha-osf1:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
@@ -322,7 +291,7 @@ link_o.alpha-osf1:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_O)
 | 
			
		||||
link_a.alpha-osf1:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
@@ -343,7 +312,7 @@ link_a.alpha-osf1:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_A)
 | 
			
		||||
link_app.alpha-osf1:
 | 
			
		||||
	@if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_APP); \
 | 
			
		||||
	else \
 | 
			
		||||
		LDFLAGS="$(CFLAGS) -rpath $(LIBRPATH)"; \
 | 
			
		||||
@@ -351,7 +320,7 @@ link_app.alpha-osf1:
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
 | 
			
		||||
link_o.solaris:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
@@ -365,12 +334,12 @@ link_o.solaris:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_O)
 | 
			
		||||
link_a.solaris:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
		MINUSZ='-z '; \
 | 
			
		||||
		($(CC) -v 2>&1 | grep gcc) > /dev/null && MINUSZ='-Wl,-z,'; \
 | 
			
		||||
		(${CC} -v 2>&1 | grep gcc) > /dev/null && MINUSZ='-Wl,-z,'; \
 | 
			
		||||
		SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
		SHLIB_SUFFIX=;\
 | 
			
		||||
		ALLSYMSFLAGS="$${MINUSZ}allextract"; \
 | 
			
		||||
@@ -379,7 +348,7 @@ link_a.solaris:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_A)
 | 
			
		||||
link_app.solaris:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_APP); \
 | 
			
		||||
	else \
 | 
			
		||||
		LDFLAGS="$(CFLAGS) -R $(LIBRPATH)"; \
 | 
			
		||||
@@ -388,7 +357,7 @@ link_app.solaris:
 | 
			
		||||
 | 
			
		||||
# OpenServer 5 native compilers used
 | 
			
		||||
link_o.svr3:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
@@ -400,7 +369,7 @@ link_o.svr3:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_O)
 | 
			
		||||
link_a.svr3:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
@@ -412,12 +381,12 @@ link_a.svr3:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_A_UNPACKED)
 | 
			
		||||
link_app.svr3:
 | 
			
		||||
	@$(DETECT_GNU_LD) && $(DO_GNU_APP); \
 | 
			
		||||
	@${DETECT_GNU_LD} && $(DO_GNU_APP); \
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
 | 
			
		||||
# UnixWare 7 and OpenUNIX 8 native compilers used
 | 
			
		||||
link_o.svr5:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
@@ -431,12 +400,12 @@ link_o.svr5:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_O)
 | 
			
		||||
link_a.svr5:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
		SHARE_FLAG='-G'; \
 | 
			
		||||
		($(CC) -v 2>&1 | grep gcc) > /dev/null && SHARE_FLAG='-shared'; \
 | 
			
		||||
		(${CC} -v 2>&1 | grep gcc) > /dev/null && SHARE_FLAG='-shared'; \
 | 
			
		||||
		SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
		SHLIB_SUFFIX=; \
 | 
			
		||||
		ALLSYMSFLAGS=''; \
 | 
			
		||||
@@ -445,11 +414,11 @@ link_a.svr5:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_A_UNPACKED)
 | 
			
		||||
link_app.svr5:
 | 
			
		||||
	@$(DETECT_GNU_LD) && $(DO_GNU_APP); \
 | 
			
		||||
	@${DETECT_GNU_LD} && $(DO_GNU_APP); \
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
 | 
			
		||||
link_o.irix:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
@@ -463,7 +432,7 @@ link_o.irix:
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_SO_O)
 | 
			
		||||
link_a.irix:
 | 
			
		||||
	@ if $(DETECT_GNU_LD); then \
 | 
			
		||||
	@ if ${DETECT_GNU_LD}; then \
 | 
			
		||||
		$(DO_GNU_SO); \
 | 
			
		||||
	else \
 | 
			
		||||
		$(CALC_VERSIONS); \
 | 
			
		||||
@@ -489,7 +458,7 @@ link_app.irix:
 | 
			
		||||
# ELFs by the way].
 | 
			
		||||
#
 | 
			
		||||
link_o.hpux:
 | 
			
		||||
	@if $(DETECT_GNU_LD); then $(DO_GNU_SO); else \
 | 
			
		||||
	@if ${DETECT_GNU_LD}; then $(DO_GNU_SO); else \
 | 
			
		||||
	$(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).sl; \
 | 
			
		||||
	expr "$(CFLAGS)" : '.*DSO_DLFCN' > /dev/null && SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
@@ -502,7 +471,7 @@ link_o.hpux:
 | 
			
		||||
	rm -f $$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX || :; \
 | 
			
		||||
	$(LINK_SO_O) && chmod a=rx $$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX
 | 
			
		||||
link_a.hpux:
 | 
			
		||||
	@if $(DETECT_GNU_LD); then $(DO_GNU_SO); else \
 | 
			
		||||
	@if ${DETECT_GNU_LD}; then $(DO_GNU_SO); else \
 | 
			
		||||
	$(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).sl; \
 | 
			
		||||
	expr $(PLATFORM) : '.*ia64' > /dev/null && SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
@@ -515,7 +484,7 @@ link_a.hpux:
 | 
			
		||||
	rm -f $$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX || :; \
 | 
			
		||||
	$(LINK_SO_A) && chmod a=rx $$SHLIB$$SHLIB_SOVER$$SHLIB_SUFFIX
 | 
			
		||||
link_app.hpux:
 | 
			
		||||
	@if $(DETECT_GNU_LD); then $(DO_GNU_APP); else \
 | 
			
		||||
	@if ${DETECT_GNU_LD}; then $(DO_GNU_APP); else \
 | 
			
		||||
	LDFLAGS="$(CFLAGS) -Wl,+s,+cdp,../:,+cdp,./:,+b,$(LIBRPATH)"; \
 | 
			
		||||
	fi; \
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
@@ -544,10 +513,28 @@ link_app.aix:
 | 
			
		||||
	LDFLAGS="$(CFLAGS) -Wl,-brtl,-blibpath:$(LIBRPATH):$${LIBPATH:-/usr/lib:/lib}"; \
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
 | 
			
		||||
link_o.reliantunix:
 | 
			
		||||
	@ $(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
	SHLIB_SUFFIX=; \
 | 
			
		||||
	ALLSYMSFLAGS=; \
 | 
			
		||||
	NOALLSYMSFLAGS=''; \
 | 
			
		||||
	SHAREDFLAGS='$(CFLAGS) -G'; \
 | 
			
		||||
	$(LINK_SO_O)
 | 
			
		||||
link_a.reliantunix:
 | 
			
		||||
	@ $(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
	SHLIB_SUFFIX=; \
 | 
			
		||||
	ALLSYMSFLAGS=; \
 | 
			
		||||
	NOALLSYMSFLAGS=''; \
 | 
			
		||||
	SHAREDFLAGS='$(CFLAGS) -G'; \
 | 
			
		||||
	$(LINK_SO_A_UNPACKED)
 | 
			
		||||
link_app.reliantunix:
 | 
			
		||||
	$(LINK_APP)
 | 
			
		||||
 | 
			
		||||
# Targets to build symbolic links when needed
 | 
			
		||||
symlink.gnu symlink.solaris symlink.svr3 symlink.svr5 symlink.irix \
 | 
			
		||||
symlink.aix:
 | 
			
		||||
symlink.aix symlink.reliantunix:
 | 
			
		||||
	@ $(CALC_VERSIONS); \
 | 
			
		||||
	SHLIB=lib$(LIBNAME).so; \
 | 
			
		||||
	$(SYMLINK_SO)
 | 
			
		||||
@@ -616,3 +603,7 @@ link_o.aix-shared: link_o.aix
 | 
			
		||||
link_a.aix-shared: link_a.aix
 | 
			
		||||
link_app.aix-shared: link_app.aix
 | 
			
		||||
symlink.aix-shared: symlink.aix
 | 
			
		||||
link_o.reliantunix-shared: link_o.reliantunix
 | 
			
		||||
link_a.reliantunix-shared: link_a.reliantunix
 | 
			
		||||
link_app.reliantunix-shared: link_app.reliantunix
 | 
			
		||||
symlink.reliantunix-shared: symlink.reliantunix
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										202
									
								
								NEWS
									
									
									
									
									
								
							
							
						
						
									
										202
									
								
								NEWS
									
									
									
									
									
								
							@@ -5,187 +5,59 @@
 | 
			
		||||
  This file gives a brief overview of the major changes between each OpenSSL
 | 
			
		||||
  release. For more details please read the CHANGES file.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1j and OpenSSL 1.0.2 [in beta]:
 | 
			
		||||
  Major changes between OpenSSL 0.9.8zf and OpenSSL 0.9.8zg [11 Jun 2015]
 | 
			
		||||
 | 
			
		||||
      o Suite B support for TLS 1.2 and DTLS 1.2
 | 
			
		||||
      o Support for DTLS 1.2
 | 
			
		||||
      o TLS automatic EC curve selection.
 | 
			
		||||
      o API to set TLS supported signature algorithms and curves
 | 
			
		||||
      o SSL_CONF configuration API.
 | 
			
		||||
      o TLS Brainpool support.
 | 
			
		||||
      o ALPN support.
 | 
			
		||||
      o CMS support for RSA-PSS, RSA-OAEP, ECDH and X9.42 DH.
 | 
			
		||||
      o Malformed ECParameters causes infinite loop (CVE-2015-1788)
 | 
			
		||||
      o Exploitable out-of-bounds read in X509_cmp_time (CVE-2015-1789)
 | 
			
		||||
      o PKCS7 crash with missing EnvelopedContent (CVE-2015-1790)
 | 
			
		||||
      o CMS verify infinite loop with unknown hash function (CVE-2015-1792)
 | 
			
		||||
      o Race condition handling NewSessionTicket (CVE-2015-1791)
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1i and OpenSSL 1.0.1j [15 Oct 2014]
 | 
			
		||||
  Major changes between OpenSSL 0.9.8ze and OpenSSL 0.9.8zf [19 Mar 2015]
 | 
			
		||||
 | 
			
		||||
      o Segmentation fault in ASN1_TYPE_cmp fix (CVE-2015-0286)
 | 
			
		||||
      o ASN.1 structure reuse memory corruption fix (CVE-2015-0287)
 | 
			
		||||
      o PKCS7 NULL pointer dereferences fix (CVE-2015-0289)
 | 
			
		||||
      o DoS via reachable assert in SSLv2 servers fix (CVE-2015-0293)
 | 
			
		||||
      o Use After Free following d2i_ECPrivatekey error fix (CVE-2015-0209)
 | 
			
		||||
      o X509_to_X509_REQ NULL pointer deref fix (CVE-2015-0288)
 | 
			
		||||
      o Removed the export ciphers from the DEFAULT ciphers
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 0.9.8zd and OpenSSL 0.9.8ze [15 Jan 2015]
 | 
			
		||||
 | 
			
		||||
      o Build fixes for the Windows and OpenVMS platforms
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 0.9.8zc and OpenSSL 0.9.8zd [8 Jan 2015]
 | 
			
		||||
 | 
			
		||||
      o Fix for CVE-2014-3571
 | 
			
		||||
      o Fix for CVE-2014-3569
 | 
			
		||||
      o Fix for CVE-2014-3572
 | 
			
		||||
      o Fix for CVE-2015-0204
 | 
			
		||||
      o Fix for CVE-2014-8275
 | 
			
		||||
      o Fix for CVE-2014-3570
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 0.9.8zb and OpenSSL 0.9.8zc [15 Oct 2014]:
 | 
			
		||||
 | 
			
		||||
      o Fix for CVE-2014-3513
 | 
			
		||||
      o Fix for CVE-2014-3567
 | 
			
		||||
      o Mitigation for CVE-2014-3566 (SSL protocol vulnerability)
 | 
			
		||||
      o Fix for CVE-2014-3568
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1h and OpenSSL 1.0.1i [6 Aug 2014]
 | 
			
		||||
  Major changes between OpenSSL 0.9.8za and OpenSSL 0.9.8zb [6 Aug 2014]:
 | 
			
		||||
 | 
			
		||||
      o Fix for CVE-2014-3512
 | 
			
		||||
      o Fix for CVE-2014-3511
 | 
			
		||||
      o Fix for CVE-2014-3510
 | 
			
		||||
      o Fix for CVE-2014-3507
 | 
			
		||||
      o Fix for CVE-2014-3506
 | 
			
		||||
      o Fix for CVE-2014-3505
 | 
			
		||||
      o Fix for CVE-2014-3509
 | 
			
		||||
      o Fix for CVE-2014-5139
 | 
			
		||||
      o Fix for CVE-2014-3508
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1g and OpenSSL 1.0.1h [5 Jun 2014]
 | 
			
		||||
  Known issues in OpenSSL 0.9.8za:
 | 
			
		||||
 | 
			
		||||
      o Fix for CVE-2014-0224
 | 
			
		||||
      o Fix for CVE-2014-0221
 | 
			
		||||
      o Fix for CVE-2014-0195
 | 
			
		||||
      o Fix for CVE-2014-3470
 | 
			
		||||
      o Fix for CVE-2010-5298
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1f and OpenSSL 1.0.1g [7 Apr 2014]
 | 
			
		||||
 | 
			
		||||
      o Fix for CVE-2014-0160
 | 
			
		||||
      o Add TLS padding extension workaround for broken servers.
 | 
			
		||||
      o Fix for CVE-2014-0076
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1e and OpenSSL 1.0.1f [6 Jan 2014]
 | 
			
		||||
 | 
			
		||||
      o Don't include gmt_unix_time in TLS server and client random values
 | 
			
		||||
      o Fix for TLS record tampering bug CVE-2013-4353
 | 
			
		||||
      o Fix for TLS version checking bug CVE-2013-6449
 | 
			
		||||
      o Fix for DTLS retransmission bug CVE-2013-6450
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1d and OpenSSL 1.0.1e [11 Feb 2013]:
 | 
			
		||||
 | 
			
		||||
      o Corrected fix for CVE-2013-0169
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1c and OpenSSL 1.0.1d [4 Feb 2013]:
 | 
			
		||||
 | 
			
		||||
      o Fix renegotiation in TLS 1.1, 1.2 by using the correct TLS version.
 | 
			
		||||
      o Include the fips configuration module.
 | 
			
		||||
      o Fix OCSP bad key DoS attack CVE-2013-0166
 | 
			
		||||
      o Fix for SSL/TLS/DTLS CBC plaintext recovery attack CVE-2013-0169
 | 
			
		||||
      o Fix for TLS AESNI record handling flaw CVE-2012-2686
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1b and OpenSSL 1.0.1c [10 May 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix TLS/DTLS record length checking bug CVE-2012-2333
 | 
			
		||||
      o Don't attempt to use non-FIPS composite ciphers in FIPS mode.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1a and OpenSSL 1.0.1b [26 Apr 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix compilation error on non-x86 platforms.
 | 
			
		||||
      o Make FIPS capable OpenSSL ciphers work in non-FIPS mode.
 | 
			
		||||
      o Fix SSL_OP_NO_TLSv1_1 clash with SSL_OP_ALL in OpenSSL 1.0.0
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.1 and OpenSSL 1.0.1a [19 Apr 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix for ASN1 overflow bug CVE-2012-2110
 | 
			
		||||
      o Workarounds for some servers that hang on long client hellos.
 | 
			
		||||
      o Fix SEGV in AES code.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0h and OpenSSL 1.0.1 [14 Mar 2012]:
 | 
			
		||||
 | 
			
		||||
      o TLS/DTLS heartbeat support.
 | 
			
		||||
      o SCTP support.
 | 
			
		||||
      o RFC 5705 TLS key material exporter.
 | 
			
		||||
      o RFC 5764 DTLS-SRTP negotiation.
 | 
			
		||||
      o Next Protocol Negotiation.
 | 
			
		||||
      o PSS signatures in certificates, requests and CRLs.
 | 
			
		||||
      o Support for password based recipient info for CMS.
 | 
			
		||||
      o Support TLS v1.2 and TLS v1.1.
 | 
			
		||||
      o Preliminary FIPS capability for unvalidated 2.0 FIPS module.
 | 
			
		||||
      o SRP support.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0k and OpenSSL 1.0.0l [6 Jan 2014]
 | 
			
		||||
 | 
			
		||||
      o Fix for DTLS retransmission bug CVE-2013-6450
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0j and OpenSSL 1.0.0k [5 Feb 2013]:
 | 
			
		||||
 | 
			
		||||
      o Fix for SSL/TLS/DTLS CBC plaintext recovery attack CVE-2013-0169
 | 
			
		||||
      o Fix OCSP bad key DoS attack CVE-2013-0166
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0i and OpenSSL 1.0.0j [10 May 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix DTLS record length checking bug CVE-2012-2333
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0h and OpenSSL 1.0.0i [19 Apr 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix for ASN1 overflow bug CVE-2012-2110
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0g and OpenSSL 1.0.0h [12 Mar 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix for CMS/PKCS#7 MMA CVE-2012-0884
 | 
			
		||||
      o Corrected fix for CVE-2011-4619
 | 
			
		||||
      o Various DTLS fixes.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0f and OpenSSL 1.0.0g [18 Jan 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix for DTLS DoS issue CVE-2012-0050
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0e and OpenSSL 1.0.0f [4 Jan 2012]:
 | 
			
		||||
 | 
			
		||||
      o Fix for DTLS plaintext recovery attack CVE-2011-4108
 | 
			
		||||
      o Clear block padding bytes of SSL 3.0 records CVE-2011-4576
 | 
			
		||||
      o Only allow one SGC handshake restart for SSL/TLS CVE-2011-4619
 | 
			
		||||
      o Check parameters are not NULL in GOST ENGINE CVE-2012-0027
 | 
			
		||||
      o Check for malformed RFC3779 data CVE-2011-4577
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0d and OpenSSL 1.0.0e [6 Sep 2011]:
 | 
			
		||||
 | 
			
		||||
      o Fix for CRL vulnerability issue CVE-2011-3207
 | 
			
		||||
      o Fix for ECDH crashes CVE-2011-3210
 | 
			
		||||
      o Protection against EC timing attacks.
 | 
			
		||||
      o Support ECDH ciphersuites for certificates using SHA2 algorithms.
 | 
			
		||||
      o Various DTLS fixes.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0c and OpenSSL 1.0.0d [8 Feb 2011]:
 | 
			
		||||
 | 
			
		||||
      o Fix for security issue CVE-2011-0014
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0b and OpenSSL 1.0.0c [2 Dec 2010]:
 | 
			
		||||
 | 
			
		||||
      o Fix for security issue CVE-2010-4180
 | 
			
		||||
      o Fix for CVE-2010-4252
 | 
			
		||||
      o Fix mishandling of absent EC point format extension.
 | 
			
		||||
      o Fix various platform compilation issues.
 | 
			
		||||
      o Corrected fix for security issue CVE-2010-3864.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0a and OpenSSL 1.0.0b [16 Nov 2010]:
 | 
			
		||||
 | 
			
		||||
      o Fix for security issue CVE-2010-3864.
 | 
			
		||||
      o Fix for CVE-2010-2939
 | 
			
		||||
      o Fix WIN32 build system for GOST ENGINE.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 1.0.0 and OpenSSL 1.0.0a [1 Jun 2010]:
 | 
			
		||||
 | 
			
		||||
      o Fix for security issue CVE-2010-1633.
 | 
			
		||||
      o GOST MAC and CFB fixes.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 0.9.8n and OpenSSL 1.0.0 [29 Mar 2010]:
 | 
			
		||||
 | 
			
		||||
      o RFC3280 path validation: sufficient to process PKITS tests.
 | 
			
		||||
      o Integrated support for PVK files and keyblobs.
 | 
			
		||||
      o Change default private key format to PKCS#8.
 | 
			
		||||
      o CMS support: able to process all examples in RFC4134
 | 
			
		||||
      o Streaming ASN1 encode support for PKCS#7 and CMS.
 | 
			
		||||
      o Multiple signer and signer add support for PKCS#7 and CMS.
 | 
			
		||||
      o ASN1 printing support.
 | 
			
		||||
      o Whirlpool hash algorithm added.
 | 
			
		||||
      o RFC3161 time stamp support.
 | 
			
		||||
      o New generalised public key API supporting ENGINE based algorithms.
 | 
			
		||||
      o New generalised public key API utilities.
 | 
			
		||||
      o New ENGINE supporting GOST algorithms.
 | 
			
		||||
      o SSL/TLS GOST ciphersuite support.
 | 
			
		||||
      o PKCS#7 and CMS GOST support.
 | 
			
		||||
      o RFC4279 PSK ciphersuite support.
 | 
			
		||||
      o Supported points format extension for ECC ciphersuites.
 | 
			
		||||
      o ecdsa-with-SHA224/256/384/512 signature types.
 | 
			
		||||
      o dsa-with-SHA224 and dsa-with-SHA256 signature types.
 | 
			
		||||
      o Opaque PRF Input TLS extension support.
 | 
			
		||||
      o Updated time routines to avoid OS limitations.
 | 
			
		||||
      o Compilation failure of s3_pkt.c on some platforms due to missing
 | 
			
		||||
        <limits.h> include. Fixed in 0.9.8zb-dev.
 | 
			
		||||
      o FIPS capable link failure with missing symbol BN_consttime_swap.
 | 
			
		||||
        Fixed in 0.9.8zb-dev. Workaround is to compile with no-ec: the EC
 | 
			
		||||
        algorithms are not FIPS approved in OpenSSL 0.9.8 anyway.
 | 
			
		||||
 | 
			
		||||
  Major changes between OpenSSL 0.9.8y and OpenSSL 0.9.8za [5 Jun 2014]:
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
@@ -159,8 +159,6 @@ cd ..\..\..
 | 
			
		||||
echo SHA1
 | 
			
		||||
cd crypto\sha\asm
 | 
			
		||||
perl sha1-586.pl %ASM_MODE% > s1-nw.asm
 | 
			
		||||
perl sha256-586.pl %ASM_MODE% > sha256-nw.asm
 | 
			
		||||
perl sha512-586.pl %ASM_MODE% > sha512-nw.asm
 | 
			
		||||
cd ..\..\..
 | 
			
		||||
 | 
			
		||||
echo RIPEMD160
 | 
			
		||||
@@ -173,11 +171,6 @@ cd crypto\rc5\asm
 | 
			
		||||
perl rc5-586.pl %ASM_MODE% > r5-nw.asm
 | 
			
		||||
cd ..\..\..
 | 
			
		||||
 | 
			
		||||
echo WHIRLPOOL
 | 
			
		||||
cd crypto\whrlpool\asm
 | 
			
		||||
perl wp-mmx.pl %ASM_MODE% > wp-nw.asm
 | 
			
		||||
cd ..\..\..
 | 
			
		||||
 | 
			
		||||
echo CPUID
 | 
			
		||||
cd crypto
 | 
			
		||||
perl x86cpuid.pl %ASM_MODE% > x86cpuid-nw.asm
 | 
			
		||||
 
 | 
			
		||||
@@ -270,6 +270,22 @@ sub ssl_tests
 | 
			
		||||
   print( OUT "\n========================================================\n");
 | 
			
		||||
   print( OUT "SSL TESTS:\n\n");
 | 
			
		||||
 | 
			
		||||
   system("ssltest -ssl2 (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2:");
 | 
			
		||||
   log_output("ssltest -ssl2", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("$ssltest -ssl2 -server_auth (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2 with server authentication:");
 | 
			
		||||
   log_output("$ssltest -ssl2 -server_auth", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("$ssltest -ssl2 -client_auth (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2 with client authentication:");
 | 
			
		||||
   log_output("$ssltest -ssl2 -client_auth", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("$ssltest -ssl2 -server_auth -client_auth (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2 with both client and server authentication:");
 | 
			
		||||
   log_output("$ssltest -ssl2 -server_auth -client_auth", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("ssltest -ssl3 (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv3:");
 | 
			
		||||
   log_output("ssltest -ssl3", $outFile);
 | 
			
		||||
@@ -302,10 +318,26 @@ sub ssl_tests
 | 
			
		||||
   log_desc("Testing sslv2/sslv3 with both client and server authentication:");
 | 
			
		||||
   log_output("$ssltest -server_auth -client_auth", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("ssltest -bio_pair -ssl2 (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2 via BIO pair:");
 | 
			
		||||
   log_output("ssltest -bio_pair -ssl2", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("ssltest -bio_pair -dhe1024dsa -v (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2/sslv3 with 1024 bit DHE via BIO pair:");
 | 
			
		||||
   log_output("ssltest -bio_pair -dhe1024dsa -v", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("$ssltest -bio_pair -ssl2 -server_auth (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2 with server authentication via BIO pair:");
 | 
			
		||||
   log_output("$ssltest -bio_pair -ssl2 -server_auth", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("$ssltest -bio_pair -ssl2 -client_auth (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2 with client authentication via BIO pair:");
 | 
			
		||||
   log_output("$ssltest -bio_pair -ssl2 -client_auth", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("$ssltest -bio_pair -ssl2 -server_auth -client_auth (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv2 with both client and server authentication via BIO pair:");
 | 
			
		||||
   log_output("$ssltest -bio_pair -ssl2 -server_auth -client_auth", $outFile);
 | 
			
		||||
 | 
			
		||||
   system("ssltest -bio_pair -ssl3 (CLIB_OPT)/>$outFile");
 | 
			
		||||
   log_desc("Testing sslv3 via BIO pair:");
 | 
			
		||||
   log_output("ssltest -bio_pair -ssl3", $outFile);
 | 
			
		||||
 
 | 
			
		||||
@@ -66,7 +66,7 @@ static LHASH *error_hash=NULL;
 | 
			
		||||
static LHASH *thread_hash=NULL;
 | 
			
		||||
 | 
			
		||||
several files have routines with static "init" to track if error strings
 | 
			
		||||
   have been loaded ( may not want separate error strings for each process )
 | 
			
		||||
   have been loaded ( may not want seperate error strings for each process )
 | 
			
		||||
   The "init" variable can't be left "global" because the error has is a ptr
 | 
			
		||||
   that is malloc'ed.  The malloc'ed error has is dependant on the "init"
 | 
			
		||||
   vars.
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										14
									
								
								PROBLEMS
									
									
									
									
									
								
							
							
						
						
									
										14
									
								
								PROBLEMS
									
									
									
									
									
								
							@@ -197,17 +197,3 @@ reconfigure with additional no-sse2 [or 386] option passed to ./config.
 | 
			
		||||
We don't have framework to associate -ldl with no-dso, therefore the only
 | 
			
		||||
way is to edit Makefile right after ./config no-dso and remove -ldl from
 | 
			
		||||
EX_LIBS line.
 | 
			
		||||
 | 
			
		||||
* hpux-parisc2-cc no-asm build fails with SEGV in ECDSA/DH.
 | 
			
		||||
 | 
			
		||||
Compiler bug, presumably at particular patch level. Remaining
 | 
			
		||||
hpux*-parisc*-cc configurations can be affected too. Drop optimization
 | 
			
		||||
level to +O2 when compiling bn_nist.o.
 | 
			
		||||
 | 
			
		||||
* solaris64-sparcv9-cc link failure
 | 
			
		||||
 | 
			
		||||
Solaris 8 ar can fail to maintain symbol table in .a, which results in
 | 
			
		||||
link failures. Apply 109147-09 or later or modify Makefile generated
 | 
			
		||||
by ./Configure solaris64-sparcv9-cc and replace RANLIB assignment with
 | 
			
		||||
 | 
			
		||||
	RANLIB= /usr/ccs/bin/ar rs
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										40
									
								
								README
									
									
									
									
									
								
							
							
						
						
									
										40
									
								
								README
									
									
									
									
									
								
							@@ -1,5 +1,5 @@
 | 
			
		||||
 | 
			
		||||
 OpenSSL 1.1.0-dev
 | 
			
		||||
 OpenSSL 0.9.8zg 11 Jun 2015
 | 
			
		||||
 | 
			
		||||
 Copyright (c) 1998-2011 The OpenSSL Project
 | 
			
		||||
 Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson
 | 
			
		||||
@@ -90,6 +90,32 @@
 | 
			
		||||
        SSL/TLS Client and Server Tests
 | 
			
		||||
        Handling of S/MIME signed or encrypted mail
 | 
			
		||||
 | 
			
		||||
 | 
			
		||||
 PATENTS
 | 
			
		||||
 -------
 | 
			
		||||
 | 
			
		||||
 Various companies hold various patents for various algorithms in various
 | 
			
		||||
 locations around the world. _YOU_ are responsible for ensuring that your use
 | 
			
		||||
 of any algorithms is legal by checking if there are any patents in your
 | 
			
		||||
 country.  The file contains some of the patents that we know about or are
 | 
			
		||||
 rumored to exist. This is not a definitive list.
 | 
			
		||||
 | 
			
		||||
 RSA Security holds software patents on the RC5 algorithm.  If you
 | 
			
		||||
 intend to use this cipher, you must contact RSA Security for
 | 
			
		||||
 licensing conditions. Their web page is http://www.rsasecurity.com/.
 | 
			
		||||
 | 
			
		||||
 RC4 is a trademark of RSA Security, so use of this label should perhaps
 | 
			
		||||
 only be used with RSA Security's permission.
 | 
			
		||||
 | 
			
		||||
 The IDEA algorithm is patented by Ascom in Austria, France, Germany, Italy,
 | 
			
		||||
 Japan, the Netherlands, Spain, Sweden, Switzerland, UK and the USA.  They
 | 
			
		||||
 should be contacted if that algorithm is to be used; their web page is
 | 
			
		||||
 http://www.ascom.ch/.
 | 
			
		||||
 | 
			
		||||
 NTT and Mitsubishi have patents and pending patents on the Camellia
 | 
			
		||||
 algorithm, but allow use at no charge without requiring an explicit
 | 
			
		||||
 licensing agreement: http://info.isl.ntt.co.jp/crypt/eng/info/chiteki.html
 | 
			
		||||
 | 
			
		||||
 INSTALLATION
 | 
			
		||||
 ------------
 | 
			
		||||
 | 
			
		||||
@@ -135,7 +161,8 @@
 | 
			
		||||
    - Problem Description (steps that will reproduce the problem, if known)
 | 
			
		||||
    - Stack Traceback (if the application dumps core)
 | 
			
		||||
 | 
			
		||||
 Email the report to:
 | 
			
		||||
 Report the bug to the OpenSSL project via the Request Tracker
 | 
			
		||||
 (http://www.openssl.org/support/rt.html) by mail to:
 | 
			
		||||
 | 
			
		||||
    openssl-bugs@openssl.org
 | 
			
		||||
 | 
			
		||||
@@ -143,11 +170,10 @@
 | 
			
		||||
 or support queries. Just because something doesn't work the way you expect
 | 
			
		||||
 does not mean it is necessarily a bug in OpenSSL.
 | 
			
		||||
 | 
			
		||||
 Note that mail to openssl-bugs@openssl.org is recorded in the public
 | 
			
		||||
 request tracker database (see https://www.openssl.org/support/rt.html
 | 
			
		||||
 for details) and also forwarded to a public mailing list. Confidential
 | 
			
		||||
 mail may be sent to openssl-security@openssl.org (PGP key available from
 | 
			
		||||
 the key servers).
 | 
			
		||||
 Note that mail to openssl-bugs@openssl.org is recorded in the publicly
 | 
			
		||||
 readable request tracker database and is forwarded to a public
 | 
			
		||||
 mailing list. Confidential mail may be sent to openssl-security@openssl.org
 | 
			
		||||
 (PGP key available from the key servers).
 | 
			
		||||
 | 
			
		||||
 HOW TO CONTRIBUTE TO OpenSSL
 | 
			
		||||
 ----------------------------
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										61
									
								
								README.ECC
									
									
									
									
									
								
							
							
						
						
									
										61
									
								
								README.ECC
									
									
									
									
									
								
							@@ -1,61 +0,0 @@
 | 
			
		||||
NOTE: The OpenSSL Software Foundation has executed a sublicense agreement
 | 
			
		||||
entitled "Elliptic Curve Cryptography Patent License Agreement" with the
 | 
			
		||||
National Security Agency/ Central Security Service Commercial Solutions
 | 
			
		||||
Center (NCSC) dated 2010-11-04. That agreement permits implementation and
 | 
			
		||||
distribution of software containing features covered by any or all of the
 | 
			
		||||
following patents:
 | 
			
		||||
 | 
			
		||||
1.) U.S. Pat. No. 5,761,305 entitled "Key Agreement and Transport Protocol 
 | 
			
		||||
    with Implicit Signatures" issued on June 2, 1998;
 | 
			
		||||
2.) Can. Pat. Appl. Ser. No. 2176972 entitled "Key Agreement and Transport 
 | 
			
		||||
    Protocol with Implicit Signature and Reduced Bandwidth" filed on May 
 | 
			
		||||
    16, 1996;
 | 
			
		||||
3.) U.S. Pat. No. 5,889,865 entitled "Key Agreement and Transport Protocol 
 | 
			
		||||
    with Implicit Signatures" issued on March 30, 1999;
 | 
			
		||||
4.) U.S. Pat. No. 5,896,455 entitled "Key Agreement and Transport Protocol 
 | 
			
		||||
    with Implicit Signatures" issued on April 20, 1999;
 | 
			
		||||
5.) U.S. Pat. No. 5,933,504 entitled "Strengthened Public Key Protocol" 
 | 
			
		||||
    issued on August 3, 1999;
 | 
			
		||||
6.) Can. Pat. Appl. Ser. No. 2176866 entitled "Strengthened Public Key 
 | 
			
		||||
    Protocol" filed on May 17, 1996;
 | 
			
		||||
7.) E.P. Pat. Appl. Ser. No. 96201322.3 entitled "Strengthened Public Key 
 | 
			
		||||
    Protocol" filed on May 17, 1996;
 | 
			
		||||
8.) U.S. Pat. No. 5,999,626 entitled "Digital Signatures on a Smartcard" 
 | 
			
		||||
    issued on December 7, 1999;
 | 
			
		||||
9.) Can. Pat. Appl. Ser. No. 2202566 entitled "Digital Signatures on a 
 | 
			
		||||
    Smartcard" filed on April 14, 1997;
 | 
			
		||||
10.) E.P. Pat. Appl. No. 97106114.8 entitled "Digital Signatures on a 
 | 
			
		||||
     Smartcard" filed on April 15, 1997;
 | 
			
		||||
11.) U.S Pat. No. 6,122,736 entitled "Key Agreement and Transport Protocol 
 | 
			
		||||
     with Implicit Signatures" issued on September 19, 2000;
 | 
			
		||||
12.) Can. Pat. Appl. Ser. No. 2174261 entitled "Key Agreement and Transport 
 | 
			
		||||
     Protocol with Implicit Signatures" filed on April 16, 1996;
 | 
			
		||||
13.) E.P. Pat. Appl. Ser. No. 96105920.1 entitled "Key Agreement and 
 | 
			
		||||
     Transport Protocol with Implicit Signatures" filed on April 16, 1996;
 | 
			
		||||
14.) U.S. Pat. No. 6,141,420 entitled "Elliptic Curve Encryption Systems" 
 | 
			
		||||
     issued on October 31, 2000;
 | 
			
		||||
15.) Can. Pat. Appl. Ser. No. 2155038 entitled "Elliptic Curve Encryption 
 | 
			
		||||
     Systems" filed on July 31, 1995;
 | 
			
		||||
16.) E.P. Pat. Appl. Ser. No. 95926348.4 entitled "Elliptic Curve Encryption 
 | 
			
		||||
     Systems" filed on July 31, 1995;
 | 
			
		||||
17.) U.S. Pat. No. 6,336,188 entitled "Authenticated Key Agreement" issued 
 | 
			
		||||
     on January 1, 2002;
 | 
			
		||||
18.) U.S. Pat. No. 6,487,661 entitled "Key Agreement and Transport Protocol" 
 | 
			
		||||
     issued on November 26, 2002;
 | 
			
		||||
19.) Can. Pat. Appl. Ser. No. 2174260 entitled "Key Agreement and Transport 
 | 
			
		||||
     Protocol" filed on April 16, 1996;
 | 
			
		||||
20.) E.P. Pat. Appl. Ser. No. 96105921.9 entitled "Key Agreement and 
 | 
			
		||||
     Transport Protocol" filed on April 21, 1996;
 | 
			
		||||
21.) U.S. Pat. No. 6,563,928 entitled "Strengthened Public Key Protocol" 
 | 
			
		||||
     issued on May 13, 2003;
 | 
			
		||||
22.) U.S. Pat. No. 6,618,483 entitled "Elliptic Curve Encryption Systems" 
 | 
			
		||||
     issued September 9, 2003;
 | 
			
		||||
23.) U.S. Pat. Appl. Ser. No. 09/434,247 entitled "Digital Signatures on a 
 | 
			
		||||
     Smartcard" filed on November 5, 1999;
 | 
			
		||||
24.) U.S. Pat. Appl. Ser. No. 09/558,256 entitled "Key Agreement and 
 | 
			
		||||
     Transport Protocol with Implicit Signatures" filed on April 25, 2000;
 | 
			
		||||
25.) U.S. Pat. Appl. Ser. No. 09/942,492 entitled "Digital Signatures on a 
 | 
			
		||||
     Smartcard" filed on August 29, 2001 and published on July 18, 2002; and,
 | 
			
		||||
26.) U.S. Pat. Appl. Ser. No. 10/185,735 entitled "Strengthened Public Key 
 | 
			
		||||
     Protocol" filed on July 1, 2000.
 | 
			
		||||
 | 
			
		||||
							
								
								
									
										130
									
								
								README.FIPS
									
									
									
									
									
								
							
							
						
						
									
										130
									
								
								README.FIPS
									
									
									
									
									
								
							@@ -1,130 +0,0 @@
 | 
			
		||||
Preliminary status and build information for FIPS module v2.0
 | 
			
		||||
 | 
			
		||||
NB: if you are cross compiling you now need to use the latest "incore" script
 | 
			
		||||
this can be found at util/incore in the tarballs.
 | 
			
		||||
 | 
			
		||||
If you have any object files from a previous build do:
 | 
			
		||||
 | 
			
		||||
make clean
 | 
			
		||||
 | 
			
		||||
To build the module do:
 | 
			
		||||
 | 
			
		||||
./config fipscanisteronly
 | 
			
		||||
make
 | 
			
		||||
 | 
			
		||||
Build should complete without errors.
 | 
			
		||||
 | 
			
		||||
Build test utilities:
 | 
			
		||||
 | 
			
		||||
make build_tests
 | 
			
		||||
 | 
			
		||||
Run test suite:
 | 
			
		||||
 | 
			
		||||
test/fips_test_suite
 | 
			
		||||
 | 
			
		||||
again should complete without errors.
 | 
			
		||||
 | 
			
		||||
Run test vectors: 
 | 
			
		||||
 | 
			
		||||
1. Download an appropriate set of testvectors from www.openssl.org/docs/fips
 | 
			
		||||
   only the fips-2.0 testvector files are usable for complete tests.
 | 
			
		||||
 | 
			
		||||
2. Extract the files to a suitable directory.
 | 
			
		||||
 | 
			
		||||
3. Run the test vector perl script, for example:
 | 
			
		||||
 | 
			
		||||
   cd fips
 | 
			
		||||
   perl fipsalgtest.pl --dir=/wherever/stuff/was/extracted
 | 
			
		||||
 | 
			
		||||
4. It should say "passed all tests" at the end. Report full details of any
 | 
			
		||||
   failures.
 | 
			
		||||
 | 
			
		||||
If you wish to use the older 1.2.x testvectors (for example those from 2007)
 | 
			
		||||
you need the command line switch --disable-v2 to fipsalgtest.pl
 | 
			
		||||
 | 
			
		||||
Examine the external symbols in fips/fipscanister.o they should all begin
 | 
			
		||||
with FIPS or fips. One way to check with GNU nm is:
 | 
			
		||||
 | 
			
		||||
	nm -g --defined-only fips/fipscanister.o | grep -v -i fips
 | 
			
		||||
 | 
			
		||||
If you get *any* output at all from this test (i.e. symbols not starting with
 | 
			
		||||
fips or FIPS) please report it.
 | 
			
		||||
 | 
			
		||||
Restricted tarball tests.
 | 
			
		||||
 | 
			
		||||
The validated module will have its own tarball containing sufficient code to
 | 
			
		||||
build fipscanister.o and the associated algorithm tests. You can create a
 | 
			
		||||
similar tarball yourself for testing purposes using the commands below.
 | 
			
		||||
 | 
			
		||||
Standard restricted tarball:
 | 
			
		||||
 | 
			
		||||
make -f Makefile.fips dist
 | 
			
		||||
 | 
			
		||||
Prime field field only ECC tarball:
 | 
			
		||||
 | 
			
		||||
make NOEC2M=1 -f Makefile.fips dist
 | 
			
		||||
 | 
			
		||||
Once you've created the tarball extract into a fresh directory and do:
 | 
			
		||||
 | 
			
		||||
./config
 | 
			
		||||
make
 | 
			
		||||
 | 
			
		||||
You can then run the algorithm tests as above. This build automatically uses
 | 
			
		||||
fipscanisterbuild and no-ec2m as appropriate.
 | 
			
		||||
 | 
			
		||||
FIPS capable OpenSSL test: WARNING PRELIMINARY INSTRUCTIONS, SUBJECT TO CHANGE.
 | 
			
		||||
 | 
			
		||||
At least initially the test module and FIPS capable OpenSSL may change and
 | 
			
		||||
by out of sync. You are advised to check for any changes and pull the latest
 | 
			
		||||
source from CVS if you have problems. See anon CVS and rsync instructions at:
 | 
			
		||||
 | 
			
		||||
http://www.openssl.org/source/repos.html
 | 
			
		||||
 | 
			
		||||
Make or download a restricted tarball from ftp://ftp.openssl.org/snapshot/
 | 
			
		||||
 | 
			
		||||
If required set the environment variable FIPSDIR to an appropriate location
 | 
			
		||||
to install the test module. If cross compiling set other environment
 | 
			
		||||
variables too.
 | 
			
		||||
 | 
			
		||||
In this restricted tarball on a Linux or U*ix like system run:
 | 
			
		||||
 | 
			
		||||
./config
 | 
			
		||||
make
 | 
			
		||||
make install
 | 
			
		||||
 | 
			
		||||
On Windows from a VC++ environment do:
 | 
			
		||||
 | 
			
		||||
ms\do_fips
 | 
			
		||||
 | 
			
		||||
This will build and install the test module and some associated files.
 | 
			
		||||
 | 
			
		||||
Now download the latest version of the OpenSSL 1.0.1 branch from either a
 | 
			
		||||
snapshot or preferably CVS. For Linux do:
 | 
			
		||||
 | 
			
		||||
./config fips [other args]
 | 
			
		||||
make
 | 
			
		||||
 | 
			
		||||
For Windows:
 | 
			
		||||
 | 
			
		||||
perl Configure VC-WIN32 fips [other args]
 | 
			
		||||
ms\do_nasm
 | 
			
		||||
nmake -f ms\ntdll.mak
 | 
			
		||||
 | 
			
		||||
(or ms\nt.mak for a static build).
 | 
			
		||||
 | 
			
		||||
Where [other args] can be any other arguments you use for an OpenSSL build
 | 
			
		||||
such as "shared" or "zlib".
 | 
			
		||||
 | 
			
		||||
This will build the fips capable OpenSSL and link it to the test module. You
 | 
			
		||||
can now try linking and testing applications against the FIPS capable OpenSSL.
 | 
			
		||||
 | 
			
		||||
Please report any problems to either the openssl-dev mailing list or directly
 | 
			
		||||
to me steve@openssl.org . Check the mailing lists regularly to avoid duplicate
 | 
			
		||||
reports.
 | 
			
		||||
 | 
			
		||||
Known issues:
 | 
			
		||||
 | 
			
		||||
Code needs extensively reviewing to ensure it builds correctly on 
 | 
			
		||||
supported platforms and is compliant with FIPS 140-2.
 | 
			
		||||
The "FIPS capable OpenSSL" is still largely untested, it builds and runs
 | 
			
		||||
some simple tests OK on some systems but needs far more "real world" testing.
 | 
			
		||||
@@ -1,67 +0,0 @@
 | 
			
		||||
$! install-vms.com -- Installs the files in a given directory tree
 | 
			
		||||
$!
 | 
			
		||||
$! Author: Richard Levitte <richard@levitte.org>
 | 
			
		||||
$! Time of creation: 23-MAY-1998 19:22
 | 
			
		||||
$!
 | 
			
		||||
$! P1	root of the directory tree
 | 
			
		||||
$!
 | 
			
		||||
$!
 | 
			
		||||
$! Announce/identify.
 | 
			
		||||
$!
 | 
			
		||||
$ proc = f$environment( "procedure")
 | 
			
		||||
$ write sys$output "@@@ "+ -
 | 
			
		||||
   f$parse( proc, , , "name")+ f$parse( proc, , , "type")
 | 
			
		||||
$!
 | 
			
		||||
$ on error then goto tidy
 | 
			
		||||
$ on control_c then goto tidy
 | 
			
		||||
$!
 | 
			
		||||
$ if p1 .eqs. ""
 | 
			
		||||
$ then
 | 
			
		||||
$   write sys$output "First argument missing."
 | 
			
		||||
$   write sys$output -
 | 
			
		||||
     "Should be the directory where you want things installed."
 | 
			
		||||
$   exit
 | 
			
		||||
$ endif
 | 
			
		||||
$
 | 
			
		||||
$ if (f$getsyi( "cpu") .lt. 128)
 | 
			
		||||
$ then
 | 
			
		||||
$   arch = "VAX"
 | 
			
		||||
$ else
 | 
			
		||||
$   arch = f$edit( f$getsyi( "arch_name"), "upcase")
 | 
			
		||||
$   if (arch .eqs. "") then arch = "UNK"
 | 
			
		||||
$ endif
 | 
			
		||||
$
 | 
			
		||||
$ root = f$parse( P1, "[]A.;0", , , "SYNTAX_ONLY, NO_CONCEAL")- "A.;0"
 | 
			
		||||
$ root_dev = f$parse( root, , , "device", "syntax_only")
 | 
			
		||||
$ root_dir = f$parse( root, , , "directory", "syntax_only") - -
 | 
			
		||||
   "[000000." - "][" - "[" - "]"
 | 
			
		||||
$ root = root_dev + "[" + root_dir
 | 
			
		||||
$
 | 
			
		||||
$ define /nolog wrk_sslroot 'root'.] /translation_attributes = concealed
 | 
			
		||||
$ define /nolog wrk_sslinclude wrk_sslroot:[include]
 | 
			
		||||
$
 | 
			
		||||
$ if f$parse( "wrk_sslroot:[000000]") .eqs. "" then -
 | 
			
		||||
   create /directory /log wrk_sslroot:[000000]
 | 
			
		||||
$ if f$parse( "wrk_sslinclude:") .eqs. "" then -
 | 
			
		||||
   create /directory /log wrk_sslinclude:
 | 
			
		||||
$ if f$parse( "wrk_sslroot:[vms]") .eqs. "" then -
 | 
			
		||||
   create /directory /log wrk_sslroot:[vms]
 | 
			
		||||
$!
 | 
			
		||||
$ copy /log /protection = world:re openssl_startup.com wrk_sslroot:[vms]
 | 
			
		||||
$ copy /log /protection = world:re openssl_undo.com wrk_sslroot:[vms]
 | 
			
		||||
$ copy /log /protection = world:re openssl_utils.com wrk_sslroot:[vms]
 | 
			
		||||
$!
 | 
			
		||||
$ tidy:
 | 
			
		||||
$!
 | 
			
		||||
$ call deass wrk_sslroot
 | 
			
		||||
$ call deass wrk_sslinclude
 | 
			
		||||
$!
 | 
			
		||||
$ exit
 | 
			
		||||
$!
 | 
			
		||||
$ deass: subroutine
 | 
			
		||||
$ if (f$trnlnm( p1, "LNM$PROCESS") .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$   deassign /process 'p1'
 | 
			
		||||
$ endif
 | 
			
		||||
$ endsubroutine
 | 
			
		||||
$!
 | 
			
		||||
							
								
								
									
										79
									
								
								VMS/install.com
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										79
									
								
								VMS/install.com
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,79 @@
 | 
			
		||||
$! INSTALL.COM -- Installs the files in a given directory tree
 | 
			
		||||
$!
 | 
			
		||||
$! Author: Richard Levitte <richard@levitte.org>
 | 
			
		||||
$! Time of creation: 23-MAY-1998 19:22
 | 
			
		||||
$!
 | 
			
		||||
$! P1	root of the directory tree
 | 
			
		||||
$!
 | 
			
		||||
$	IF P1 .EQS. ""
 | 
			
		||||
$	THEN
 | 
			
		||||
$	    WRITE SYS$OUTPUT "First argument missing."
 | 
			
		||||
$	    WRITE SYS$OUTPUT "Should be the directory where you want things installed."
 | 
			
		||||
$	    EXIT
 | 
			
		||||
$	ENDIF
 | 
			
		||||
$
 | 
			
		||||
$	IF (F$GETSYI("CPU").LT.128)
 | 
			
		||||
$	THEN
 | 
			
		||||
$	    ARCH := VAX
 | 
			
		||||
$	ELSE
 | 
			
		||||
$	    ARCH = F$EDIT( F$GETSYI( "ARCH_NAME"), "UPCASE")
 | 
			
		||||
$	    IF (ARCH .EQS. "") THEN ARCH = "UNK"
 | 
			
		||||
$	ENDIF
 | 
			
		||||
$
 | 
			
		||||
$	ROOT = F$PARSE(P1,"[]A.;0",,,"SYNTAX_ONLY,NO_CONCEAL") - "A.;0"
 | 
			
		||||
$	ROOT_DEV = F$PARSE(ROOT,,,"DEVICE","SYNTAX_ONLY")
 | 
			
		||||
$	ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
 | 
			
		||||
		   - "[000000." - "][" - "[" - "]"
 | 
			
		||||
$	ROOT = ROOT_DEV + "[" + ROOT_DIR
 | 
			
		||||
$
 | 
			
		||||
$	DEFINE/NOLOG WRK_SSLROOT 'ROOT'.] /TRANS=CONC
 | 
			
		||||
$	DEFINE/NOLOG WRK_SSLINCLUDE WRK_SSLROOT:[INCLUDE]
 | 
			
		||||
$
 | 
			
		||||
$	IF F$PARSE("WRK_SSLROOT:[000000]") .EQS. "" THEN -
 | 
			
		||||
	   CREATE/DIR/LOG WRK_SSLROOT:[000000]
 | 
			
		||||
$	IF F$PARSE("WRK_SSLINCLUDE:") .EQS. "" THEN -
 | 
			
		||||
	   CREATE/DIR/LOG WRK_SSLINCLUDE:
 | 
			
		||||
$	IF F$PARSE("WRK_SSLROOT:[VMS]") .EQS. "" THEN -
 | 
			
		||||
	   CREATE/DIR/LOG WRK_SSLROOT:[VMS]
 | 
			
		||||
$
 | 
			
		||||
$	IF F$SEARCH("WRK_SSLINCLUDE:vms_idhacks.h") .NES. "" THEN -
 | 
			
		||||
	   DELETE WRK_SSLINCLUDE:vms_idhacks.h;*
 | 
			
		||||
$
 | 
			
		||||
$	OPEN/WRITE SF WRK_SSLROOT:[VMS]OPENSSL_STARTUP.COM
 | 
			
		||||
$	WRITE SYS$OUTPUT "%OPEN-I-CREATED,  ",F$SEARCH("WRK_SSLROOT:[VMS]OPENSSL_STARTUP.COM")," created."
 | 
			
		||||
$	WRITE SF "$! Startup file for Openssl"
 | 
			
		||||
$	WRITE SF "$!"
 | 
			
		||||
$	WRITE SF "$! Do not edit this file, as it will be regenerated during next installation."
 | 
			
		||||
$	WRITE SF "$! Instead, add or change SSLROOT:[VMS]OPENSSL_SYSTARTUP.COM"
 | 
			
		||||
$	WRITE SF "$!"
 | 
			
		||||
$	WRITE SF "$! P1	a qualifier to DEFINE.  For example ""/SYSTEM"" to get the logical names"
 | 
			
		||||
$	WRITE SF "$!	defined in the system logical name table."
 | 
			
		||||
$	WRITE SF "$!"
 | 
			
		||||
$	WRITE SF "$	IF (F$GETSYI(""CPU"").LT.128)"
 | 
			
		||||
$	WRITE SF "$	THEN"
 | 
			
		||||
$	WRITE SF "$	    ARCH := VAX"
 | 
			
		||||
$	WRITE SF "$	ELSE"
 | 
			
		||||
$	WRITE SF "$	    ARCH = F$EDIT( F$GETSYI( ""ARCH_NAME""), ""UPCASE"")"
 | 
			
		||||
$	WRITE SF "$	    IF (ARCH .EQS. """") THEN ARCH = ""UNK"""
 | 
			
		||||
$	WRITE SF "$	ENDIF"
 | 
			
		||||
$	WRITE SF "$	DEFINE/NOLOG'P1	SSLROOT		",ROOT,".] /TRANS=CONC"
 | 
			
		||||
$	WRITE SF "$	DEFINE/NOLOG'P1	SSLLIB		SSLROOT:['ARCH'_LIB]"
 | 
			
		||||
$	WRITE SF "$	DEFINE/NOLOG'P1	SSLINCLUDE	SSLROOT:[INCLUDE]"
 | 
			
		||||
$	WRITE SF "$	DEFINE/NOLOG'P1	SSLEXE		SSLROOT:['ARCH'_EXE]"
 | 
			
		||||
$	WRITE SF "$	DEFINE/NOLOG'P1	SSLCERTS	SSLROOT:[CERTS]"
 | 
			
		||||
$	WRITE SF "$	DEFINE/NOLOG'P1	SSLPRIVATE	SSLROOT:[PRIVATE]"
 | 
			
		||||
$	WRITE SF "$"
 | 
			
		||||
$	WRITE SF "$!	This is program can include <openssl/{foo}.h>"
 | 
			
		||||
$	WRITE SF "$	DEFINE/NOLOG'P1	OPENSSL		SSLINCLUDE:"
 | 
			
		||||
$	WRITE SF "$"
 | 
			
		||||
$	WRITE SF "$	IF F$SEARCH(""SSLROOT:[VMS]OPENSSL_SYSTARTUP.COM"") .NES."""" THEN -"
 | 
			
		||||
$	WRITE SF "	   @SSLROOT:[VMS]OPENSSL_SYSTARTUP.COM"
 | 
			
		||||
$	WRITE SF "$"
 | 
			
		||||
$	WRITE SF "$	EXIT"
 | 
			
		||||
$	CLOSE SF
 | 
			
		||||
$	SET FILE/PROT=WORLD:RE WRK_SSLROOT:[VMS]OPENSSL_STARTUP.COM
 | 
			
		||||
$
 | 
			
		||||
$	COPY OPENSSL_UTILS.COM WRK_SSLROOT:[VMS]/LOG
 | 
			
		||||
$	SET FILE/PROT=WORLD:RE WRK_SSLROOT:[VMS]OPENSSL_UTILS.COM
 | 
			
		||||
$
 | 
			
		||||
$	EXIT
 | 
			
		||||
							
								
								
									
										229
									
								
								VMS/mkshared.com
									
									
									
									
									
								
							
							
						
						
									
										229
									
								
								VMS/mkshared.com
									
									
									
									
									
								
							@@ -1,166 +1,85 @@
 | 
			
		||||
$! MKSHARED.COM -- Create shareable images.
 | 
			
		||||
$! MKSHARED.COM -- script to created shareable images on VMS
 | 
			
		||||
$!
 | 
			
		||||
$! P1: "64" for 64-bit pointers.
 | 
			
		||||
$! No command line parameters.  This should be run at the start of the source
 | 
			
		||||
$! tree (the same directory where one finds INSTALL.VMS).
 | 
			
		||||
$!
 | 
			
		||||
$! P2: Zlib object library path (optional).
 | 
			
		||||
$!
 | 
			
		||||
$! Input:	[.UTIL]LIBEAY.NUM,[.xxx.EXE.CRYPTO]SSL_LIBCRYPTO[32].OLB
 | 
			
		||||
$!		[.UTIL]SSLEAY.NUM,[.xxx.EXE.SSL]SSL_LIBSSL[32].OLB
 | 
			
		||||
$!		[.CRYPTO.xxx]OPENSSLCONF.H
 | 
			
		||||
$! Output:	[.xxx.EXE.CRYPTO]SSL_LIBCRYPTO_SHR[32].OPT,.MAP,.EXE
 | 
			
		||||
$!		[.xxx.EXE.SSL]SSL_LIBSSL_SRH[32].OPT,.MAP,.EXE
 | 
			
		||||
$! Input:	[.UTIL]LIBEAY.NUM,[.xxx.EXE.CRYPTO]LIBCRYPTO.OLB
 | 
			
		||||
$!		[.UTIL]SSLEAY.NUM,[.xxx.EXE.SSL]LIBSSL.OLB
 | 
			
		||||
$! Output:	[.xxx.EXE.CRYPTO]LIBCRYPTO.OPT,.MAP,.EXE
 | 
			
		||||
$!		[.xxx.EXE.SSL]LIBSSL.OPT,.MAP,.EXE
 | 
			
		||||
$!
 | 
			
		||||
$! So far, tests have only been made on VMS for Alpha.  VAX will come in time.
 | 
			
		||||
$! ===========================================================================
 | 
			
		||||
$!
 | 
			
		||||
$! Announce/identify.
 | 
			
		||||
$!
 | 
			
		||||
$ proc = f$environment( "procedure")
 | 
			
		||||
$ write sys$output "@@@ "+ -
 | 
			
		||||
   f$parse( proc, , , "name")+ f$parse( proc, , , "type")
 | 
			
		||||
$!
 | 
			
		||||
$! Save the original default device:[directory].
 | 
			
		||||
$!
 | 
			
		||||
$ def_orig = f$environment( "default")
 | 
			
		||||
$ on error then goto tidy
 | 
			
		||||
$ on control_c then goto tidy
 | 
			
		||||
$!
 | 
			
		||||
$! SET DEFAULT to the main kit directory.
 | 
			
		||||
$!
 | 
			
		||||
$ proc = f$environment("procedure")
 | 
			
		||||
$ proc = f$parse( "A.;", proc)- "A.;"
 | 
			
		||||
$ set default 'proc'
 | 
			
		||||
$ set default [-]
 | 
			
		||||
$!
 | 
			
		||||
$
 | 
			
		||||
$! ----- Prepare info for processing: version number and file info
 | 
			
		||||
$ gosub read_version_info
 | 
			
		||||
$ if libver .eqs. ""
 | 
			
		||||
$ then
 | 
			
		||||
$   write sys$error "ERROR: Couldn't find any library version info..."
 | 
			
		||||
$   go to tidy:
 | 
			
		||||
$   exit
 | 
			
		||||
$ endif
 | 
			
		||||
$
 | 
			
		||||
$ if (f$getsyi("cpu").lt.128)
 | 
			
		||||
$ then
 | 
			
		||||
$   arch_vax = 1
 | 
			
		||||
$   arch = "VAX"
 | 
			
		||||
$     arch := VAX
 | 
			
		||||
$ else
 | 
			
		||||
$   arch_vax = 0
 | 
			
		||||
$     arch = f$edit( f$getsyi( "ARCH_NAME"), "UPCASE")
 | 
			
		||||
$     if (arch .eqs. "") then arch = "UNK"
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ archd = arch
 | 
			
		||||
$ lib32 = "32"
 | 
			
		||||
$ shr = "SHR32"
 | 
			
		||||
$!
 | 
			
		||||
$ if (p1 .nes. "")
 | 
			
		||||
$
 | 
			
		||||
$ if arch .nes. "VAX"
 | 
			
		||||
$ then
 | 
			
		||||
$   if (p1 .eqs. "64")
 | 
			
		||||
$   then
 | 
			
		||||
$     archd = arch+ "_64"
 | 
			
		||||
$     lib32 = ""
 | 
			
		||||
$     shr = "SHR"
 | 
			
		||||
$   arch_vax = 0
 | 
			
		||||
$   libid  = "Crypto"
 | 
			
		||||
$   libnum = "[.UTIL]LIBEAY.NUM"
 | 
			
		||||
$   libdir = "[.''ARCH'.EXE.CRYPTO]"
 | 
			
		||||
$   libolb = "''libdir'LIBCRYPTO.OLB"
 | 
			
		||||
$   libopt = "''libdir'LIBCRYPTO.OPT"
 | 
			
		||||
$   libmap = "''libdir'LIBCRYPTO.MAP"
 | 
			
		||||
$   libgoal= "''libdir'LIBCRYPTO.EXE"
 | 
			
		||||
$   libref = ""
 | 
			
		||||
$   gosub create_nonvax_shr
 | 
			
		||||
$   libid  = "SSL"
 | 
			
		||||
$   libnum = "[.UTIL]SSLEAY.NUM"
 | 
			
		||||
$   libdir = "[.''ARCH'.EXE.SSL]"
 | 
			
		||||
$   libolb = "''libdir'LIBSSL.OLB"
 | 
			
		||||
$   libopt = "''libdir'LIBSSL.OPT"
 | 
			
		||||
$   libmap = "''libdir'LIBSSL.MAP"
 | 
			
		||||
$   libgoal= "''libdir'LIBSSL.EXE"
 | 
			
		||||
$   libref = "[.''ARCH'.EXE.CRYPTO]LIBCRYPTO.EXE"
 | 
			
		||||
$   gosub create_nonvax_shr
 | 
			
		||||
$ else
 | 
			
		||||
$     if (p1 .nes. "32")
 | 
			
		||||
$     then
 | 
			
		||||
$       write sys$output "Second argument invalid."
 | 
			
		||||
$       write sys$output "It should be "32", "64", or nothing."
 | 
			
		||||
$       exit
 | 
			
		||||
$     endif
 | 
			
		||||
$   endif
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$! ----- Prepare info for processing: disabled algorithms info
 | 
			
		||||
$ gosub read_disabled_algorithms_info
 | 
			
		||||
$!
 | 
			
		||||
$ ZLIB = p2
 | 
			
		||||
$ zlib_lib = ""
 | 
			
		||||
$ if (ZLIB .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$   file2 = f$parse( ZLIB, "libz.olb", , , "syntax_only")
 | 
			
		||||
$   if (f$search( file2) .eqs. "")
 | 
			
		||||
$   then
 | 
			
		||||
$     write sys$output ""
 | 
			
		||||
$     write sys$output "The Option ", ZLIB, " Is Invalid."
 | 
			
		||||
$     write sys$output "    Can't find library: ''file2'"
 | 
			
		||||
$     write sys$output ""
 | 
			
		||||
$     goto tidy
 | 
			
		||||
$   endif
 | 
			
		||||
$   zlib_lib = ", ''file2' /library"
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ if (arch_vax)
 | 
			
		||||
$ then
 | 
			
		||||
$   arch_vax = 1
 | 
			
		||||
$   libtit = "CRYPTO_TRANSFER_VECTOR"
 | 
			
		||||
$   libid  = "Crypto"
 | 
			
		||||
$   libnum = "[.UTIL]LIBEAY.NUM"
 | 
			
		||||
$   libdir = "[.''ARCHD'.EXE.CRYPTO]"
 | 
			
		||||
$   libmar = "''libdir'SSL_LIBCRYPTO_''shr'.MAR"
 | 
			
		||||
$   libolb = "''libdir'SSL_LIBCRYPTO''lib32'.OLB"
 | 
			
		||||
$   libopt = "''libdir'SSL_LIBCRYPTO_''shr'.OPT"
 | 
			
		||||
$   libobj = "''libdir'SSL_LIBCRYPTO_''shr'.OBJ"
 | 
			
		||||
$   libmap = "''libdir'SSL_LIBCRYPTO_''shr'.MAP"
 | 
			
		||||
$   libgoal= "''libdir'SSL_LIBCRYPTO_''shr'.EXE"
 | 
			
		||||
$   libdir = "[.''ARCH'.EXE.CRYPTO]"
 | 
			
		||||
$   libmar = "''libdir'LIBCRYPTO.MAR"
 | 
			
		||||
$   libolb = "''libdir'LIBCRYPTO.OLB"
 | 
			
		||||
$   libopt = "''libdir'LIBCRYPTO.OPT"
 | 
			
		||||
$   libobj = "''libdir'LIBCRYPTO.OBJ"
 | 
			
		||||
$   libmap = "''libdir'LIBCRYPTO.MAP"
 | 
			
		||||
$   libgoal= "''libdir'LIBCRYPTO.EXE"
 | 
			
		||||
$   libref = ""
 | 
			
		||||
$   libvec = "LIBCRYPTO"
 | 
			
		||||
$   if f$search( libolb) .nes. "" then gosub create_vax_shr
 | 
			
		||||
$   gosub create_vax_shr
 | 
			
		||||
$   libtit = "SSL_TRANSFER_VECTOR"
 | 
			
		||||
$   libid  = "SSL"
 | 
			
		||||
$   libnum = "[.UTIL]SSLEAY.NUM"
 | 
			
		||||
$   libdir = "[.''ARCHD'.EXE.SSL]"
 | 
			
		||||
$   libmar = "''libdir'SSL_LIBSSL_''shr'.MAR"
 | 
			
		||||
$   libolb = "''libdir'SSL_LIBSSL''lib32'.OLB"
 | 
			
		||||
$   libopt = "''libdir'SSL_LIBSSL_''shr'.OPT"
 | 
			
		||||
$   libobj = "''libdir'SSL_LIBSSL_''shr'.OBJ"
 | 
			
		||||
$   libmap = "''libdir'SSL_LIBSSL_''shr'.MAP"
 | 
			
		||||
$   libgoal= "''libdir'SSL_LIBSSL_''shr'.EXE"
 | 
			
		||||
$   libref = "[.''ARCHD'.EXE.CRYPTO]SSL_LIBCRYPTO_''shr'.EXE"
 | 
			
		||||
$   libdir = "[.''ARCH'.EXE.SSL]"
 | 
			
		||||
$   libmar = "''libdir'LIBSSL.MAR"
 | 
			
		||||
$   libolb = "''libdir'LIBSSL.OLB"
 | 
			
		||||
$   libopt = "''libdir'LIBSSL.OPT"
 | 
			
		||||
$   libobj = "''libdir'LIBSSL.OBJ"
 | 
			
		||||
$   libmap = "''libdir'LIBSSL.MAP"
 | 
			
		||||
$   libgoal= "''libdir'LIBSSL.EXE"
 | 
			
		||||
$   libref = "[.''ARCH'.EXE.CRYPTO]LIBCRYPTO.EXE"
 | 
			
		||||
$   libvec = "LIBSSL"
 | 
			
		||||
$   if f$search( libolb) .nes. "" then gosub create_vax_shr
 | 
			
		||||
$ else
 | 
			
		||||
$   libid  = "Crypto"
 | 
			
		||||
$   libnum = "[.UTIL]LIBEAY.NUM"
 | 
			
		||||
$   libdir = "[.''ARCHD'.EXE.CRYPTO]"
 | 
			
		||||
$   libolb = "''libdir'SSL_LIBCRYPTO''lib32'.OLB"
 | 
			
		||||
$   libopt = "''libdir'SSL_LIBCRYPTO_''shr'.OPT"
 | 
			
		||||
$   libmap = "''libdir'SSL_LIBCRYPTO_''shr'.MAP"
 | 
			
		||||
$   libgoal= "''libdir'SSL_LIBCRYPTO_''shr'.EXE"
 | 
			
		||||
$   libref = ""
 | 
			
		||||
$   if f$search( libolb) .nes. "" then gosub create_nonvax_shr
 | 
			
		||||
$   libid  = "SSL"
 | 
			
		||||
$   libnum = "[.UTIL]SSLEAY.NUM"
 | 
			
		||||
$   libdir = "[.''ARCHD'.EXE.SSL]"
 | 
			
		||||
$   libolb = "''libdir'SSL_LIBSSL''lib32'.OLB"
 | 
			
		||||
$   libopt = "''libdir'SSL_LIBSSL_''shr'.OPT"
 | 
			
		||||
$   libmap = "''libdir'SSL_LIBSSL_''shr'.MAP"
 | 
			
		||||
$   libgoal= "''libdir'SSL_LIBSSL_''shr'.EXE"
 | 
			
		||||
$   libref = "[.''ARCHD'.EXE.CRYPTO]SSL_LIBCRYPTO_''shr'.EXE"
 | 
			
		||||
$   if f$search( libolb) .nes. "" then gosub create_nonvax_shr
 | 
			
		||||
$   gosub create_vax_shr
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ tidy:
 | 
			
		||||
$!
 | 
			
		||||
$! Close any open files.
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$trnlnm( "libnum", "LNM$PROCESS", 0, "SUPERVISOR") .nes. "") then -
 | 
			
		||||
   close libnum
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$trnlnm( "mar", "LNM$PROCESS", 0, "SUPERVISOR") .nes. "") then -
 | 
			
		||||
   close mar
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$trnlnm( "opt", "LNM$PROCESS", 0, "SUPERVISOR") .nes. "") then -
 | 
			
		||||
   close opt
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$trnlnm( "vf", "LNM$PROCESS", 0, "SUPERVISOR") .nes. "") then -
 | 
			
		||||
   close vf
 | 
			
		||||
$!
 | 
			
		||||
$! Restore the original default device:[directory].
 | 
			
		||||
$!
 | 
			
		||||
$ set default 'def_orig'
 | 
			
		||||
$ exit
 | 
			
		||||
$
 | 
			
		||||
$! ----- Subroutines to build the shareable libraries
 | 
			
		||||
$! ----- Soubroutines to build the shareable libraries
 | 
			
		||||
$! For each supported architecture, there's a main shareable library
 | 
			
		||||
$! creator, which is called from the main code above.
 | 
			
		||||
$! The creator will define a number of variables to tell the next levels of
 | 
			
		||||
@@ -194,7 +113,7 @@ $! The creator routine
 | 
			
		||||
$ create_nonvax_shr:
 | 
			
		||||
$   open/write opt 'libopt'
 | 
			
		||||
$   write opt "identification=""",libid," ",libverstr,""""
 | 
			
		||||
$   write opt libolb, " /library"
 | 
			
		||||
$   write opt libolb,"/lib"
 | 
			
		||||
$   if libref .nes. "" then write opt libref,"/SHARE"
 | 
			
		||||
$   write opt "SYMBOL_VECTOR=(-"
 | 
			
		||||
$   libfirstentry := true
 | 
			
		||||
@@ -205,8 +124,7 @@ $   gosub read_func_num
 | 
			
		||||
$   write opt ")"
 | 
			
		||||
$   write opt "GSMATCH=",libvmatch,",",libver
 | 
			
		||||
$   close opt
 | 
			
		||||
$   link /map = 'libmap' /full /share = 'libgoal' 'libopt' /options -
 | 
			
		||||
     'zlib_lib'
 | 
			
		||||
$   link/map='libmap'/full/share='libgoal' 'libopt'/option
 | 
			
		||||
$   return
 | 
			
		||||
$
 | 
			
		||||
$! The record writer routine
 | 
			
		||||
@@ -278,7 +196,7 @@ $   close mar
 | 
			
		||||
$   open/write opt 'libopt'
 | 
			
		||||
$   write opt "identification=""",libid," ",libverstr,""""
 | 
			
		||||
$   write opt libobj
 | 
			
		||||
$   write opt libolb, " /library"
 | 
			
		||||
$   write opt libolb,"/lib"
 | 
			
		||||
$   if libref .nes. "" then write opt libref,"/SHARE"
 | 
			
		||||
$   type sys$input:/out=opt:
 | 
			
		||||
!
 | 
			
		||||
@@ -297,8 +215,7 @@ $   libwriter := write_vax_psect_attr
 | 
			
		||||
$   gosub read_func_num
 | 
			
		||||
$   close opt
 | 
			
		||||
$   macro/obj='libobj' 'libmar'
 | 
			
		||||
$   link /map = 'libmap' /full /share = 'libgoal' 'libopt' /options -
 | 
			
		||||
     'zlib_lib'
 | 
			
		||||
$   link/map='libmap'/full/share='libgoal' 'libopt'/option
 | 
			
		||||
$   return
 | 
			
		||||
$
 | 
			
		||||
$! The record writer routine for VAX functions
 | 
			
		||||
@@ -320,9 +237,9 @@ $   return
 | 
			
		||||
$
 | 
			
		||||
$! ----- Common subroutines
 | 
			
		||||
$! -----
 | 
			
		||||
$! The .num file reader.  This one has great responsibility.
 | 
			
		||||
$! The .num file reader.  This one has great responsability.
 | 
			
		||||
$ read_func_num:
 | 
			
		||||
$   open /read libnum 'libnum'
 | 
			
		||||
$   open libnum 'libnum'
 | 
			
		||||
$   goto read_nums
 | 
			
		||||
$
 | 
			
		||||
$ read_nums:
 | 
			
		||||
@@ -331,12 +248,9 @@ $   liblastentry:=false
 | 
			
		||||
$   entrycount=0
 | 
			
		||||
$   loop:
 | 
			
		||||
$     read/end=loop_end/err=loop_end libnum line
 | 
			
		||||
$     lin = f$edit( line, "COMPRESS,TRIM")
 | 
			
		||||
$!    Skip a "#" comment line.
 | 
			
		||||
$     if (f$extract( 0, 1, lin) .eqs. "#") then goto loop
 | 
			
		||||
$     entrynum = f$int(f$element( 1, " ", lin))
 | 
			
		||||
$     entryinfo = f$element( 2, " ", lin)
 | 
			
		||||
$     curentry = f$element( 0, " ", lin)
 | 
			
		||||
$     entrynum=f$int(f$element(1," ",f$edit(line,"COMPRESS,TRIM")))
 | 
			
		||||
$     entryinfo=f$element(2," ",f$edit(line,"COMPRESS,TRIM"))
 | 
			
		||||
$     curentry=f$element(0," ",f$edit(line,"COMPRESS,TRIM"))
 | 
			
		||||
$     info_exist=f$element(0,":",entryinfo)
 | 
			
		||||
$     info_platforms=","+f$element(1,":",entryinfo)+","
 | 
			
		||||
$     info_kind=f$element(2,":",entryinfo)
 | 
			
		||||
@@ -353,7 +267,7 @@ $       if plat_entry .eqs. "" then goto loop1
 | 
			
		||||
$       if plat_entry .nes. ","
 | 
			
		||||
$       then
 | 
			
		||||
$         if f$extract(0,1,plat_entry) .nes. "!" then negatives = 0
 | 
			
		||||
$         if (arch_vax)
 | 
			
		||||
$         if f$getsyi("CPU") .lt. 128
 | 
			
		||||
$         then
 | 
			
		||||
$           if plat_entry .eqs. "EXPORT_VAR_AS_FUNCTION" then -
 | 
			
		||||
$             truesum = truesum + 1
 | 
			
		||||
@@ -362,7 +276,6 @@ $             falsesum = falsesum + 1
 | 
			
		||||
$         endif
 | 
			
		||||
$!
 | 
			
		||||
$         if ((plat_entry .eqs. "VMS") .or. -
 | 
			
		||||
            ((plat_entry .eqs. "ZLIB") .and. (ZLIB .nes. "")) .or. -
 | 
			
		||||
            (arch_vax .and. (plat_entry .eqs. "VMSVAX"))) then -
 | 
			
		||||
            truesum = truesum + 1
 | 
			
		||||
$!
 | 
			
		||||
@@ -388,7 +301,8 @@ $	alg_i = alg_i + 1
 | 
			
		||||
$       if alg_entry .eqs. "" then goto loop2
 | 
			
		||||
$       if alg_entry .nes. ","
 | 
			
		||||
$       then
 | 
			
		||||
$	  if disabled_algorithms - ("," + alg_entry + ",") .nes disabled_algorithms then goto loop
 | 
			
		||||
$         if alg_entry .eqs. "KRB5" then goto loop ! Special for now
 | 
			
		||||
$	  if alg_entry .eqs. "STATIC_ENGINE" then goto loop ! Special for now
 | 
			
		||||
$         if f$trnlnm("OPENSSL_NO_"+alg_entry) .nes. "" then goto loop
 | 
			
		||||
$	  goto loop2
 | 
			
		||||
$       endif
 | 
			
		||||
@@ -455,22 +369,3 @@ $     endif
 | 
			
		||||
$   endloop_rvi:
 | 
			
		||||
$   close vf
 | 
			
		||||
$   return
 | 
			
		||||
$
 | 
			
		||||
$! The disabled algorithms reader
 | 
			
		||||
$ read_disabled_algorithms_info:
 | 
			
		||||
$   disabled_algorithms = ","
 | 
			
		||||
$   open /read cf [.CRYPTO.'ARCH']OPENSSLCONF.H
 | 
			
		||||
$   loop_rci:
 | 
			
		||||
$     read/err=endloop_rci/end=endloop_rci cf rci_line
 | 
			
		||||
$     rci_line = f$edit(rci_line,"TRIM,COMPRESS")
 | 
			
		||||
$     rci_ei = 0
 | 
			
		||||
$     if f$extract(0,9,rci_line) .eqs. "# define " then rci_ei = 2
 | 
			
		||||
$     if f$extract(0,8,rci_line) .eqs. "#define " then rci_ei = 1
 | 
			
		||||
$     if rci_ei .eq. 0 then goto loop_rci
 | 
			
		||||
$     rci_e = f$element(rci_ei," ",rci_line)
 | 
			
		||||
$     if f$extract(0,11,rci_e) .nes. "OPENSSL_NO_" then goto loop_rci
 | 
			
		||||
$     disabled_algorithms = disabled_algorithms + f$extract(11,999,rci_e) + ","
 | 
			
		||||
$     goto loop_rci
 | 
			
		||||
$   endloop_rci:
 | 
			
		||||
$   close cf
 | 
			
		||||
$   return
 | 
			
		||||
 
 | 
			
		||||
@@ -1,108 +0,0 @@
 | 
			
		||||
$!
 | 
			
		||||
$! Startup file for OpenSSL 1.x.
 | 
			
		||||
$!
 | 
			
		||||
$! 2011-03-05 SMS.
 | 
			
		||||
$!
 | 
			
		||||
$! This procedure must reside in the OpenSSL installation directory.
 | 
			
		||||
$! It will fail if it is copied to a different location.
 | 
			
		||||
$!
 | 
			
		||||
$! P1  qualifier(s) for DEFINE.  For example, "/SYSTEM" to get the
 | 
			
		||||
$!     logical names defined in the system logical name table.
 | 
			
		||||
$!
 | 
			
		||||
$! P2  "64", to use executables which were built with 64-bit pointers.
 | 
			
		||||
$!
 | 
			
		||||
$! Good (default) and bad status values.
 | 
			
		||||
$!
 | 
			
		||||
$ status =    %x00010001 ! RMS$_NORMAL, normal successful completion.
 | 
			
		||||
$ rms_e_fnf = %x00018292 ! RMS$_FNF, file not found.
 | 
			
		||||
$!
 | 
			
		||||
$! Prepare for problems.
 | 
			
		||||
$!
 | 
			
		||||
$ orig_dev_dir = f$environment( "DEFAULT")
 | 
			
		||||
$ on control_y then goto clean_up
 | 
			
		||||
$ on error then goto clean_up
 | 
			
		||||
$!
 | 
			
		||||
$! Determine hardware architecture.
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$getsyi( "cpu") .lt. 128)
 | 
			
		||||
$ then
 | 
			
		||||
$   arch_name = "VAX"
 | 
			
		||||
$ else
 | 
			
		||||
$   arch_name = f$edit( f$getsyi( "arch_name"), "upcase")
 | 
			
		||||
$   if (arch_name .eqs. "") then arch_name = "UNK"
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ if (p2 .eqs. "64")
 | 
			
		||||
$ then
 | 
			
		||||
$   arch_name_exe = arch_name+ "_64"
 | 
			
		||||
$ else
 | 
			
		||||
$   arch_name_exe = arch_name
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$! Derive the OpenSSL installation device:[directory] from the location
 | 
			
		||||
$! of this command procedure.
 | 
			
		||||
$!
 | 
			
		||||
$ proc = f$environment( "procedure")
 | 
			
		||||
$ proc_dev_dir = f$parse( "A.;", proc, , , "no_conceal") - "A.;"
 | 
			
		||||
$ proc_dev = f$parse( proc_dev_dir, , , "device", "syntax_only")
 | 
			
		||||
$ proc_dir = f$parse( proc_dev_dir, , , "directory", "syntax_only") - -
 | 
			
		||||
   ".][000000"- "[000000."- "]["- "["- "]"
 | 
			
		||||
$ proc_dev_dir = proc_dev+ "["+ proc_dir+ "]"
 | 
			
		||||
$ set default 'proc_dev_dir'
 | 
			
		||||
$ set default [-]
 | 
			
		||||
$ ossl_dev_dir = f$environment( "default")
 | 
			
		||||
$!
 | 
			
		||||
$! Check existence of expected directories (to see if this procedure has
 | 
			
		||||
$! been moved away from its proper place).
 | 
			
		||||
$!
 | 
			
		||||
$ if ((f$search( "certs.dir;1") .eqs. "") .or. -
 | 
			
		||||
   (f$search( "include.dir;1") .eqs. "") .or. -
 | 
			
		||||
   (f$search( "private.dir;1") .eqs. "") .or. -
 | 
			
		||||
   (f$search( "vms.dir;1") .eqs. ""))
 | 
			
		||||
$ then
 | 
			
		||||
$    write sys$output -
 | 
			
		||||
      "   Can't find expected common OpenSSL directories in:"
 | 
			
		||||
$    write sys$output "   ''ossl_dev_dir'"
 | 
			
		||||
$    status = rms_e_fnf
 | 
			
		||||
$    goto clean_up
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ if ((f$search( "''arch_name_exe'_exe.dir;1") .eqs. "") .or. -
 | 
			
		||||
   (f$search( "''arch_name'_lib.dir;1") .eqs. ""))
 | 
			
		||||
$ then
 | 
			
		||||
$    write sys$output -
 | 
			
		||||
      "   Can't find expected architecture-specific OpenSSL directories in:"
 | 
			
		||||
$    write sys$output "   ''ossl_dev_dir'"
 | 
			
		||||
$    status = rms_e_fnf
 | 
			
		||||
$    goto clean_up
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$! All seems well (enough).  Define the OpenSSL logical names.
 | 
			
		||||
$!
 | 
			
		||||
$ ossl_root = ossl_dev_dir- "]"+ ".]"
 | 
			
		||||
$ define /translation_attributes = concealed /nolog'p1 SSLROOT 'ossl_root'
 | 
			
		||||
$ define /nolog 'p1' SSLCERTS     sslroot:[certs]
 | 
			
		||||
$ define /nolog 'p1' SSLINCLUDE   sslroot:[include]
 | 
			
		||||
$ define /nolog 'p1' SSLPRIVATE   sslroot:[private]
 | 
			
		||||
$ define /nolog 'p1' SSLEXE       sslroot:['arch_name_exe'_exe]
 | 
			
		||||
$ define /nolog 'p1' SSLLIB       sslroot:['arch_name'_lib]
 | 
			
		||||
$!
 | 
			
		||||
$! Defining OPENSSL lets a C program use "#include <openssl/{foo}.h>":
 | 
			
		||||
$ define /nolog 'p1' OPENSSL      SSLINCLUDE:
 | 
			
		||||
$!
 | 
			
		||||
$! Run a site-specific procedure, if it exists.
 | 
			
		||||
$!
 | 
			
		||||
$ if f$search( "sslroot:[vms]openssl_systartup.com") .nes."" then -
 | 
			
		||||
   @ sslroot:[vms]openssl_systartup.com
 | 
			
		||||
$!
 | 
			
		||||
$! Restore the original default dev:[dir] (if known).
 | 
			
		||||
$!
 | 
			
		||||
$ clean_up:
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$type( orig_dev_dir) .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$    set default 'orig_dev_dir'
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ EXIT 'status'
 | 
			
		||||
$!
 | 
			
		||||
@@ -1,20 +0,0 @@
 | 
			
		||||
$!
 | 
			
		||||
$! Deassign OpenSSL logical names.
 | 
			
		||||
$!
 | 
			
		||||
$ call deass "OPENSSL" "''p1'"
 | 
			
		||||
$ call deass "SSLCERTS" "''p1'"
 | 
			
		||||
$ call deass "SSLEXE" "''p1'"
 | 
			
		||||
$ call deass "SSLINCLUDE" "''p1'"
 | 
			
		||||
$ call deass "SSLLIB" "''p1'"
 | 
			
		||||
$ call deass "SSLPRIVATE" "''p1'"
 | 
			
		||||
$ call deass "SSLROOT" "''p1'"
 | 
			
		||||
$!
 | 
			
		||||
$ exit
 | 
			
		||||
$!
 | 
			
		||||
$deass: subroutine
 | 
			
		||||
$ if (f$trnlnm( p1) .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$    deassign 'p2' 'p1'
 | 
			
		||||
$ endif
 | 
			
		||||
$ endsubroutine
 | 
			
		||||
$!
 | 
			
		||||
							
								
								
									
										7
									
								
								apps/.cvsignore
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										7
									
								
								apps/.cvsignore
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,7 @@
 | 
			
		||||
openssl
 | 
			
		||||
Makefile.save
 | 
			
		||||
der_chop
 | 
			
		||||
der_chop.bak
 | 
			
		||||
CA.pl
 | 
			
		||||
*.flc
 | 
			
		||||
semantic.cache
 | 
			
		||||
							
								
								
									
										90
									
								
								apps/CA.com
									
									
									
									
									
								
							
							
						
						
									
										90
									
								
								apps/CA.com
									
									
									
									
									
								
							@@ -37,25 +37,14 @@ $ VERIFY = openssl + " verify"
 | 
			
		||||
$ X509   = openssl + " x509"
 | 
			
		||||
$ PKCS12 = openssl + " pkcs12"
 | 
			
		||||
$ echo   = "write sys$Output"
 | 
			
		||||
$ RET = 1
 | 
			
		||||
$!
 | 
			
		||||
$! 2010-12-20 SMS.
 | 
			
		||||
$! Use a concealed logical name to reduce command line lengths, to
 | 
			
		||||
$! avoid DCL errors on VAX:
 | 
			
		||||
$!     %DCL-W-TKNOVF, command element is too long - shorten
 | 
			
		||||
$! (Path segments like "openssl-1_0_1-stable-SNAP-20101217" accumulate
 | 
			
		||||
$! quickly.)
 | 
			
		||||
$!
 | 
			
		||||
$ CATOP = F$PARSE( F$ENVIRONMENT( "DEFAULT"), "[]")- "].;"+ ".demoCA.]"
 | 
			
		||||
$ define /translation_attributes = concealed CATOP 'CATOP'
 | 
			
		||||
$!
 | 
			
		||||
$ on error then goto clean_up
 | 
			
		||||
$ on control_y then goto clean_up
 | 
			
		||||
$!
 | 
			
		||||
$ CAKEY  = "CATOP:[private]cakey.pem"
 | 
			
		||||
$ CACERT = "CATOP:[000000]cacert.pem"
 | 
			
		||||
$ s = F$PARSE(F$ENVIRONMENT("DEFAULT"),"[]") - "].;"
 | 
			
		||||
$ CATOP  := 's'.demoCA
 | 
			
		||||
$ CAKEY  := ]cakey.pem
 | 
			
		||||
$ CACERT := ]cacert.pem
 | 
			
		||||
$
 | 
			
		||||
$ __INPUT := SYS$COMMAND
 | 
			
		||||
$ RET = 1
 | 
			
		||||
$!
 | 
			
		||||
$ i = 1
 | 
			
		||||
$opt_loop:
 | 
			
		||||
@@ -66,7 +55,7 @@ $
 | 
			
		||||
$ IF (prog_opt .EQS. "?" .OR. prog_opt .EQS. "-h" .OR. prog_opt .EQS. "-help") 
 | 
			
		||||
$ THEN
 | 
			
		||||
$   echo "usage: CA -newcert|-newreq|-newca|-sign|-verify" 
 | 
			
		||||
$   goto clean_up
 | 
			
		||||
$   exit
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$ IF (prog_opt .EQS. "-input")
 | 
			
		||||
@@ -80,7 +69,7 @@ $!
 | 
			
		||||
$ IF (prog_opt .EQS. "-newcert")
 | 
			
		||||
$ THEN
 | 
			
		||||
$   ! Create a certificate.
 | 
			
		||||
$   DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$   DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$   REQ -new -x509 -keyout newreq.pem -out newreq.pem 'DAYS'
 | 
			
		||||
$   RET=$STATUS
 | 
			
		||||
$   echo "Certificate (and private key) is in newreq.pem"
 | 
			
		||||
@@ -90,7 +79,7 @@ $!
 | 
			
		||||
$ IF (prog_opt .EQS. "-newreq")
 | 
			
		||||
$ THEN
 | 
			
		||||
$   ! Create a certificate request
 | 
			
		||||
$   DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$   DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$   REQ -new -keyout newreq.pem -out newreq.pem 'DAYS'
 | 
			
		||||
$   RET=$STATUS
 | 
			
		||||
$   echo "Request (and private key) is in newreq.pem"
 | 
			
		||||
@@ -101,39 +90,40 @@ $ IF (prog_opt .EQS. "-newca")
 | 
			
		||||
$ THEN
 | 
			
		||||
$   ! If explicitly asked for or it doesn't exist then setup the directory
 | 
			
		||||
$   ! structure that Eric likes to manage things.
 | 
			
		||||
$   IF F$SEARCH( "CATOP:[000000]serial.") .EQS. ""
 | 
			
		||||
$   IF F$SEARCH(CATOP+"]serial.") .EQS. ""
 | 
			
		||||
$   THEN
 | 
			
		||||
$     CREATE /DIRECTORY /PROTECTION=OWNER:RWED CATOP:[000000]
 | 
			
		||||
$     CREATE /DIRECTORY /PROTECTION=OWNER:RWED CATOP:[certs]
 | 
			
		||||
$     CREATE /DIRECTORY /PROTECTION=OWNER:RWED CATOP:[crl]
 | 
			
		||||
$     CREATE /DIRECTORY /PROTECTION=OWNER:RWED CATOP:[newcerts]
 | 
			
		||||
$     CREATE /DIRECTORY /PROTECTION=OWNER:RWED CATOP:[private]
 | 
			
		||||
$     CREATE /DIR /PROTECTION=OWNER:RWED 'CATOP']
 | 
			
		||||
$     CREATE /DIR /PROTECTION=OWNER:RWED 'CATOP'.certs]
 | 
			
		||||
$     CREATE /DIR /PROTECTION=OWNER:RWED 'CATOP'.crl]
 | 
			
		||||
$     CREATE /DIR /PROTECTION=OWNER:RWED 'CATOP'.newcerts]
 | 
			
		||||
$     CREATE /DIR /PROTECTION=OWNER:RWED 'CATOP'.private]
 | 
			
		||||
$
 | 
			
		||||
$     OPEN /WRITE ser_file CATOP:[000000]serial. 
 | 
			
		||||
$     OPEN   /WRITE ser_file 'CATOP']serial. 
 | 
			
		||||
$     WRITE ser_file "01"
 | 
			
		||||
$     CLOSE ser_file
 | 
			
		||||
$     APPEND /NEW_VERSION NL: CATOP:[000000]index.txt
 | 
			
		||||
$     APPEND/NEW NL: 'CATOP']index.txt
 | 
			
		||||
$
 | 
			
		||||
$     ! The following is to make sure access() doesn't get confused.  It
 | 
			
		||||
$     ! really needs one file in the directory to give correct answers...
 | 
			
		||||
$     COPY NLA0: CATOP:[certs].;
 | 
			
		||||
$     COPY NLA0: CATOP:[crl].;
 | 
			
		||||
$     COPY NLA0: CATOP:[newcerts].;
 | 
			
		||||
$     COPY NLA0: CATOP:[private].;
 | 
			
		||||
$     COPY NLA0: 'CATOP'.certs].;
 | 
			
		||||
$     COPY NLA0: 'CATOP'.crl].;
 | 
			
		||||
$     COPY NLA0: 'CATOP'.newcerts].;
 | 
			
		||||
$     COPY NLA0: 'CATOP'.private].;
 | 
			
		||||
$   ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$   IF F$SEARCH( CAKEY) .EQS. ""
 | 
			
		||||
$   IF F$SEARCH(CATOP+".private"+CAKEY) .EQS. ""
 | 
			
		||||
$   THEN
 | 
			
		||||
$     READ '__INPUT' FILE -
 | 
			
		||||
	   /PROMPT="CA certificate filename (or enter to create): "
 | 
			
		||||
$     IF (FILE .NES. "") .AND. (F$SEARCH(FILE) .NES. "")
 | 
			
		||||
$     THEN
 | 
			
		||||
$       COPY 'FILE' 'CAKEY'
 | 
			
		||||
$       COPY 'FILE' 'CATOP'.private'CAKEY'
 | 
			
		||||
$	RET=$STATUS
 | 
			
		||||
$     ELSE
 | 
			
		||||
$       echo "Making CA certificate ..."
 | 
			
		||||
$       DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$       REQ -new -x509 -keyout 'CAKEY' -out 'CACERT' 'DAYS'
 | 
			
		||||
$       DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$       REQ -new -x509 -keyout 'CATOP'.private'CAKEY' -
 | 
			
		||||
		       -out 'CATOP''CACERT' 'DAYS'
 | 
			
		||||
$	RET=$STATUS
 | 
			
		||||
$     ENDIF
 | 
			
		||||
$   ENDIF
 | 
			
		||||
@@ -145,16 +135,16 @@ $ THEN
 | 
			
		||||
$   i = i + 1
 | 
			
		||||
$   cname = P'i'
 | 
			
		||||
$   IF cname .EQS. "" THEN cname = "My certificate"
 | 
			
		||||
$   PKCS12 -in newcert.pem -inkey newreq.pem -certfile 'CACERT' -
 | 
			
		||||
$   PKCS12 -in newcert.pem -inkey newreq.pem -certfile 'CATOP''CACERT -
 | 
			
		||||
	   -out newcert.p12 -export -name "''cname'"
 | 
			
		||||
$   RET=$STATUS
 | 
			
		||||
$   goto clean_up
 | 
			
		||||
$   exit RET
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$ IF (prog_opt .EQS. "-xsign")
 | 
			
		||||
$ THEN
 | 
			
		||||
$!
 | 
			
		||||
$   DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$   DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$   CA -policy policy_anything -infiles newreq.pem
 | 
			
		||||
$   RET=$STATUS
 | 
			
		||||
$   GOTO opt_loop_continue
 | 
			
		||||
@@ -163,7 +153,7 @@ $!
 | 
			
		||||
$ IF ((prog_opt .EQS. "-sign") .OR. (prog_opt .EQS. "-signreq"))
 | 
			
		||||
$ THEN
 | 
			
		||||
$!   
 | 
			
		||||
$   DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$   DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$   CA -policy policy_anything -out newcert.pem -infiles newreq.pem
 | 
			
		||||
$   RET=$STATUS
 | 
			
		||||
$   type newcert.pem
 | 
			
		||||
@@ -175,9 +165,9 @@ $ IF (prog_opt .EQS. "-signcert")
 | 
			
		||||
$  THEN
 | 
			
		||||
$!   
 | 
			
		||||
$   echo "Cert passphrase will be requested twice - bug?"
 | 
			
		||||
$   DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$   DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$   X509 -x509toreq -in newreq.pem -signkey newreq.pem -out tmp.pem
 | 
			
		||||
$   DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$   DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$   CA -policy policy_anything -out newcert.pem -infiles tmp.pem
 | 
			
		||||
y
 | 
			
		||||
y
 | 
			
		||||
@@ -192,17 +182,17 @@ $!
 | 
			
		||||
$   i = i + 1
 | 
			
		||||
$   IF (p'i' .EQS. "")
 | 
			
		||||
$   THEN
 | 
			
		||||
$     DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$     VERIFY "-CAfile" 'CACERT' newcert.pem
 | 
			
		||||
$     DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$     VERIFY "-CAfile" 'CATOP''CACERT' newcert.pem
 | 
			
		||||
$   ELSE
 | 
			
		||||
$     j = i
 | 
			
		||||
$    verify_opt_loop:
 | 
			
		||||
$     IF j .GT. 8 THEN GOTO verify_opt_loop_end
 | 
			
		||||
$     IF p'j' .NES. ""
 | 
			
		||||
$     THEN 
 | 
			
		||||
$       DEFINE /USER_MODE SYS$INPUT '__INPUT'
 | 
			
		||||
$       DEFINE/USER SYS$INPUT '__INPUT'
 | 
			
		||||
$       __tmp = p'j'
 | 
			
		||||
$       VERIFY "-CAfile" 'CACERT' '__tmp'
 | 
			
		||||
$       VERIFY "-CAfile" 'CATOP''CACERT' '__tmp'
 | 
			
		||||
$       tmp=$STATUS
 | 
			
		||||
$       IF tmp .NE. 0 THEN RET=tmp
 | 
			
		||||
$     ENDIF
 | 
			
		||||
@@ -218,8 +208,8 @@ $ IF (prog_opt .NES. "")
 | 
			
		||||
$ THEN
 | 
			
		||||
$!   
 | 
			
		||||
$   echo "Unknown argument ''prog_opt'"
 | 
			
		||||
$   RET = 3
 | 
			
		||||
$   goto clean_up
 | 
			
		||||
$   
 | 
			
		||||
$   EXIT 3
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$
 | 
			
		||||
$opt_loop_continue:
 | 
			
		||||
@@ -227,10 +217,4 @@ $ i = i + 1
 | 
			
		||||
$ GOTO opt_loop
 | 
			
		||||
$
 | 
			
		||||
$opt_loop_end:
 | 
			
		||||
$!
 | 
			
		||||
$clean_up:
 | 
			
		||||
$!
 | 
			
		||||
$ if f$trnlnm( "CATOP", "LNM$PROCESS") .nes. "" then -
 | 
			
		||||
   deassign /process CATOP
 | 
			
		||||
$!
 | 
			
		||||
$ EXIT 'RET'
 | 
			
		||||
 
 | 
			
		||||
@@ -1,10 +1,37 @@
 | 
			
		||||
#!/usr/local/bin/perl
 | 
			
		||||
#
 | 
			
		||||
# CA - wrapper around ca to make it easier to use
 | 
			
		||||
# CA - wrapper around ca to make it easier to use ... basically ca requires
 | 
			
		||||
#      some setup stuff to be done before you can use it and this makes
 | 
			
		||||
#      things easier between now and when Eric is convinced to fix it :-)
 | 
			
		||||
#
 | 
			
		||||
# CA -newca ... will setup the right stuff
 | 
			
		||||
# CA -newreq[-nodes] ... will generate a certificate request 
 | 
			
		||||
# CA -sign ... will sign the generated request and output 
 | 
			
		||||
#
 | 
			
		||||
# At the end of that grab newreq.pem and newcert.pem (one has the key 
 | 
			
		||||
# and the other the certificate) and cat them together and that is what
 | 
			
		||||
# you want/need ... I'll make even this a little cleaner later.
 | 
			
		||||
#
 | 
			
		||||
#
 | 
			
		||||
# 12-Jan-96 tjh    Added more things ... including CA -signcert which
 | 
			
		||||
#                  converts a certificate to a request and then signs it.
 | 
			
		||||
# 10-Jan-96 eay    Fixed a few more bugs and added the SSLEAY_CONFIG
 | 
			
		||||
#		   environment variable so this can be driven from
 | 
			
		||||
#		   a script.
 | 
			
		||||
# 25-Jul-96 eay    Cleaned up filenames some more.
 | 
			
		||||
# 11-Jun-96 eay    Fixed a few filename missmatches.
 | 
			
		||||
# 03-May-96 eay    Modified to use 'ssleay cmd' instead of 'cmd'.
 | 
			
		||||
# 18-Apr-96 tjh    Original hacking
 | 
			
		||||
#
 | 
			
		||||
# Tim Hudson
 | 
			
		||||
# tjh@cryptsoft.com
 | 
			
		||||
#
 | 
			
		||||
 | 
			
		||||
# 27-Apr-98 snh    Translation into perl, fix existing CA bug.
 | 
			
		||||
#
 | 
			
		||||
#
 | 
			
		||||
# Steve Henson
 | 
			
		||||
# shenson@bigfoot.com
 | 
			
		||||
 | 
			
		||||
# default openssl.cnf file has setup as per the following
 | 
			
		||||
# demoCA ... where everything is stored
 | 
			
		||||
@@ -30,7 +57,6 @@ $CATOP="./demoCA";
 | 
			
		||||
$CAKEY="cakey.pem";
 | 
			
		||||
$CAREQ="careq.pem";
 | 
			
		||||
$CACERT="cacert.pem";
 | 
			
		||||
$CACRL="crl.pem";
 | 
			
		||||
 | 
			
		||||
$DIRMODE = 0777;
 | 
			
		||||
 | 
			
		||||
@@ -39,7 +65,6 @@ $RET = 0;
 | 
			
		||||
foreach (@ARGV) {
 | 
			
		||||
	if ( /^(-\?|-h|-help)$/ ) {
 | 
			
		||||
	    print STDERR "usage: CA -newcert|-newreq|-newreq-nodes|-newca|-sign|-verify\n";
 | 
			
		||||
	    print STDERR "       CA -crl|-revoke cert-filename [reason]\n";
 | 
			
		||||
	    exit 0;
 | 
			
		||||
	} elsif (/^-newcert$/) {
 | 
			
		||||
	    # create a certificate
 | 
			
		||||
@@ -135,50 +160,17 @@ foreach (@ARGV) {
 | 
			
		||||
	    } else {
 | 
			
		||||
		    system ("$VERIFY -CAfile $CATOP/$CACERT newcert.pem");
 | 
			
		||||
		    $RET=$?;
 | 
			
		||||
		    exit $RET;
 | 
			
		||||
	    	    exit 0;
 | 
			
		||||
	    }
 | 
			
		||||
	} elsif (/^-crl$/) {
 | 
			
		||||
		system ("$CA -gencrl -out $CATOP/crl/$CACRL");
 | 
			
		||||
		$RET=$?;
 | 
			
		||||
		print "Generated CRL is in $CATOP/crl/$CACRL\n" if (!$RET);
 | 
			
		||||
	} elsif (/^-revoke$/) {
 | 
			
		||||
		my $cname = $ARGV[1];
 | 
			
		||||
		if (!defined $cname) {
 | 
			
		||||
			print "Certificate filename is required; reason optional.\n";
 | 
			
		||||
			exit 1;
 | 
			
		||||
		}
 | 
			
		||||
		my $reason = $ARGV[2];
 | 
			
		||||
		$reason = " -crl_reason $reason"
 | 
			
		||||
			if defined $reason && crl_reason_ok($reason);
 | 
			
		||||
		my $cmd = "$CA -revoke \"$cname\"".$reason;
 | 
			
		||||
		system ($cmd);
 | 
			
		||||
		$RET=$?;
 | 
			
		||||
		exit $RET;
 | 
			
		||||
	} else {
 | 
			
		||||
	    print STDERR "Unknown arg $_\n";
 | 
			
		||||
	    print STDERR "usage: CA -newcert|-newreq|-newreq-nodes|-newca|-sign|-verify\n";
 | 
			
		||||
	    print STDERR "       CA -crl|-revoke cert-filename [reason]\n";
 | 
			
		||||
	    exit 1;
 | 
			
		||||
	}
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
exit $RET;
 | 
			
		||||
 | 
			
		||||
sub crl_reason_ok {
 | 
			
		||||
	my ($r) = shift;
 | 
			
		||||
	if ($r eq 'unspecified' || $r eq 'keyCompromise' ||
 | 
			
		||||
	$r eq 'CACompromise' || $r eq 'affiliationChanged' ||
 | 
			
		||||
	$r eq 'superseded' || $r eq 'cessationOfOperation' ||
 | 
			
		||||
	$r eq 'certificateHold' || $r eq 'removeFromCRL') {
 | 
			
		||||
		return 1;
 | 
			
		||||
	}
 | 
			
		||||
	print STDERR "Invalid CRL reason; must be one of:\n";
 | 
			
		||||
	print STDERR "    unspecified, keyCompromise, CACompromise,\n";
 | 
			
		||||
	print STDERR "    affiliationChanged, superseded, cessationOfOperation\n";
 | 
			
		||||
	print STDERR "    certificateHold, removeFromCRL";
 | 
			
		||||
	exit 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
sub cp_pem {
 | 
			
		||||
my ($infile, $outfile, $bound) = @_;
 | 
			
		||||
open IN, $infile;
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										1032
									
								
								apps/Makefile
									
									
									
									
									
								
							
							
						
						
									
										1032
									
								
								apps/Makefile
									
									
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										1180
									
								
								apps/apps.c
									
									
									
									
									
								
							
							
						
						
									
										1180
									
								
								apps/apps.c
									
									
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										124
									
								
								apps/apps.h
									
									
									
									
									
								
							
							
						
						
									
										124
									
								
								apps/apps.h
									
									
									
									
									
								
							@@ -138,6 +138,11 @@ long app_RAND_load_files(char *file); /* `file' is a list of files to read,
 | 
			
		||||
                                       * (see e_os.h).  The string is
 | 
			
		||||
                                       * destroyed! */
 | 
			
		||||
 | 
			
		||||
# ifdef OPENSSL_SYS_WIN32
 | 
			
		||||
#  define rename(from,to) WIN32_rename((from),(to))
 | 
			
		||||
int WIN32_rename(const char *oldname, const char *newname);
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# ifndef MONOLITH
 | 
			
		||||
 | 
			
		||||
#  define MAIN(a,v)       main(a,v)
 | 
			
		||||
@@ -145,9 +150,11 @@ long app_RAND_load_files(char *file); /* `file' is a list of files to read,
 | 
			
		||||
#  ifndef NON_MAIN
 | 
			
		||||
CONF *config = NULL;
 | 
			
		||||
BIO *bio_err = NULL;
 | 
			
		||||
int in_FIPS_mode = 0;
 | 
			
		||||
#  else
 | 
			
		||||
extern CONF *config;
 | 
			
		||||
extern BIO *bio_err;
 | 
			
		||||
extern int in_FIPS_mode;
 | 
			
		||||
#  endif
 | 
			
		||||
 | 
			
		||||
# else
 | 
			
		||||
@@ -156,6 +163,7 @@ extern BIO *bio_err;
 | 
			
		||||
extern CONF *config;
 | 
			
		||||
extern char *default_config_file;
 | 
			
		||||
extern BIO *bio_err;
 | 
			
		||||
extern int in_FIPS_mode;
 | 
			
		||||
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
@@ -169,43 +177,65 @@ extern BIO *bio_err;
 | 
			
		||||
#  define do_pipe_sig()
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# ifdef OPENSSL_NO_COMP
 | 
			
		||||
#  define zlib_cleanup()
 | 
			
		||||
# else
 | 
			
		||||
#  define zlib_cleanup() COMP_zlib_cleanup()
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# if defined(MONOLITH) && !defined(OPENSSL_C)
 | 
			
		||||
#  define apps_startup() \
 | 
			
		||||
                do_pipe_sig()
 | 
			
		||||
#  define apps_shutdown()
 | 
			
		||||
# else
 | 
			
		||||
#  ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
#   if defined(OPENSSL_SYS_MSDOS) || defined(OPENSSL_SYS_WIN16) || \
 | 
			
		||||
     defined(OPENSSL_SYS_WIN32)
 | 
			
		||||
#    ifdef _O_BINARY
 | 
			
		||||
#     define apps_startup() \
 | 
			
		||||
                        do { do_pipe_sig(); CRYPTO_malloc_init(); \
 | 
			
		||||
                        do { _fmode=_O_BINARY; do_pipe_sig(); CRYPTO_malloc_init(); \
 | 
			
		||||
                        ERR_load_crypto_strings(); OpenSSL_add_all_algorithms(); \
 | 
			
		||||
                        ENGINE_load_builtin_engines(); setup_ui_method(); } while(0)
 | 
			
		||||
#   define apps_shutdown() \
 | 
			
		||||
                        do { CONF_modules_unload(1); destroy_ui_method(); \
 | 
			
		||||
                        OBJ_cleanup(); EVP_cleanup(); ENGINE_cleanup(); \
 | 
			
		||||
                        CRYPTO_cleanup_all_ex_data(); ERR_remove_thread_state(NULL); \
 | 
			
		||||
                        RAND_cleanup(); \
 | 
			
		||||
                        ERR_free_strings(); zlib_cleanup();} while(0)
 | 
			
		||||
#    else
 | 
			
		||||
#     define apps_startup() \
 | 
			
		||||
                        do { do_pipe_sig(); CRYPTO_malloc_init(); \
 | 
			
		||||
                        do { _fmode=O_BINARY; do_pipe_sig(); CRYPTO_malloc_init(); \
 | 
			
		||||
                        ERR_load_crypto_strings(); OpenSSL_add_all_algorithms(); \
 | 
			
		||||
                        ENGINE_load_builtin_engines(); setup_ui_method(); } while(0)
 | 
			
		||||
#    endif
 | 
			
		||||
#   else
 | 
			
		||||
#    define apps_startup() \
 | 
			
		||||
                        do { do_pipe_sig(); OpenSSL_add_all_algorithms(); \
 | 
			
		||||
                        ERR_load_crypto_strings(); ENGINE_load_builtin_engines(); \
 | 
			
		||||
                        setup_ui_method(); } while(0)
 | 
			
		||||
#   endif
 | 
			
		||||
#   define apps_shutdown() \
 | 
			
		||||
                        do { CONF_modules_unload(1); destroy_ui_method(); \
 | 
			
		||||
                        OBJ_cleanup(); EVP_cleanup(); \
 | 
			
		||||
                        CRYPTO_cleanup_all_ex_data(); ERR_remove_thread_state(NULL); \
 | 
			
		||||
                        RAND_cleanup(); \
 | 
			
		||||
                        ERR_free_strings(); zlib_cleanup(); } while(0)
 | 
			
		||||
                        EVP_cleanup(); ENGINE_cleanup(); \
 | 
			
		||||
                        CRYPTO_cleanup_all_ex_data(); ERR_remove_state(0); \
 | 
			
		||||
                        ERR_free_strings(); } while(0)
 | 
			
		||||
#  else
 | 
			
		||||
#   if defined(OPENSSL_SYS_MSDOS) || defined(OPENSSL_SYS_WIN16) || \
 | 
			
		||||
     defined(OPENSSL_SYS_WIN32)
 | 
			
		||||
#    ifdef _O_BINARY
 | 
			
		||||
#     define apps_startup() \
 | 
			
		||||
                        do { _fmode=_O_BINARY; do_pipe_sig(); CRYPTO_malloc_init(); \
 | 
			
		||||
                        ERR_load_crypto_strings(); OpenSSL_add_all_algorithms(); \
 | 
			
		||||
                        setup_ui_method(); } while(0)
 | 
			
		||||
#    else
 | 
			
		||||
#     define apps_startup() \
 | 
			
		||||
                        do { _fmode=O_BINARY; do_pipe_sig(); CRYPTO_malloc_init(); \
 | 
			
		||||
                        ERR_load_crypto_strings(); OpenSSL_add_all_algorithms(); \
 | 
			
		||||
                        setup_ui_method(); } while(0)
 | 
			
		||||
#    endif
 | 
			
		||||
#   else
 | 
			
		||||
#    define apps_startup() \
 | 
			
		||||
                        do { do_pipe_sig(); OpenSSL_add_all_algorithms(); \
 | 
			
		||||
                        ERR_load_crypto_strings(); \
 | 
			
		||||
                        setup_ui_method(); } while(0)
 | 
			
		||||
#   endif
 | 
			
		||||
#   define apps_shutdown() \
 | 
			
		||||
                        do { CONF_modules_unload(1); destroy_ui_method(); \
 | 
			
		||||
                        EVP_cleanup(); \
 | 
			
		||||
                        CRYPTO_cleanup_all_ex_data(); ERR_remove_state(0); \
 | 
			
		||||
                        ERR_free_strings(); } while(0)
 | 
			
		||||
#  endif
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# if defined(OPENSSL_SYSNAME_WIN32) || defined(OPENSSL_SYSNAME_WINCE)
 | 
			
		||||
# ifdef OPENSSL_SYSNAME_WIN32
 | 
			
		||||
#  define openssl_fdset(a,b) FD_SET((unsigned int)a, b)
 | 
			
		||||
# else
 | 
			
		||||
#  define openssl_fdset(a,b) FD_SET(a, b)
 | 
			
		||||
@@ -245,9 +275,6 @@ int app_passwd(BIO *err, char *arg1, char *arg2, char **pass1, char **pass2);
 | 
			
		||||
int add_oid_section(BIO *err, CONF *conf);
 | 
			
		||||
X509 *load_cert(BIO *err, const char *file, int format,
 | 
			
		||||
                const char *pass, ENGINE *e, const char *cert_descrip);
 | 
			
		||||
X509_CRL *load_crl(const char *infile, int format);
 | 
			
		||||
int load_cert_crl_http(const char *url, BIO *err,
 | 
			
		||||
                       X509 **pcert, X509_CRL **pcrl);
 | 
			
		||||
EVP_PKEY *load_key(BIO *err, const char *file, int format, int maybe_stdin,
 | 
			
		||||
                   const char *pass, ENGINE *e, const char *key_descrip);
 | 
			
		||||
EVP_PKEY *load_pubkey(BIO *err, const char *file, int format, int maybe_stdin,
 | 
			
		||||
@@ -255,9 +282,6 @@ EVP_PKEY *load_pubkey(BIO *err, const char *file, int format, int maybe_stdin,
 | 
			
		||||
STACK_OF(X509) *load_certs(BIO *err, const char *file, int format,
 | 
			
		||||
                           const char *pass, ENGINE *e,
 | 
			
		||||
                           const char *cert_descrip);
 | 
			
		||||
STACK_OF(X509_CRL) *load_crls(BIO *err, const char *file, int format,
 | 
			
		||||
                              const char *pass, ENGINE *e,
 | 
			
		||||
                              const char *cert_descrip);
 | 
			
		||||
X509_STORE *setup_verify(BIO *bp, char *CAfile, char *CApath);
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
ENGINE *setup_engine(BIO *err, const char *engine, int debug);
 | 
			
		||||
@@ -265,10 +289,8 @@ ENGINE *setup_engine(BIO *err, const char *engine, int debug);
 | 
			
		||||
 | 
			
		||||
# ifndef OPENSSL_NO_OCSP
 | 
			
		||||
OCSP_RESPONSE *process_responder(BIO *err, OCSP_REQUEST *req,
 | 
			
		||||
                                 const char *host, const char *path,
 | 
			
		||||
                                 const char *port, int use_ssl,
 | 
			
		||||
                                 const STACK_OF(CONF_VALUE) *headers,
 | 
			
		||||
                                 int req_timeout);
 | 
			
		||||
                                 char *host, char *path, char *port,
 | 
			
		||||
                                 int use_ssl, int req_timeout);
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
int load_config(BIO *err, CONF *cnf);
 | 
			
		||||
@@ -310,44 +332,18 @@ int save_index(const char *dbfile, const char *suffix, CA_DB *db);
 | 
			
		||||
int rotate_index(const char *dbfile, const char *new_suffix,
 | 
			
		||||
                 const char *old_suffix);
 | 
			
		||||
void free_index(CA_DB *db);
 | 
			
		||||
# define index_name_cmp_noconst(a, b) \
 | 
			
		||||
        index_name_cmp((const OPENSSL_CSTRING *)CHECKED_PTR_OF(OPENSSL_STRING, a), \
 | 
			
		||||
        (const OPENSSL_CSTRING *)CHECKED_PTR_OF(OPENSSL_STRING, b))
 | 
			
		||||
int index_name_cmp(const OPENSSL_CSTRING *a, const OPENSSL_CSTRING *b);
 | 
			
		||||
int index_name_cmp(const char **a, const char **b);
 | 
			
		||||
int parse_yesno(const char *str, int def);
 | 
			
		||||
 | 
			
		||||
X509_NAME *parse_name(char *str, long chtype, int multirdn);
 | 
			
		||||
int args_verify(char ***pargs, int *pargc,
 | 
			
		||||
                int *badarg, BIO *err, X509_VERIFY_PARAM **pm);
 | 
			
		||||
void policies_print(BIO *out, X509_STORE_CTX *ctx);
 | 
			
		||||
int bio_to_mem(unsigned char **out, int maxlen, BIO *in);
 | 
			
		||||
int pkey_ctrl_string(EVP_PKEY_CTX *ctx, char *value);
 | 
			
		||||
int init_gen_str(BIO *err, EVP_PKEY_CTX **pctx,
 | 
			
		||||
                 const char *algname, ENGINE *e, int do_param);
 | 
			
		||||
int do_X509_sign(BIO *err, X509 *x, EVP_PKEY *pkey, const EVP_MD *md,
 | 
			
		||||
                 STACK_OF(OPENSSL_STRING) *sigopts);
 | 
			
		||||
int do_X509_REQ_sign(BIO *err, X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md,
 | 
			
		||||
                     STACK_OF(OPENSSL_STRING) *sigopts);
 | 
			
		||||
int do_X509_CRL_sign(BIO *err, X509_CRL *x, EVP_PKEY *pkey, const EVP_MD *md,
 | 
			
		||||
                     STACK_OF(OPENSSL_STRING) *sigopts);
 | 
			
		||||
# ifndef OPENSSL_NO_PSK
 | 
			
		||||
extern char *psk_key;
 | 
			
		||||
# endif
 | 
			
		||||
# ifndef OPENSSL_NO_JPAKE
 | 
			
		||||
void jpake_client_auth(BIO *out, BIO *conn, const char *secret);
 | 
			
		||||
void jpake_server_auth(BIO *out, BIO *conn, const char *secret);
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# ifndef OPENSSL_NO_TLSEXT
 | 
			
		||||
unsigned char *next_protos_parse(unsigned short *outlen, const char *in);
 | 
			
		||||
# endif                         /* ndef OPENSSL_NO_TLSEXT */
 | 
			
		||||
 | 
			
		||||
void print_cert_checks(BIO *bio, X509 *x,
 | 
			
		||||
                       const char *checkhost,
 | 
			
		||||
                       const char *checkemail, const char *checkip);
 | 
			
		||||
 | 
			
		||||
void store_setup_crl_download(X509_STORE *st);
 | 
			
		||||
 | 
			
		||||
# define FORMAT_UNDEF    0
 | 
			
		||||
# define FORMAT_ASN1     1
 | 
			
		||||
# define FORMAT_TEXT     2
 | 
			
		||||
@@ -358,12 +354,6 @@ void store_setup_crl_download(X509_STORE *st);
 | 
			
		||||
# define FORMAT_ENGINE   7
 | 
			
		||||
# define FORMAT_IISSGC   8      /* XXX this stupid macro helps us to avoid
 | 
			
		||||
                                 * adding yet another param to load_*key() */
 | 
			
		||||
# define FORMAT_PEMRSA   9      /* PEM RSAPubicKey format */
 | 
			
		||||
# define FORMAT_ASN1RSA  10     /* DER RSAPubicKey format */
 | 
			
		||||
# define FORMAT_MSBLOB   11     /* MS Key blob format */
 | 
			
		||||
# define FORMAT_PVK      12     /* MS PVK file format */
 | 
			
		||||
# define FORMAT_HTTP     13     /* Download using HTTP */
 | 
			
		||||
# define FORMAT_NSS      14     /* NSS keylog format */
 | 
			
		||||
 | 
			
		||||
# define EXT_COPY_NONE   0
 | 
			
		||||
# define EXT_COPY_ADD    1
 | 
			
		||||
@@ -375,14 +365,4 @@ void store_setup_crl_download(X509_STORE *st);
 | 
			
		||||
 | 
			
		||||
# define SERIAL_RAND_BITS        64
 | 
			
		||||
 | 
			
		||||
int app_isdir(const char *);
 | 
			
		||||
int raw_read_stdin(void *, int);
 | 
			
		||||
int raw_write_stdout(const void *, int);
 | 
			
		||||
 | 
			
		||||
# define TM_START        0
 | 
			
		||||
# define TM_STOP         1
 | 
			
		||||
double app_tminterval(int stop, int usertime);
 | 
			
		||||
 | 
			
		||||
# define OPENSSL_NO_SSL_INTERN
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
@@ -92,14 +92,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    unsigned int length = 0;
 | 
			
		||||
    long num, tmplen;
 | 
			
		||||
    BIO *in = NULL, *out = NULL, *b64 = NULL, *derout = NULL;
 | 
			
		||||
    int informat, indent = 0, noout = 0, dump = 0, strictpem = 0;
 | 
			
		||||
    char *infile = NULL, *str = NULL, *prog, *oidfile = NULL, *derfile =
 | 
			
		||||
        NULL, *name = NULL, *header = NULL;
 | 
			
		||||
    int informat, indent = 0, noout = 0, dump = 0;
 | 
			
		||||
    char *infile = NULL, *str = NULL, *prog, *oidfile = NULL, *derfile = NULL;
 | 
			
		||||
    char *genstr = NULL, *genconf = NULL;
 | 
			
		||||
    unsigned char *tmpbuf;
 | 
			
		||||
    const unsigned char *ctmpbuf;
 | 
			
		||||
    BUF_MEM *buf = NULL;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *osk = NULL;
 | 
			
		||||
    STACK *osk = NULL;
 | 
			
		||||
    ASN1_TYPE *at = NULL;
 | 
			
		||||
 | 
			
		||||
    informat = FORMAT_PEM;
 | 
			
		||||
@@ -116,7 +115,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    prog = argv[0];
 | 
			
		||||
    argc--;
 | 
			
		||||
    argv++;
 | 
			
		||||
    if ((osk = sk_OPENSSL_STRING_new_null()) == NULL) {
 | 
			
		||||
    if ((osk = sk_new_null()) == NULL) {
 | 
			
		||||
        BIO_printf(bio_err, "Memory allocation failure\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
@@ -162,7 +161,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        } else if (strcmp(*argv, "-strparse") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            sk_OPENSSL_STRING_push(osk, *(++argv));
 | 
			
		||||
            sk_push(osk, *(++argv));
 | 
			
		||||
        } else if (strcmp(*argv, "-genstr") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
@@ -171,9 +170,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            genconf = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-strictpem") == 0) {
 | 
			
		||||
            strictpem = 1;
 | 
			
		||||
            informat = FORMAT_PEM;
 | 
			
		||||
        } else {
 | 
			
		||||
            BIO_printf(bio_err, "unknown option %s\n", *argv);
 | 
			
		||||
            badops = 1;
 | 
			
		||||
@@ -207,9 +203,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   " -genstr str   string to generate ASN1 structure from\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   " -genconf file file to generate ASN1 structure from\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   " -strictpem    do not attempt base64 decode outside PEM markers (-inform \n");
 | 
			
		||||
        BIO_printf(bio_err, "               will be ignored)\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -255,15 +248,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (strictpem) {
 | 
			
		||||
        if (PEM_read_bio(in, &name, &header, (unsigned char **)&str, &num) !=
 | 
			
		||||
            1) {
 | 
			
		||||
            BIO_printf(bio_err, "Error reading PEM file\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
 | 
			
		||||
    if ((buf = BUF_MEM_new()) == NULL)
 | 
			
		||||
        goto end;
 | 
			
		||||
    if (!BUF_MEM_grow(buf, BUFSIZ * 8))
 | 
			
		||||
@@ -302,20 +286,18 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
    str = buf->data;
 | 
			
		||||
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    /* If any structs to parse go through in sequence */
 | 
			
		||||
 | 
			
		||||
    if (sk_OPENSSL_STRING_num(osk)) {
 | 
			
		||||
    if (sk_num(osk)) {
 | 
			
		||||
        tmpbuf = (unsigned char *)str;
 | 
			
		||||
        tmplen = num;
 | 
			
		||||
        for (i = 0; i < sk_OPENSSL_STRING_num(osk); i++) {
 | 
			
		||||
        for (i = 0; i < sk_num(osk); i++) {
 | 
			
		||||
            ASN1_TYPE *atmp;
 | 
			
		||||
            int typ;
 | 
			
		||||
            j = atoi(sk_OPENSSL_STRING_value(osk, i));
 | 
			
		||||
            j = atoi(sk_value(osk, i));
 | 
			
		||||
            if (j == 0) {
 | 
			
		||||
                BIO_printf(bio_err, "'%s' is an invalid number\n",
 | 
			
		||||
                           sk_OPENSSL_STRING_value(osk, i));
 | 
			
		||||
                           sk_value(osk, i));
 | 
			
		||||
                continue;
 | 
			
		||||
            }
 | 
			
		||||
            tmpbuf += j;
 | 
			
		||||
@@ -380,16 +362,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
    if (buf != NULL)
 | 
			
		||||
        BUF_MEM_free(buf);
 | 
			
		||||
    if (name != NULL)
 | 
			
		||||
        OPENSSL_free(name);
 | 
			
		||||
    if (header != NULL)
 | 
			
		||||
        OPENSSL_free(header);
 | 
			
		||||
    if (strictpem && str != NULL)
 | 
			
		||||
        OPENSSL_free(str);
 | 
			
		||||
    if (at != NULL)
 | 
			
		||||
        ASN1_TYPE_free(at);
 | 
			
		||||
    if (osk != NULL)
 | 
			
		||||
        sk_OPENSSL_STRING_free(osk);
 | 
			
		||||
        sk_free(osk);
 | 
			
		||||
    OBJ_cleanup();
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										306
									
								
								apps/ca.c
									
									
									
									
									
								
							
							
						
						
									
										306
									
								
								apps/ca.c
									
									
									
									
									
								
							@@ -63,6 +63,7 @@
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#include <ctype.h>
 | 
			
		||||
#include <sys/types.h>
 | 
			
		||||
#include <sys/stat.h>
 | 
			
		||||
#include <openssl/conf.h>
 | 
			
		||||
#include <openssl/bio.h>
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
@@ -82,7 +83,7 @@
 | 
			
		||||
#  else
 | 
			
		||||
#   include <unixlib.h>
 | 
			
		||||
#  endif
 | 
			
		||||
# elif !defined(OPENSSL_SYS_VXWORKS) && !defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_SYS_NETWARE)
 | 
			
		||||
# elif !defined(OPENSSL_SYS_VXWORKS) && !defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_SYS_NETWARE) && !defined(__TANDEM)
 | 
			
		||||
#  include <sys/file.h>
 | 
			
		||||
# endif
 | 
			
		||||
#endif
 | 
			
		||||
@@ -179,7 +180,7 @@ static const char *ca_usage[] = {
 | 
			
		||||
    " -utf8           - input characters are UTF8 (default ASCII)\n",
 | 
			
		||||
    " -multivalue-rdn - enable support for multivalued RDNs\n",
 | 
			
		||||
    " -extensions ..  - Extension section (override value in config file)\n",
 | 
			
		||||
    " -extfile file   - Configuration file with X509v3 extensions to add\n",
 | 
			
		||||
    " -extfile file   - Configuration file with X509v3 extentions to add\n",
 | 
			
		||||
    " -crlexts ..     - CRL extension section (override value in config file)\n",
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    " -engine e       - use engine e, possibly a hardware device.\n",
 | 
			
		||||
@@ -197,25 +198,23 @@ extern int EF_ALIGNMENT;
 | 
			
		||||
 | 
			
		||||
static void lookup_fail(const char *name, const char *tag);
 | 
			
		||||
static int certify(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                   STACK_OF(CONF_VALUE) *policy, CA_DB *db,
 | 
			
		||||
                   BIGNUM *serial, char *subj, unsigned long chtype,
 | 
			
		||||
                   int multirdn, int email_dn, char *startdate, char *enddate,
 | 
			
		||||
                   long days, int batch, char *ext_sect, CONF *conf,
 | 
			
		||||
                   int verbose, unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(CONF_VALUE) *policy,
 | 
			
		||||
                   CA_DB *db, BIGNUM *serial, char *subj,
 | 
			
		||||
                   unsigned long chtype, int multirdn, int email_dn,
 | 
			
		||||
                   char *startdate, char *enddate, long days, int batch,
 | 
			
		||||
                   char *ext_sect, CONF *conf, int verbose,
 | 
			
		||||
                   unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   int default_op, int ext_copy, int selfsign);
 | 
			
		||||
static int certify_cert(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
                        const EVP_MD *dgst, STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                        STACK_OF(CONF_VALUE) *policy, CA_DB *db,
 | 
			
		||||
                        BIGNUM *serial, char *subj, unsigned long chtype,
 | 
			
		||||
                        int multirdn, int email_dn, char *startdate,
 | 
			
		||||
                        char *enddate, long days, int batch, char *ext_sect,
 | 
			
		||||
                        CONF *conf, int verbose, unsigned long certopt,
 | 
			
		||||
                        unsigned long nameopt, int default_op, int ext_copy,
 | 
			
		||||
                        ENGINE *e);
 | 
			
		||||
                        const EVP_MD *dgst, STACK_OF(CONF_VALUE) *policy,
 | 
			
		||||
                        CA_DB *db, BIGNUM *serial, char *subj,
 | 
			
		||||
                        unsigned long chtype, int multirdn, int email_dn,
 | 
			
		||||
                        char *startdate, char *enddate, long days, int batch,
 | 
			
		||||
                        char *ext_sect, CONF *conf, int verbose,
 | 
			
		||||
                        unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                        int default_op, int ext_copy, ENGINE *e);
 | 
			
		||||
static int certify_spkac(X509 **xret, char *infile, EVP_PKEY *pkey,
 | 
			
		||||
                         X509 *x509, const EVP_MD *dgst,
 | 
			
		||||
                         STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                         STACK_OF(CONF_VALUE) *policy, CA_DB *db,
 | 
			
		||||
                         BIGNUM *serial, char *subj, unsigned long chtype,
 | 
			
		||||
                         int multirdn, int email_dn, char *startdate,
 | 
			
		||||
@@ -225,12 +224,12 @@ static int certify_spkac(X509 **xret, char *infile, EVP_PKEY *pkey,
 | 
			
		||||
static void write_new_certificate(BIO *bp, X509 *x, int output_der,
 | 
			
		||||
                                  int notext);
 | 
			
		||||
static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                   STACK_OF(CONF_VALUE) *policy, CA_DB *db, BIGNUM *serial,
 | 
			
		||||
                   char *subj, unsigned long chtype, int multirdn,
 | 
			
		||||
                   int email_dn, char *startdate, char *enddate, long days,
 | 
			
		||||
                   int batch, int verbose, X509_REQ *req, char *ext_sect,
 | 
			
		||||
                   CONF *conf, unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(CONF_VALUE) *policy,
 | 
			
		||||
                   CA_DB *db, BIGNUM *serial, char *subj,
 | 
			
		||||
                   unsigned long chtype, int multirdn, int email_dn,
 | 
			
		||||
                   char *startdate, char *enddate, long days, int batch,
 | 
			
		||||
                   int verbose, X509_REQ *req, char *ext_sect, CONF *conf,
 | 
			
		||||
                   unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   int default_op, int ext_copy, int selfsign);
 | 
			
		||||
static int do_revoke(X509 *x509, CA_DB *db, int ext, char *extval);
 | 
			
		||||
static int get_certificate_status(const char *ser_status, CA_DB *db);
 | 
			
		||||
@@ -266,7 +265,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    int doupdatedb = 0;
 | 
			
		||||
    long crldays = 0;
 | 
			
		||||
    long crlhours = 0;
 | 
			
		||||
    long crlsec = 0;
 | 
			
		||||
    long errorline = -1;
 | 
			
		||||
    char *configfile = NULL;
 | 
			
		||||
    char *md = NULL;
 | 
			
		||||
@@ -314,13 +312,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    ASN1_TIME *tmptm;
 | 
			
		||||
    ASN1_INTEGER *tmpser;
 | 
			
		||||
    char *f;
 | 
			
		||||
    const char *p;
 | 
			
		||||
    char *const *pp;
 | 
			
		||||
    const char *p, **pp;
 | 
			
		||||
    int i, j;
 | 
			
		||||
    const EVP_MD *dgst = NULL;
 | 
			
		||||
    STACK_OF(CONF_VALUE) *attribs = NULL;
 | 
			
		||||
    STACK_OF(X509) *cert_sk = NULL;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *sigopts = NULL;
 | 
			
		||||
#undef BSIZE
 | 
			
		||||
#define BSIZE 256
 | 
			
		||||
    MS_STATIC char buf[3][BSIZE];
 | 
			
		||||
@@ -428,13 +424,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            outdir = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-sigopt") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            if (!sigopts)
 | 
			
		||||
                sigopts = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            if (!sigopts || !sk_OPENSSL_STRING_push(sigopts, *(++argv)))
 | 
			
		||||
                goto bad;
 | 
			
		||||
        } else if (strcmp(*argv, "-notext") == 0)
 | 
			
		||||
            notext = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-batch") == 0)
 | 
			
		||||
@@ -455,10 +444,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            crlhours = atol(*(++argv));
 | 
			
		||||
        } else if (strcmp(*argv, "-crlsec") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            crlsec = atol(*(++argv));
 | 
			
		||||
        } else if (strcmp(*argv, "-infiles") == 0) {
 | 
			
		||||
            argc--;
 | 
			
		||||
            argv++;
 | 
			
		||||
@@ -479,11 +464,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            infile = *(++argv);
 | 
			
		||||
            dorevoke = 1;
 | 
			
		||||
        } else if (strcmp(*argv, "-valid") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            infile = *(++argv);
 | 
			
		||||
            dorevoke = 2;
 | 
			
		||||
        } else if (strcmp(*argv, "-extensions") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
@@ -541,10 +521,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (badops) {
 | 
			
		||||
        const char **pp2;
 | 
			
		||||
 | 
			
		||||
        for (pp2 = ca_usage; (*pp2 != NULL); pp2++)
 | 
			
		||||
            BIO_printf(bio_err, "%s", *pp2);
 | 
			
		||||
        for (pp = ca_usage; (*pp != NULL); pp++)
 | 
			
		||||
            BIO_printf(bio_err, "%s", *pp);
 | 
			
		||||
        goto err;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -664,7 +642,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        ERR_clear_error();
 | 
			
		||||
#ifdef RL_DEBUG
 | 
			
		||||
    if (!p)
 | 
			
		||||
        BIO_printf(bio_err, "DEBUG: unique_subject undefined\n");
 | 
			
		||||
        BIO_printf(bio_err, "DEBUG: unique_subject undefined\n", p);
 | 
			
		||||
#endif
 | 
			
		||||
#ifdef RL_DEBUG
 | 
			
		||||
    BIO_printf(bio_err, "DEBUG: configured unique_subject is %d\n",
 | 
			
		||||
@@ -794,6 +772,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        /*****************************************************************/
 | 
			
		||||
    /* lookup where to write new certificates */
 | 
			
		||||
    if ((outdir == NULL) && (req)) {
 | 
			
		||||
        struct stat sb;
 | 
			
		||||
 | 
			
		||||
        if ((outdir = NCONF_get_string(conf, section, ENV_NEW_CERTS_DIR))
 | 
			
		||||
            == NULL) {
 | 
			
		||||
@@ -812,23 +791,25 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
         * routines to convert the directory syntax to Unixly, and give that
 | 
			
		||||
         * to access().  However, time's too short to do that just now.
 | 
			
		||||
         */
 | 
			
		||||
# ifndef _WIN32
 | 
			
		||||
        if (access(outdir, R_OK | W_OK | X_OK) != 0)
 | 
			
		||||
# else
 | 
			
		||||
        if (_access(outdir, R_OK | W_OK | X_OK) != 0)
 | 
			
		||||
# endif
 | 
			
		||||
        {
 | 
			
		||||
        if (access(outdir, R_OK | W_OK | X_OK) != 0) {
 | 
			
		||||
            BIO_printf(bio_err, "I am unable to access the %s directory\n",
 | 
			
		||||
                       outdir);
 | 
			
		||||
            perror(outdir);
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (app_isdir(outdir) <= 0) {
 | 
			
		||||
        if (stat(outdir, &sb) != 0) {
 | 
			
		||||
            BIO_printf(bio_err, "unable to stat(%s)\n", outdir);
 | 
			
		||||
            perror(outdir);
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
# ifdef S_ISDIR
 | 
			
		||||
        if (!S_ISDIR(sb.st_mode)) {
 | 
			
		||||
            BIO_printf(bio_err, "%s need to be a directory\n", outdir);
 | 
			
		||||
            perror(outdir);
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
# endif
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -843,8 +824,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    /* Lets check some fields */
 | 
			
		||||
    for (i = 0; i < sk_OPENSSL_PSTRING_num(db->db->data); i++) {
 | 
			
		||||
        pp = sk_OPENSSL_PSTRING_value(db->db->data, i);
 | 
			
		||||
    for (i = 0; i < sk_num(db->db->data); i++) {
 | 
			
		||||
        pp = (const char **)sk_value(db->db->data, i);
 | 
			
		||||
        if ((pp[DB_type][0] != DB_TYPE_REV) && (pp[DB_rev_date][0] != '\0')) {
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "entry %d: not revoked yet, but has a revocation date\n",
 | 
			
		||||
@@ -856,7 +837,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            BIO_printf(bio_err, " in entry %d\n", i + 1);
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
        if (!check_time_format((char *)pp[DB_exp_date])) {
 | 
			
		||||
        if (!check_time_format(pp[DB_exp_date])) {
 | 
			
		||||
            BIO_printf(bio_err, "entry %d: invalid expiry date\n", i + 1);
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
@@ -893,7 +874,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
#endif
 | 
			
		||||
        TXT_DB_write(out, db->db);
 | 
			
		||||
        BIO_printf(bio_err, "%d entries loaded from the database\n",
 | 
			
		||||
                   sk_OPENSSL_PSTRING_num(db->db->data));
 | 
			
		||||
                   db->db->data->num);
 | 
			
		||||
        BIO_printf(bio_err, "generating index\n");
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -927,7 +908,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
        /*****************************************************************/
 | 
			
		||||
    /* Read extensions config file                                   */
 | 
			
		||||
    /* Read extentions config file                                   */
 | 
			
		||||
    if (extfile) {
 | 
			
		||||
        extconf = NCONF_new(NULL);
 | 
			
		||||
        if (NCONF_load(extconf, extfile, &errorline) <= 0) {
 | 
			
		||||
@@ -978,15 +959,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto err;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!strcmp(md, "default")) {
 | 
			
		||||
        int def_nid;
 | 
			
		||||
        if (EVP_PKEY_get_default_digest_nid(pkey, &def_nid) <= 0) {
 | 
			
		||||
            BIO_puts(bio_err, "no default digest\n");
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
        md = (char *)OBJ_nid2sn(def_nid);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if ((dgst = EVP_get_digestbyname(md)) == NULL) {
 | 
			
		||||
        BIO_printf(bio_err, "%s is an unsupported message digest type\n", md);
 | 
			
		||||
        goto err;
 | 
			
		||||
@@ -1050,9 +1022,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (startdate == NULL)
 | 
			
		||||
                ERR_clear_error();
 | 
			
		||||
        }
 | 
			
		||||
        if (startdate && !ASN1_TIME_set_string(NULL, startdate)) {
 | 
			
		||||
        if (startdate && !ASN1_UTCTIME_set_string(NULL, startdate)) {
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "start date is invalid, it should be YYMMDDHHMMSSZ or YYYYMMDDHHMMSSZ\n");
 | 
			
		||||
                       "start date is invalid, it should be YYMMDDHHMMSSZ\n");
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
        if (startdate == NULL)
 | 
			
		||||
@@ -1063,9 +1035,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (enddate == NULL)
 | 
			
		||||
                ERR_clear_error();
 | 
			
		||||
        }
 | 
			
		||||
        if (enddate && !ASN1_TIME_set_string(NULL, enddate)) {
 | 
			
		||||
        if (enddate && !ASN1_UTCTIME_set_string(NULL, enddate)) {
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "end date is invalid, it should be YYMMDDHHMMSSZ or YYYYMMDDHHMMSSZ\n");
 | 
			
		||||
                       "end date is invalid, it should be YYMMDDHHMMSSZ\n");
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
@@ -1105,10 +1077,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
        if (spkac_file != NULL) {
 | 
			
		||||
            total++;
 | 
			
		||||
            j = certify_spkac(&x, spkac_file, pkey, x509, dgst, sigopts,
 | 
			
		||||
                              attribs, db, serial, subj, chtype, multirdn,
 | 
			
		||||
                              email_dn, startdate, enddate, days, extensions,
 | 
			
		||||
                              conf, verbose, certopt, nameopt, default_op,
 | 
			
		||||
            j = certify_spkac(&x, spkac_file, pkey, x509, dgst, attribs, db,
 | 
			
		||||
                              serial, subj, chtype, multirdn, email_dn,
 | 
			
		||||
                              startdate, enddate, days, extensions, conf,
 | 
			
		||||
                              verbose, certopt, nameopt, default_op,
 | 
			
		||||
                              ext_copy);
 | 
			
		||||
            if (j < 0)
 | 
			
		||||
                goto err;
 | 
			
		||||
@@ -1129,8 +1101,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
        if (ss_cert_file != NULL) {
 | 
			
		||||
            total++;
 | 
			
		||||
            j = certify_cert(&x, ss_cert_file, pkey, x509, dgst, sigopts,
 | 
			
		||||
                             attribs,
 | 
			
		||||
            j = certify_cert(&x, ss_cert_file, pkey, x509, dgst, attribs,
 | 
			
		||||
                             db, serial, subj, chtype, multirdn, email_dn,
 | 
			
		||||
                             startdate, enddate, days, batch, extensions,
 | 
			
		||||
                             conf, verbose, certopt, nameopt, default_op,
 | 
			
		||||
@@ -1150,7 +1121,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
        if (infile != NULL) {
 | 
			
		||||
            total++;
 | 
			
		||||
            j = certify(&x, infile, pkey, x509p, dgst, sigopts, attribs, db,
 | 
			
		||||
            j = certify(&x, infile, pkey, x509p, dgst, attribs, db,
 | 
			
		||||
                        serial, subj, chtype, multirdn, email_dn, startdate,
 | 
			
		||||
                        enddate, days, batch, extensions, conf, verbose,
 | 
			
		||||
                        certopt, nameopt, default_op, ext_copy, selfsign);
 | 
			
		||||
@@ -1169,7 +1140,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
        for (i = 0; i < argc; i++) {
 | 
			
		||||
            total++;
 | 
			
		||||
            j = certify(&x, argv[i], pkey, x509p, dgst, sigopts, attribs, db,
 | 
			
		||||
            j = certify(&x, argv[i], pkey, x509p, dgst, attribs, db,
 | 
			
		||||
                        serial, subj, chtype, multirdn, email_dn, startdate,
 | 
			
		||||
                        enddate, days, batch, extensions, conf, verbose,
 | 
			
		||||
                        certopt, nameopt, default_op, ext_copy, selfsign);
 | 
			
		||||
@@ -1314,16 +1285,15 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto err;
 | 
			
		||||
            }
 | 
			
		||||
 | 
			
		||||
        if (!crldays && !crlhours && !crlsec) {
 | 
			
		||||
        if (!crldays && !crlhours) {
 | 
			
		||||
            if (!NCONF_get_number(conf, section,
 | 
			
		||||
                                  ENV_DEFAULT_CRL_DAYS, &crldays))
 | 
			
		||||
                crldays = 0;
 | 
			
		||||
            if (!NCONF_get_number(conf, section,
 | 
			
		||||
                                  ENV_DEFAULT_CRL_HOURS, &crlhours))
 | 
			
		||||
                crlhours = 0;
 | 
			
		||||
            ERR_clear_error();
 | 
			
		||||
        }
 | 
			
		||||
        if ((crldays == 0) && (crlhours == 0) && (crlsec == 0)) {
 | 
			
		||||
        if ((crldays == 0) && (crlhours == 0)) {
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "cannot lookup how long until the next CRL is issued\n");
 | 
			
		||||
            goto err;
 | 
			
		||||
@@ -1341,17 +1311,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            goto err;
 | 
			
		||||
        X509_gmtime_adj(tmptm, 0);
 | 
			
		||||
        X509_CRL_set_lastUpdate(crl, tmptm);
 | 
			
		||||
        if (!X509_time_adj_ex(tmptm, crldays, crlhours * 60 * 60 + crlsec,
 | 
			
		||||
                              NULL)) {
 | 
			
		||||
            BIO_puts(bio_err, "error setting CRL nextUpdate\n");
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
        X509_gmtime_adj(tmptm, (crldays * 24 + crlhours) * 60 * 60);
 | 
			
		||||
        X509_CRL_set_nextUpdate(crl, tmptm);
 | 
			
		||||
 | 
			
		||||
        ASN1_TIME_free(tmptm);
 | 
			
		||||
 | 
			
		||||
        for (i = 0; i < sk_OPENSSL_PSTRING_num(db->db->data); i++) {
 | 
			
		||||
            pp = sk_OPENSSL_PSTRING_value(db->db->data, i);
 | 
			
		||||
        for (i = 0; i < sk_num(db->db->data); i++) {
 | 
			
		||||
            pp = (const char **)sk_value(db->db->data, i);
 | 
			
		||||
            if (pp[DB_type][0] == DB_TYPE_REV) {
 | 
			
		||||
                if ((r = X509_REVOKED_new()) == NULL)
 | 
			
		||||
                    goto err;
 | 
			
		||||
@@ -1381,6 +1347,15 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        /* we now have a CRL */
 | 
			
		||||
        if (verbose)
 | 
			
		||||
            BIO_printf(bio_err, "signing CRL\n");
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
        if (pkey->type == EVP_PKEY_DSA)
 | 
			
		||||
            dgst = EVP_dss1();
 | 
			
		||||
        else
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_ECDSA
 | 
			
		||||
        if (pkey->type == EVP_PKEY_EC)
 | 
			
		||||
            dgst = EVP_ecdsa();
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
        /* Add any extensions asked for */
 | 
			
		||||
 | 
			
		||||
@@ -1413,12 +1388,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (!save_serial(crlnumberfile, "new", crlnumber, NULL))
 | 
			
		||||
                goto err;
 | 
			
		||||
 | 
			
		||||
        if (crlnumber) {
 | 
			
		||||
            BN_free(crlnumber);
 | 
			
		||||
            crlnumber = NULL;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (!do_X509_CRL_sign(bio_err, crl, pkey, dgst, sigopts))
 | 
			
		||||
        if (!X509_CRL_sign(crl, pkey, dgst))
 | 
			
		||||
            goto err;
 | 
			
		||||
 | 
			
		||||
        PEM_write_bio_X509_CRL(Sout, crl);
 | 
			
		||||
@@ -1438,8 +1408,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            revcert = load_cert(bio_err, infile, FORMAT_PEM, NULL, e, infile);
 | 
			
		||||
            if (revcert == NULL)
 | 
			
		||||
                goto err;
 | 
			
		||||
            if (dorevoke == 2)
 | 
			
		||||
                rev_type = -1;
 | 
			
		||||
            j = do_revoke(revcert, db, rev_type, rev_arg);
 | 
			
		||||
            if (j <= 0)
 | 
			
		||||
                goto err;
 | 
			
		||||
@@ -1473,10 +1441,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (free_key && key)
 | 
			
		||||
        OPENSSL_free(key);
 | 
			
		||||
    BN_free(serial);
 | 
			
		||||
    BN_free(crlnumber);
 | 
			
		||||
    free_index(db);
 | 
			
		||||
    if (sigopts)
 | 
			
		||||
        sk_OPENSSL_STRING_free(sigopts);
 | 
			
		||||
    EVP_PKEY_free(pkey);
 | 
			
		||||
    if (x509)
 | 
			
		||||
        X509_free(x509);
 | 
			
		||||
@@ -1494,12 +1459,12 @@ static void lookup_fail(const char *name, const char *tag)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int certify(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                   STACK_OF(CONF_VALUE) *policy, CA_DB *db,
 | 
			
		||||
                   BIGNUM *serial, char *subj, unsigned long chtype,
 | 
			
		||||
                   int multirdn, int email_dn, char *startdate, char *enddate,
 | 
			
		||||
                   long days, int batch, char *ext_sect, CONF *lconf,
 | 
			
		||||
                   int verbose, unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(CONF_VALUE) *policy,
 | 
			
		||||
                   CA_DB *db, BIGNUM *serial, char *subj,
 | 
			
		||||
                   unsigned long chtype, int multirdn, int email_dn,
 | 
			
		||||
                   char *startdate, char *enddate, long days, int batch,
 | 
			
		||||
                   char *ext_sect, CONF *lconf, int verbose,
 | 
			
		||||
                   unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   int default_op, int ext_copy, int selfsign)
 | 
			
		||||
{
 | 
			
		||||
    X509_REQ *req = NULL;
 | 
			
		||||
@@ -1550,10 +1515,10 @@ static int certify(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
    } else
 | 
			
		||||
        BIO_printf(bio_err, "Signature ok\n");
 | 
			
		||||
 | 
			
		||||
    ok = do_body(xret, pkey, x509, dgst, sigopts, policy, db, serial, subj,
 | 
			
		||||
                 chtype, multirdn, email_dn, startdate, enddate, days, batch,
 | 
			
		||||
                 verbose, req, ext_sect, lconf, certopt, nameopt, default_op,
 | 
			
		||||
                 ext_copy, selfsign);
 | 
			
		||||
    ok = do_body(xret, pkey, x509, dgst, policy, db, serial, subj, chtype,
 | 
			
		||||
                 multirdn, email_dn, startdate, enddate, days, batch, verbose,
 | 
			
		||||
                 req, ext_sect, lconf, certopt, nameopt, default_op, ext_copy,
 | 
			
		||||
                 selfsign);
 | 
			
		||||
 | 
			
		||||
 err:
 | 
			
		||||
    if (req != NULL)
 | 
			
		||||
@@ -1564,14 +1529,13 @@ static int certify(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int certify_cert(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
                        const EVP_MD *dgst, STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                        STACK_OF(CONF_VALUE) *policy, CA_DB *db,
 | 
			
		||||
                        BIGNUM *serial, char *subj, unsigned long chtype,
 | 
			
		||||
                        int multirdn, int email_dn, char *startdate,
 | 
			
		||||
                        char *enddate, long days, int batch, char *ext_sect,
 | 
			
		||||
                        CONF *lconf, int verbose, unsigned long certopt,
 | 
			
		||||
                        unsigned long nameopt, int default_op, int ext_copy,
 | 
			
		||||
                        ENGINE *e)
 | 
			
		||||
                        const EVP_MD *dgst, STACK_OF(CONF_VALUE) *policy,
 | 
			
		||||
                        CA_DB *db, BIGNUM *serial, char *subj,
 | 
			
		||||
                        unsigned long chtype, int multirdn, int email_dn,
 | 
			
		||||
                        char *startdate, char *enddate, long days, int batch,
 | 
			
		||||
                        char *ext_sect, CONF *lconf, int verbose,
 | 
			
		||||
                        unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                        int default_op, int ext_copy, ENGINE *e)
 | 
			
		||||
{
 | 
			
		||||
    X509 *req = NULL;
 | 
			
		||||
    X509_REQ *rreq = NULL;
 | 
			
		||||
@@ -1607,9 +1571,9 @@ static int certify_cert(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
    if ((rreq = X509_to_X509_REQ(req, NULL, EVP_md5())) == NULL)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    ok = do_body(xret, pkey, x509, dgst, sigopts, policy, db, serial, subj,
 | 
			
		||||
                 chtype, multirdn, email_dn, startdate, enddate, days, batch,
 | 
			
		||||
                 verbose, rreq, ext_sect, lconf, certopt, nameopt, default_op,
 | 
			
		||||
    ok = do_body(xret, pkey, x509, dgst, policy, db, serial, subj, chtype,
 | 
			
		||||
                 multirdn, email_dn, startdate, enddate, days, batch, verbose,
 | 
			
		||||
                 rreq, ext_sect, lconf, certopt, nameopt, default_op,
 | 
			
		||||
                 ext_copy, 0);
 | 
			
		||||
 | 
			
		||||
 err:
 | 
			
		||||
@@ -1621,12 +1585,12 @@ static int certify_cert(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                   STACK_OF(CONF_VALUE) *policy, CA_DB *db, BIGNUM *serial,
 | 
			
		||||
                   char *subj, unsigned long chtype, int multirdn,
 | 
			
		||||
                   int email_dn, char *startdate, char *enddate, long days,
 | 
			
		||||
                   int batch, int verbose, X509_REQ *req, char *ext_sect,
 | 
			
		||||
                   CONF *lconf, unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   const EVP_MD *dgst, STACK_OF(CONF_VALUE) *policy,
 | 
			
		||||
                   CA_DB *db, BIGNUM *serial, char *subj,
 | 
			
		||||
                   unsigned long chtype, int multirdn, int email_dn,
 | 
			
		||||
                   char *startdate, char *enddate, long days, int batch,
 | 
			
		||||
                   int verbose, X509_REQ *req, char *ext_sect, CONF *lconf,
 | 
			
		||||
                   unsigned long certopt, unsigned long nameopt,
 | 
			
		||||
                   int default_op, int ext_copy, int selfsign)
 | 
			
		||||
{
 | 
			
		||||
    X509_NAME *name = NULL, *CAname = NULL, *subject = NULL, *dn_subject =
 | 
			
		||||
@@ -1642,9 +1606,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
    int ok = -1, i, j, last, nid;
 | 
			
		||||
    const char *p;
 | 
			
		||||
    CONF_VALUE *cv;
 | 
			
		||||
    OPENSSL_STRING row[DB_NUMBER];
 | 
			
		||||
    OPENSSL_STRING *irow = NULL;
 | 
			
		||||
    OPENSSL_STRING *rrow = NULL;
 | 
			
		||||
    char *row[DB_NUMBER], **rrow = NULL, **irow = NULL;
 | 
			
		||||
    char buf[25];
 | 
			
		||||
 | 
			
		||||
    tmptm = ASN1_UTCTIME_new();
 | 
			
		||||
@@ -1878,9 +1840,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (db->attributes.unique_subject) {
 | 
			
		||||
        OPENSSL_STRING *crow = row;
 | 
			
		||||
 | 
			
		||||
        rrow = TXT_DB_get_by_index(db->db, DB_name, crow);
 | 
			
		||||
        rrow = TXT_DB_get_by_index(db->db, DB_name, row);
 | 
			
		||||
        if (rrow != NULL) {
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "ERROR:There is already a certificate for %s\n",
 | 
			
		||||
@@ -1963,16 +1923,12 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
    if (strcmp(startdate, "today") == 0)
 | 
			
		||||
        X509_gmtime_adj(X509_get_notBefore(ret), 0);
 | 
			
		||||
    else
 | 
			
		||||
        ASN1_TIME_set_string(X509_get_notBefore(ret), startdate);
 | 
			
		||||
        ASN1_UTCTIME_set_string(X509_get_notBefore(ret), startdate);
 | 
			
		||||
 | 
			
		||||
    if (enddate == NULL)
 | 
			
		||||
        X509_time_adj_ex(X509_get_notAfter(ret), days, 0, NULL);
 | 
			
		||||
    else {
 | 
			
		||||
        int tdays;
 | 
			
		||||
        ASN1_TIME_set_string(X509_get_notAfter(ret), enddate);
 | 
			
		||||
        ASN1_TIME_diff(&tdays, NULL, NULL, X509_get_notAfter(ret));
 | 
			
		||||
        days = tdays;
 | 
			
		||||
    }
 | 
			
		||||
        X509_gmtime_adj(X509_get_notAfter(ret), (long)60 * 60 * 24 * days);
 | 
			
		||||
    else
 | 
			
		||||
        ASN1_UTCTIME_set_string(X509_get_notAfter(ret), enddate);
 | 
			
		||||
 | 
			
		||||
    if (!X509_set_subject_name(ret, subject))
 | 
			
		||||
        goto err;
 | 
			
		||||
@@ -2090,14 +2046,26 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509,
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
    if (pkey->type == EVP_PKEY_DSA)
 | 
			
		||||
        dgst = EVP_dss1();
 | 
			
		||||
    pktmp = X509_get_pubkey(ret);
 | 
			
		||||
    if (EVP_PKEY_missing_parameters(pktmp) &&
 | 
			
		||||
        !EVP_PKEY_missing_parameters(pkey))
 | 
			
		||||
        EVP_PKEY_copy_parameters(pktmp, pkey);
 | 
			
		||||
    EVP_PKEY_free(pktmp);
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_ECDSA
 | 
			
		||||
    if (pkey->type == EVP_PKEY_EC)
 | 
			
		||||
        dgst = EVP_ecdsa();
 | 
			
		||||
    pktmp = X509_get_pubkey(ret);
 | 
			
		||||
    if (EVP_PKEY_missing_parameters(pktmp) &&
 | 
			
		||||
        !EVP_PKEY_missing_parameters(pkey))
 | 
			
		||||
        EVP_PKEY_copy_parameters(pktmp, pkey);
 | 
			
		||||
    EVP_PKEY_free(pktmp);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    if (!do_X509_sign(bio_err, ret, pkey, dgst, sigopts))
 | 
			
		||||
    if (!X509_sign(ret, pkey, dgst))
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    /* We now just add it to the database */
 | 
			
		||||
@@ -2190,7 +2158,6 @@ static void write_new_certificate(BIO *bp, X509 *x, int output_der,
 | 
			
		||||
 | 
			
		||||
static int certify_spkac(X509 **xret, char *infile, EVP_PKEY *pkey,
 | 
			
		||||
                         X509 *x509, const EVP_MD *dgst,
 | 
			
		||||
                         STACK_OF(OPENSSL_STRING) *sigopts,
 | 
			
		||||
                         STACK_OF(CONF_VALUE) *policy, CA_DB *db,
 | 
			
		||||
                         BIGNUM *serial, char *subj, unsigned long chtype,
 | 
			
		||||
                         int multirdn, int email_dn, char *startdate,
 | 
			
		||||
@@ -2199,7 +2166,7 @@ static int certify_spkac(X509 **xret, char *infile, EVP_PKEY *pkey,
 | 
			
		||||
                         unsigned long nameopt, int default_op, int ext_copy)
 | 
			
		||||
{
 | 
			
		||||
    STACK_OF(CONF_VALUE) *sk = NULL;
 | 
			
		||||
    LHASH_OF(CONF_VALUE) *parms = NULL;
 | 
			
		||||
    LHASH *parms = NULL;
 | 
			
		||||
    X509_REQ *req = NULL;
 | 
			
		||||
    CONF_VALUE *cv = NULL;
 | 
			
		||||
    NETSCAPE_SPKI *spki = NULL;
 | 
			
		||||
@@ -2313,10 +2280,10 @@ static int certify_spkac(X509 **xret, char *infile, EVP_PKEY *pkey,
 | 
			
		||||
 | 
			
		||||
    X509_REQ_set_pubkey(req, pktmp);
 | 
			
		||||
    EVP_PKEY_free(pktmp);
 | 
			
		||||
    ok = do_body(xret, pkey, x509, dgst, sigopts, policy, db, serial, subj,
 | 
			
		||||
                 chtype, multirdn, email_dn, startdate, enddate, days, 1,
 | 
			
		||||
                 verbose, req, ext_sect, lconf, certopt, nameopt, default_op,
 | 
			
		||||
                 ext_copy, 0);
 | 
			
		||||
    ok = do_body(xret, pkey, x509, dgst, policy, db, serial, subj, chtype,
 | 
			
		||||
                 multirdn, email_dn, startdate, enddate, days, 1, verbose,
 | 
			
		||||
                 req, ext_sect, lconf, certopt, nameopt, default_op, ext_copy,
 | 
			
		||||
                 0);
 | 
			
		||||
 err:
 | 
			
		||||
    if (req != NULL)
 | 
			
		||||
        X509_REQ_free(req);
 | 
			
		||||
@@ -2332,7 +2299,15 @@ static int certify_spkac(X509 **xret, char *infile, EVP_PKEY *pkey,
 | 
			
		||||
 | 
			
		||||
static int check_time_format(const char *str)
 | 
			
		||||
{
 | 
			
		||||
    return ASN1_TIME_set_string(NULL, str);
 | 
			
		||||
    ASN1_TIME tm;
 | 
			
		||||
 | 
			
		||||
    tm.data = (unsigned char *)str;
 | 
			
		||||
    tm.length = strlen(str);
 | 
			
		||||
    tm.type = V_ASN1_UTCTIME;
 | 
			
		||||
    if (ASN1_TIME_check(&tm))
 | 
			
		||||
        return 1;
 | 
			
		||||
    tm.type = V_ASN1_GENERALIZEDTIME;
 | 
			
		||||
    return ASN1_TIME_check(&tm);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int do_revoke(X509 *x509, CA_DB *db, int type, char *value)
 | 
			
		||||
@@ -2347,8 +2322,6 @@ static int do_revoke(X509 *x509, CA_DB *db, int type, char *value)
 | 
			
		||||
        row[i] = NULL;
 | 
			
		||||
    row[DB_name] = X509_NAME_oneline(X509_get_subject_name(x509), NULL, 0);
 | 
			
		||||
    bn = ASN1_INTEGER_to_BN(X509_get_serialNumber(x509), NULL);
 | 
			
		||||
    if (!bn)
 | 
			
		||||
        goto err;
 | 
			
		||||
    if (BN_is_zero(bn))
 | 
			
		||||
        row[DB_serial] = BUF_strdup("00");
 | 
			
		||||
    else
 | 
			
		||||
@@ -2412,20 +2385,13 @@ static int do_revoke(X509 *x509, CA_DB *db, int type, char *value)
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        /* Revoke Certificate */
 | 
			
		||||
        if (type == -1)
 | 
			
		||||
            ok = 1;
 | 
			
		||||
        else
 | 
			
		||||
        ok = do_revoke(x509, db, type, value);
 | 
			
		||||
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    } else if (index_name_cmp_noconst(row, rrow)) {
 | 
			
		||||
    } else if (index_name_cmp((const char **)row, (const char **)rrow)) {
 | 
			
		||||
        BIO_printf(bio_err, "ERROR:name does not match %s\n", row[DB_name]);
 | 
			
		||||
        goto err;
 | 
			
		||||
    } else if (type == -1) {
 | 
			
		||||
        BIO_printf(bio_err, "ERROR:Already present, serial number %s\n",
 | 
			
		||||
                   row[DB_serial]);
 | 
			
		||||
        goto err;
 | 
			
		||||
    } else if (rrow[DB_type][0] == 'R') {
 | 
			
		||||
        BIO_printf(bio_err, "ERROR:Already revoked, serial number %s\n",
 | 
			
		||||
                   row[DB_serial]);
 | 
			
		||||
@@ -2483,7 +2449,7 @@ static int get_certificate_status(const char *serial, CA_DB *db)
 | 
			
		||||
 | 
			
		||||
    /* Make it Upper Case */
 | 
			
		||||
    for (i = 0; row[DB_serial][i] != '\0'; i++)
 | 
			
		||||
        row[DB_serial][i] = toupper((unsigned char)row[DB_serial][i]);
 | 
			
		||||
        row[DB_serial][i] = toupper(row[DB_serial][i]);
 | 
			
		||||
 | 
			
		||||
    ok = 1;
 | 
			
		||||
 | 
			
		||||
@@ -2547,8 +2513,8 @@ static int do_updatedb(CA_DB *db)
 | 
			
		||||
    else
 | 
			
		||||
        a_y2k = 0;
 | 
			
		||||
 | 
			
		||||
    for (i = 0; i < sk_OPENSSL_PSTRING_num(db->db->data); i++) {
 | 
			
		||||
        rrow = sk_OPENSSL_PSTRING_value(db->db->data, i);
 | 
			
		||||
    for (i = 0; i < sk_num(db->db->data); i++) {
 | 
			
		||||
        rrow = (char **)sk_value(db->db->data, i);
 | 
			
		||||
 | 
			
		||||
        if (rrow[DB_type][0] == 'V') {
 | 
			
		||||
            /* ignore entries that are not valid */
 | 
			
		||||
@@ -2787,14 +2753,24 @@ int old_entry_print(BIO *bp, ASN1_OBJECT *obj, ASN1_STRING *str)
 | 
			
		||||
 | 
			
		||||
    p = (char *)str->data;
 | 
			
		||||
    for (j = str->length; j > 0; j--) {
 | 
			
		||||
#ifdef CHARSET_EBCDIC
 | 
			
		||||
        if ((*p >= 0x20) && (*p <= 0x7e))
 | 
			
		||||
            BIO_printf(bp, "%c", os_toebcdic[*p]);
 | 
			
		||||
#else
 | 
			
		||||
        if ((*p >= ' ') && (*p <= '~'))
 | 
			
		||||
            BIO_printf(bp, "%c", *p);
 | 
			
		||||
#endif
 | 
			
		||||
        else if (*p & 0x80)
 | 
			
		||||
            BIO_printf(bp, "\\0x%02X", *p);
 | 
			
		||||
        else if ((unsigned char)*p == 0xf7)
 | 
			
		||||
            BIO_printf(bp, "^?");
 | 
			
		||||
#ifdef CHARSET_EBCDIC
 | 
			
		||||
        else
 | 
			
		||||
            BIO_printf(bp, "^%c", os_toebcdic[*p + 0x40]);
 | 
			
		||||
#else
 | 
			
		||||
        else
 | 
			
		||||
            BIO_printf(bp, "^%c", *p + '@');
 | 
			
		||||
#endif
 | 
			
		||||
        p++;
 | 
			
		||||
    }
 | 
			
		||||
    BIO_printf(bp, "'\n");
 | 
			
		||||
 
 | 
			
		||||
@@ -59,6 +59,9 @@
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <stdlib.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#ifdef OPENSSL_NO_STDIO
 | 
			
		||||
# define APPS_WIN16
 | 
			
		||||
#endif
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#include <openssl/ssl.h>
 | 
			
		||||
@@ -68,8 +71,8 @@
 | 
			
		||||
 | 
			
		||||
static const char *ciphers_usage[] = {
 | 
			
		||||
    "usage: ciphers args\n",
 | 
			
		||||
    " -v          - verbose mode, a textual listing of the SSL/TLS ciphers in OpenSSL\n",
 | 
			
		||||
    " -V          - even more verbose\n",
 | 
			
		||||
    " -v          - verbose mode, a textual listing of the ciphers in SSLeay\n",
 | 
			
		||||
    " -ssl2       - SSL2 mode\n",
 | 
			
		||||
    " -ssl3       - SSL3 mode\n",
 | 
			
		||||
    " -tls1       - TLS1 mode\n",
 | 
			
		||||
    NULL
 | 
			
		||||
@@ -80,23 +83,25 @@ int MAIN(int, char **);
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    int ret = 1, i;
 | 
			
		||||
    int verbose = 0, Verbose = 0;
 | 
			
		||||
    int use_supported = 0;
 | 
			
		||||
#ifndef OPENSSL_NO_SSL_TRACE
 | 
			
		||||
    int stdname = 0;
 | 
			
		||||
#endif
 | 
			
		||||
    int verbose = 0;
 | 
			
		||||
    const char **pp;
 | 
			
		||||
    const char *p;
 | 
			
		||||
    int badops = 0;
 | 
			
		||||
    SSL_CTX *ctx = NULL;
 | 
			
		||||
    SSL *ssl = NULL;
 | 
			
		||||
    char *ciphers = NULL;
 | 
			
		||||
    const SSL_METHOD *meth = NULL;
 | 
			
		||||
    STACK_OF(SSL_CIPHER) *sk = NULL;
 | 
			
		||||
    SSL_METHOD *meth = NULL;
 | 
			
		||||
    STACK_OF(SSL_CIPHER) *sk;
 | 
			
		||||
    char buf[512];
 | 
			
		||||
    BIO *STDout = NULL;
 | 
			
		||||
 | 
			
		||||
#if !defined(OPENSSL_NO_SSL2) && !defined(OPENSSL_NO_SSL3)
 | 
			
		||||
    meth = SSLv23_server_method();
 | 
			
		||||
#elif !defined(OPENSSL_NO_SSL3)
 | 
			
		||||
    meth = SSLv3_server_method();
 | 
			
		||||
#elif !defined(OPENSSL_NO_SSL2)
 | 
			
		||||
    meth = SSLv2_server_method();
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
@@ -109,21 +114,15 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        STDout = BIO_push(tmpbio, STDout);
 | 
			
		||||
    }
 | 
			
		||||
#endif
 | 
			
		||||
    if (!load_config(bio_err, NULL))
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    argc--;
 | 
			
		||||
    argv++;
 | 
			
		||||
    while (argc >= 1) {
 | 
			
		||||
        if (strcmp(*argv, "-v") == 0)
 | 
			
		||||
            verbose = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-V") == 0)
 | 
			
		||||
            verbose = Verbose = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-s") == 0)
 | 
			
		||||
            use_supported = 1;
 | 
			
		||||
#ifndef OPENSSL_NO_SSL_TRACE
 | 
			
		||||
        else if (strcmp(*argv, "-stdname") == 0)
 | 
			
		||||
            stdname = verbose = 1;
 | 
			
		||||
#ifndef OPENSSL_NO_SSL2
 | 
			
		||||
        else if (strcmp(*argv, "-ssl2") == 0)
 | 
			
		||||
            meth = SSLv2_client_method();
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_SSL3
 | 
			
		||||
        else if (strcmp(*argv, "-ssl3") == 0)
 | 
			
		||||
@@ -164,15 +163,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (ssl == NULL)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    if (use_supported)
 | 
			
		||||
        sk = SSL_get1_supported_ciphers(ssl);
 | 
			
		||||
    else
 | 
			
		||||
        sk = SSL_get_ciphers(ssl);
 | 
			
		||||
 | 
			
		||||
    if (!verbose) {
 | 
			
		||||
        for (i = 0; i < sk_SSL_CIPHER_num(sk); i++) {
 | 
			
		||||
            SSL_CIPHER *c = sk_SSL_CIPHER_value(sk, i);
 | 
			
		||||
            p = SSL_CIPHER_get_name(c);
 | 
			
		||||
        for (i = 0;; i++) {
 | 
			
		||||
            p = SSL_get_cipher_list(ssl, i);
 | 
			
		||||
            if (p == NULL)
 | 
			
		||||
                break;
 | 
			
		||||
            if (i != 0)
 | 
			
		||||
@@ -180,39 +173,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            BIO_printf(STDout, "%s", p);
 | 
			
		||||
        }
 | 
			
		||||
        BIO_printf(STDout, "\n");
 | 
			
		||||
    } else {                    /* verbose */
 | 
			
		||||
    } else {
 | 
			
		||||
        sk = SSL_get_ciphers(ssl);
 | 
			
		||||
 | 
			
		||||
        for (i = 0; i < sk_SSL_CIPHER_num(sk); i++) {
 | 
			
		||||
            SSL_CIPHER *c;
 | 
			
		||||
 | 
			
		||||
            c = sk_SSL_CIPHER_value(sk, i);
 | 
			
		||||
 | 
			
		||||
            if (Verbose) {
 | 
			
		||||
                unsigned long id = SSL_CIPHER_get_id(c);
 | 
			
		||||
                int id0 = (int)(id >> 24);
 | 
			
		||||
                int id1 = (int)((id >> 16) & 0xffL);
 | 
			
		||||
                int id2 = (int)((id >> 8) & 0xffL);
 | 
			
		||||
                int id3 = (int)(id & 0xffL);
 | 
			
		||||
 | 
			
		||||
                if ((id & 0xff000000L) == 0x03000000L) {
 | 
			
		||||
                    /* SSL3 cipher */
 | 
			
		||||
                    BIO_printf(STDout, "          0x%02X,0x%02X - ", id2,
 | 
			
		||||
                               id3);
 | 
			
		||||
                } else {
 | 
			
		||||
                    /* whatever */
 | 
			
		||||
                    BIO_printf(STDout, "0x%02X,0x%02X,0x%02X,0x%02X - ", id0,
 | 
			
		||||
                               id1, id2, id3);
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
#ifndef OPENSSL_NO_SSL_TRACE
 | 
			
		||||
            if (stdname) {
 | 
			
		||||
                const char *nm = SSL_CIPHER_standard_name(c);
 | 
			
		||||
                if (nm == NULL)
 | 
			
		||||
                    nm = "UNKNOWN";
 | 
			
		||||
                BIO_printf(STDout, "%s - ", nm);
 | 
			
		||||
            }
 | 
			
		||||
#endif
 | 
			
		||||
            BIO_puts(STDout, SSL_CIPHER_description(c, buf, sizeof buf));
 | 
			
		||||
            BIO_puts(STDout,
 | 
			
		||||
                     SSL_CIPHER_description(sk_SSL_CIPHER_value(sk, i), buf,
 | 
			
		||||
                                            sizeof buf));
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -223,8 +190,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
    }
 | 
			
		||||
 end:
 | 
			
		||||
    if (use_supported && sk)
 | 
			
		||||
        sk_SSL_CIPHER_free(sk);
 | 
			
		||||
    if (ctx != NULL)
 | 
			
		||||
        SSL_CTX_free(ctx);
 | 
			
		||||
    if (ssl != NULL)
 | 
			
		||||
 
 | 
			
		||||
@@ -1,52 +1,24 @@
 | 
			
		||||
subject= C = UK, O = OpenSSL Group, OU = FOR TESTING PURPOSES ONLY, CN = Test Client Cert
 | 
			
		||||
issuer= C = UK, O = OpenSSL Group, OU = FOR TESTING PURPOSES ONLY, CN = OpenSSL Test Intermediate CA
 | 
			
		||||
issuer= /C=AU/ST=Queensland/O=CryptSoft Pty Ltd/CN=Test CA (1024 bit)
 | 
			
		||||
subject=/C=AU/ST=Queensland/O=CryptSoft Pty Ltd/CN=Client test cert (512 bit)
 | 
			
		||||
-----BEGIN CERTIFICATE-----
 | 
			
		||||
MIID5zCCAs+gAwIBAgIJALnu1NlVpZ6yMA0GCSqGSIb3DQEBBQUAMHAxCzAJBgNV
 | 
			
		||||
BAYTAlVLMRYwFAYDVQQKDA1PcGVuU1NMIEdyb3VwMSIwIAYDVQQLDBlGT1IgVEVT
 | 
			
		||||
VElORyBQVVJQT1NFUyBPTkxZMSUwIwYDVQQDDBxPcGVuU1NMIFRlc3QgSW50ZXJt
 | 
			
		||||
ZWRpYXRlIENBMB4XDTExMTIwODE0MDE0OFoXDTIxMTAxNjE0MDE0OFowZDELMAkG
 | 
			
		||||
A1UEBhMCVUsxFjAUBgNVBAoMDU9wZW5TU0wgR3JvdXAxIjAgBgNVBAsMGUZPUiBU
 | 
			
		||||
RVNUSU5HIFBVUlBPU0VTIE9OTFkxGTAXBgNVBAMMEFRlc3QgQ2xpZW50IENlcnQw
 | 
			
		||||
ggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQC0ranbHRLcLVqN+0BzcZpY
 | 
			
		||||
+yOLqxzDWT1LD9eW1stC4NzXX9/DCtSIVyN7YIHdGLrIPr64IDdXXaMRzgZ2rOKs
 | 
			
		||||
lmHCAiFpO/ja99gGCJRxH0xwQatqAULfJVHeUhs7OEGOZc2nWifjqKvGfNTilP7D
 | 
			
		||||
nwi69ipQFq9oS19FmhwVHk2wg7KZGHI1qDyG04UrfCZMRitvS9+UVhPpIPjuiBi2
 | 
			
		||||
x3/FZIpL5gXJvvFK6xHY63oq2asyzBATntBgnP4qJFWWcvRx24wF1PnZabxuVoL2
 | 
			
		||||
bPnQ/KvONDrw3IdqkKhYNTul7jEcu3OlcZIMw+7DiaKJLAzKb/bBF5gm/pwW6As9
 | 
			
		||||
AgMBAAGjgY8wgYwwDAYDVR0TAQH/BAIwADAOBgNVHQ8BAf8EBAMCBeAwLAYJYIZI
 | 
			
		||||
AYb4QgENBB8WHU9wZW5TU0wgR2VuZXJhdGVkIENlcnRpZmljYXRlMB0GA1UdDgQW
 | 
			
		||||
BBSZHKyLoTh7Mb409Zn/mK1ceSDAjDAfBgNVHSMEGDAWgBQ2w2yI55X+sL3szj49
 | 
			
		||||
hqshgYfa2jANBgkqhkiG9w0BAQUFAAOCAQEAD0mL7PtPYgCEuDyOQSbLpeND5hVS
 | 
			
		||||
curxQdGnrJ6Acrhodb7E9ccATokeb0PLx6HBLQUicxhTZIQ9FbO43YkQcOU6C3BB
 | 
			
		||||
IlwskqmtN6+VmrQzNolHCDzvxNZs9lYL2VbGPGqVRyjZeHpoAlf9cQr8PgDb4d4b
 | 
			
		||||
vUx2KAhHQvV2nkmYvKyXcgnRuHggumF87mkxidriGAEFwH4qfOqetUg64WyxP7P2
 | 
			
		||||
QLipm04SyQa7ONtIApfVXgHcE42Py4/f4arzCzMjKe3VyhGkS7nsT55X/fWgTaRm
 | 
			
		||||
CQPkO+H94P958WTvQDt77bQ+D3IvYaVvfil8n6HJMOJfFT0LJuSUbpSXJg==
 | 
			
		||||
MIIB6TCCAVICAQIwDQYJKoZIhvcNAQEEBQAwWzELMAkGA1UEBhMCQVUxEzARBgNV
 | 
			
		||||
BAgTClF1ZWVuc2xhbmQxGjAYBgNVBAoTEUNyeXB0U29mdCBQdHkgTHRkMRswGQYD
 | 
			
		||||
VQQDExJUZXN0IENBICgxMDI0IGJpdCkwHhcNOTcwNjA5MTM1NzU2WhcNOTgwNjA5
 | 
			
		||||
MTM1NzU2WjBjMQswCQYDVQQGEwJBVTETMBEGA1UECBMKUXVlZW5zbGFuZDEaMBgG
 | 
			
		||||
A1UEChMRQ3J5cHRTb2Z0IFB0eSBMdGQxIzAhBgNVBAMTGkNsaWVudCB0ZXN0IGNl
 | 
			
		||||
cnQgKDUxMiBiaXQpMFwwDQYJKoZIhvcNAQEBBQADSwAwSAJBALtv55QyzG6i2Plw
 | 
			
		||||
Z1pah7++Gv8L5j6Hnyr/uTZE1NLG0ABDDexmq/R4KedLjFEIYjocDui+IXs62NNt
 | 
			
		||||
XrT8odkCAwEAATANBgkqhkiG9w0BAQQFAAOBgQBwtMmI7oGUG8nKmftQssATViH5
 | 
			
		||||
NRRtoEw07DxJp/LfatHdrhqQB73eGdL5WILZJXk46Xz2e9WMSUjVCSYhdKxtflU3
 | 
			
		||||
UR2Ajv1Oo0sTNdfz0wDqJNirLNtzyhhsaq8qMTrLwXrCP31VxBiigFSQSUFnZyTE
 | 
			
		||||
9TKwhS4GlwbtCfxSKQ==
 | 
			
		||||
-----END CERTIFICATE-----
 | 
			
		||||
-----BEGIN RSA PRIVATE KEY-----
 | 
			
		||||
MIIEpQIBAAKCAQEAtK2p2x0S3C1ajftAc3GaWPsji6scw1k9Sw/XltbLQuDc11/f
 | 
			
		||||
wwrUiFcje2CB3Ri6yD6+uCA3V12jEc4GdqzirJZhwgIhaTv42vfYBgiUcR9McEGr
 | 
			
		||||
agFC3yVR3lIbOzhBjmXNp1on46irxnzU4pT+w58IuvYqUBavaEtfRZocFR5NsIOy
 | 
			
		||||
mRhyNag8htOFK3wmTEYrb0vflFYT6SD47ogYtsd/xWSKS+YFyb7xSusR2Ot6Ktmr
 | 
			
		||||
MswQE57QYJz+KiRVlnL0cduMBdT52Wm8blaC9mz50PyrzjQ68NyHapCoWDU7pe4x
 | 
			
		||||
HLtzpXGSDMPuw4miiSwMym/2wReYJv6cFugLPQIDAQABAoIBAAZOyc9MhIwLSU4L
 | 
			
		||||
p4RgQvM4UVVe8/Id+3XTZ8NsXExJbWxXfIhiqGjaIfL8u4vsgRjcl+v1s/jo2/iT
 | 
			
		||||
KMab4o4D8gXD7UavQVDjtjb/ta79WL3SjRl2Uc9YjjMkyq6WmDNQeo2NKDdafCTB
 | 
			
		||||
1uzSJtLNipB8Z53ELPuHJhxX9QMHrMnuha49riQgXZ7buP9iQrHJFhImBjSzbxJx
 | 
			
		||||
L+TI6rkyLSf9Wi0Pd3L27Ob3QWNfNRYNSeTE+08eSRChkur5W0RuXAcuAICdQlCl
 | 
			
		||||
LBvWO/LmmvbzCqiDcgy/TliSb6CGGwgiNG7LJZmlkYNj8laGwalNlYZs3UrVv6NO
 | 
			
		||||
Br2loAECgYEA2kvCvPGj0Dg/6g7WhXDvAkEbcaL1tSeCxBbNH+6HS2UWMWvyTtCn
 | 
			
		||||
/bbD519QIdkvayy1QjEf32GV/UjUVmlULMLBcDy0DGjtL3+XpIhLKWDNxN1v1/ai
 | 
			
		||||
1oz23ZJCOgnk6K4qtFtlRS1XtynjA+rBetvYvLP9SKeFrnpzCgaA2r0CgYEA0+KX
 | 
			
		||||
1ACXDTNH5ySX3kMjSS9xdINf+OOw4CvPHFwbtc9aqk2HePlEsBTz5I/W3rKwXva3
 | 
			
		||||
NqZ/bRqVVeZB/hHKFywgdUQk2Uc5z/S7Lw70/w1HubNTXGU06Ngb6zOFAo/o/TwZ
 | 
			
		||||
zTP1BMIKSOB6PAZPS3l+aLO4FRIRotfFhgRHOoECgYEAmiZbqt8cJaJDB/5YYDzC
 | 
			
		||||
mp3tSk6gIb936Q6M5VqkMYp9pIKsxhk0N8aDCnTU+kIK6SzWBpr3/d9Ecmqmfyq7
 | 
			
		||||
5SvWO3KyVf0WWK9KH0abhOm2BKm2HBQvI0DB5u8sUx2/hsvOnjPYDISbZ11t0MtK
 | 
			
		||||
u35Zy89yMYcSsIYJjG/ROCUCgYEAgI2P9G5PNxEP5OtMwOsW84Y3Xat/hPAQFlI+
 | 
			
		||||
HES+AzbFGWJkeT8zL2nm95tVkFP1sggZ7Kxjz3w7cpx7GX0NkbWSE9O+T51pNASV
 | 
			
		||||
tN1sQ3p5M+/a+cnlqgfEGJVvc7iAcXQPa3LEi5h2yPR49QYXAgG6cifn3dDSpmwn
 | 
			
		||||
SUI7PQECgYEApGCIIpSRPLAEHTGmP87RBL1smurhwmy2s/pghkvUkWehtxg0sGHh
 | 
			
		||||
kuaqDWcskogv+QC0sVdytiLSz8G0DwcEcsHK1Fkyb8A+ayiw6jWJDo2m9+IF4Fww
 | 
			
		||||
1Te6jFPYDESnbhq7+TLGgHGhtwcu5cnb4vSuYXGXKupZGzoLOBbv1Zw=
 | 
			
		||||
MIIBOwIBAAJBALtv55QyzG6i2PlwZ1pah7++Gv8L5j6Hnyr/uTZE1NLG0ABDDexm
 | 
			
		||||
q/R4KedLjFEIYjocDui+IXs62NNtXrT8odkCAwEAAQJAbwXq0vJ/+uyEvsNgxLko
 | 
			
		||||
/V86mGXQ/KrSkeKlL0r4ENxjcyeMAGoKu6J9yMY7+X9+Zm4nxShNfTsf/+Freoe1
 | 
			
		||||
HQIhAPOSm5Q1YI+KIsII2GeVJx1U69+wnd71OasIPakS1L1XAiEAxQAW+J3/JWE0
 | 
			
		||||
ftEYakbhUOKL8tD1OaFZS71/5GdG7E8CIQCefUMmySSvwd6kC0VlATSWbW+d+jp/
 | 
			
		||||
nWmM1KvqnAo5uQIhALqEADu5U1Wvt8UN8UDGBRPQulHWNycuNV45d3nnskWPAiAw
 | 
			
		||||
ueTyr6WsZ5+SD8g/Hy3xuvF3nPmJRH+rwvVihlcFOg==
 | 
			
		||||
-----END RSA PRIVATE KEY-----
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										284
									
								
								apps/cms.c
									
									
									
									
									
								
							
							
						
						
									
										284
									
								
								apps/cms.c
									
									
									
									
									
								
							@@ -72,11 +72,9 @@
 | 
			
		||||
static int save_certs(char *signerfile, STACK_OF(X509) *signers);
 | 
			
		||||
static int cms_cb(int ok, X509_STORE_CTX *ctx);
 | 
			
		||||
static void receipt_request_print(BIO *out, CMS_ContentInfo *cms);
 | 
			
		||||
static CMS_ReceiptRequest *make_receipt_request(STACK_OF(OPENSSL_STRING)
 | 
			
		||||
                                                *rr_to, int rr_allorfirst, STACK_OF(OPENSSL_STRING)
 | 
			
		||||
                                                *rr_from);
 | 
			
		||||
static int cms_set_pkey_param(EVP_PKEY_CTX *pctx,
 | 
			
		||||
                              STACK_OF(OPENSSL_STRING) *param);
 | 
			
		||||
static CMS_ReceiptRequest *make_receipt_request(STACK * rr_to,
 | 
			
		||||
                                                int rr_allorfirst,
 | 
			
		||||
                                                STACK * rr_from);
 | 
			
		||||
 | 
			
		||||
# define SMIME_OP        0x10
 | 
			
		||||
# define SMIME_IP        0x20
 | 
			
		||||
@@ -98,16 +96,6 @@ static int cms_set_pkey_param(EVP_PKEY_CTX *pctx,
 | 
			
		||||
# define SMIME_SIGN_RECEIPT      (15 | SMIME_IP | SMIME_OP)
 | 
			
		||||
# define SMIME_VERIFY_RECEIPT    (16 | SMIME_IP)
 | 
			
		||||
 | 
			
		||||
int verify_err = 0;
 | 
			
		||||
 | 
			
		||||
typedef struct cms_key_param_st cms_key_param;
 | 
			
		||||
 | 
			
		||||
struct cms_key_param_st {
 | 
			
		||||
    int idx;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *param;
 | 
			
		||||
    cms_key_param *next;
 | 
			
		||||
};
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
@@ -119,10 +107,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    const char *inmode = "r", *outmode = "w";
 | 
			
		||||
    char *infile = NULL, *outfile = NULL, *rctfile = NULL;
 | 
			
		||||
    char *signerfile = NULL, *recipfile = NULL;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *sksigners = NULL, *skkeys = NULL;
 | 
			
		||||
    STACK *sksigners = NULL, *skkeys = NULL;
 | 
			
		||||
    char *certfile = NULL, *keyfile = NULL, *contfile = NULL;
 | 
			
		||||
    char *certsoutfile = NULL;
 | 
			
		||||
    const EVP_CIPHER *cipher = NULL, *wrap_cipher = NULL;
 | 
			
		||||
    const EVP_CIPHER *cipher = NULL;
 | 
			
		||||
    CMS_ContentInfo *cms = NULL, *rcms = NULL;
 | 
			
		||||
    X509_STORE *store = NULL;
 | 
			
		||||
    X509 *cert = NULL, *recip = NULL, *signer = NULL;
 | 
			
		||||
@@ -130,10 +118,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    STACK_OF(X509) *encerts = NULL, *other = NULL;
 | 
			
		||||
    BIO *in = NULL, *out = NULL, *indata = NULL, *rctin = NULL;
 | 
			
		||||
    int badarg = 0;
 | 
			
		||||
    int flags = CMS_DETACHED, noout = 0, print = 0;
 | 
			
		||||
    int verify_retcode = 0;
 | 
			
		||||
    int flags = CMS_DETACHED;
 | 
			
		||||
    int rr_print = 0, rr_allorfirst = -1;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *rr_to = NULL, *rr_from = NULL;
 | 
			
		||||
    STACK *rr_to = NULL, *rr_from = NULL;
 | 
			
		||||
    CMS_ReceiptRequest *rr = NULL;
 | 
			
		||||
    char *to = NULL, *from = NULL, *subject = NULL;
 | 
			
		||||
    char *CAfile = NULL, *CApath = NULL;
 | 
			
		||||
@@ -147,11 +134,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
# endif
 | 
			
		||||
    unsigned char *secret_key = NULL, *secret_keyid = NULL;
 | 
			
		||||
    unsigned char *pwri_pass = NULL, *pwri_tmp = NULL;
 | 
			
		||||
    size_t secret_keylen = 0, secret_keyidlen = 0;
 | 
			
		||||
 | 
			
		||||
    cms_key_param *key_first = NULL, *key_param = NULL;
 | 
			
		||||
 | 
			
		||||
    ASN1_OBJECT *econtent_type = NULL;
 | 
			
		||||
 | 
			
		||||
    X509_VERIFY_PARAM *vpm = NULL;
 | 
			
		||||
@@ -182,8 +166,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            operation = SMIME_RESIGN;
 | 
			
		||||
        else if (!strcmp(*args, "-verify"))
 | 
			
		||||
            operation = SMIME_VERIFY;
 | 
			
		||||
        else if (!strcmp(*args, "-verify_retcode"))
 | 
			
		||||
            verify_retcode = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-verify_receipt")) {
 | 
			
		||||
            operation = SMIME_VERIFY_RECEIPT;
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
@@ -213,8 +195,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            cipher = EVP_des_ede3_cbc();
 | 
			
		||||
        else if (!strcmp(*args, "-des"))
 | 
			
		||||
            cipher = EVP_des_cbc();
 | 
			
		||||
        else if (!strcmp(*args, "-des3-wrap"))
 | 
			
		||||
            wrap_cipher = EVP_des_ede3_wrap();
 | 
			
		||||
# endif
 | 
			
		||||
# ifndef OPENSSL_NO_SEED
 | 
			
		||||
        else if (!strcmp(*args, "-seed"))
 | 
			
		||||
@@ -235,12 +215,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            cipher = EVP_aes_192_cbc();
 | 
			
		||||
        else if (!strcmp(*args, "-aes256"))
 | 
			
		||||
            cipher = EVP_aes_256_cbc();
 | 
			
		||||
        else if (!strcmp(*args, "-aes128-wrap"))
 | 
			
		||||
            wrap_cipher = EVP_aes_128_wrap();
 | 
			
		||||
        else if (!strcmp(*args, "-aes192-wrap"))
 | 
			
		||||
            wrap_cipher = EVP_aes_192_wrap();
 | 
			
		||||
        else if (!strcmp(*args, "-aes256-wrap"))
 | 
			
		||||
            wrap_cipher = EVP_aes_256_wrap();
 | 
			
		||||
# endif
 | 
			
		||||
# ifndef OPENSSL_NO_CAMELLIA
 | 
			
		||||
        else if (!strcmp(*args, "-camellia128"))
 | 
			
		||||
@@ -254,8 +228,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            flags |= CMS_DEBUG_DECRYPT;
 | 
			
		||||
        else if (!strcmp(*args, "-text"))
 | 
			
		||||
            flags |= CMS_TEXT;
 | 
			
		||||
        else if (!strcmp(*args, "-asciicrlf"))
 | 
			
		||||
            flags |= CMS_ASCIICRLF;
 | 
			
		||||
        else if (!strcmp(*args, "-nointern"))
 | 
			
		||||
            flags |= CMS_NOINTERN;
 | 
			
		||||
        else if (!strcmp(*args, "-noverify")
 | 
			
		||||
@@ -279,18 +251,18 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            flags |= CMS_NO_CONTENT_VERIFY;
 | 
			
		||||
        else if (!strcmp(*args, "-no_attr_verify"))
 | 
			
		||||
            flags |= CMS_NO_ATTR_VERIFY;
 | 
			
		||||
        else if (!strcmp(*args, "-stream"))
 | 
			
		||||
            flags |= CMS_STREAM;
 | 
			
		||||
        else if (!strcmp(*args, "-indef"))
 | 
			
		||||
            flags |= CMS_STREAM;
 | 
			
		||||
        else if (!strcmp(*args, "-noindef"))
 | 
			
		||||
        else if (!strcmp(*args, "-stream")) {
 | 
			
		||||
            args++;
 | 
			
		||||
            continue;
 | 
			
		||||
        } else if (!strcmp(*args, "-indef")) {
 | 
			
		||||
            args++;
 | 
			
		||||
            continue;
 | 
			
		||||
        } else if (!strcmp(*args, "-noindef"))
 | 
			
		||||
            flags &= ~CMS_STREAM;
 | 
			
		||||
        else if (!strcmp(*args, "-nooldmime"))
 | 
			
		||||
            flags |= CMS_NOOLDMIMETYPE;
 | 
			
		||||
        else if (!strcmp(*args, "-crlfeol"))
 | 
			
		||||
            flags |= CMS_CRLFEOL;
 | 
			
		||||
        else if (!strcmp(*args, "-noout"))
 | 
			
		||||
            noout = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-receipt_request_print"))
 | 
			
		||||
            rr_print = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-receipt_request_all"))
 | 
			
		||||
@@ -302,18 +274,15 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            args++;
 | 
			
		||||
            if (!rr_from)
 | 
			
		||||
                rr_from = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            sk_OPENSSL_STRING_push(rr_from, *args);
 | 
			
		||||
                rr_from = sk_new_null();
 | 
			
		||||
            sk_push(rr_from, *args);
 | 
			
		||||
        } else if (!strcmp(*args, "-receipt_request_to")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            args++;
 | 
			
		||||
            if (!rr_to)
 | 
			
		||||
                rr_to = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            sk_OPENSSL_STRING_push(rr_to, *args);
 | 
			
		||||
        } else if (!strcmp(*args, "-print")) {
 | 
			
		||||
            noout = 1;
 | 
			
		||||
            print = 1;
 | 
			
		||||
                rr_to = sk_new_null();
 | 
			
		||||
            sk_push(rr_to, *args);
 | 
			
		||||
        } else if (!strcmp(*args, "-secretkey")) {
 | 
			
		||||
            long ltmp;
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
@@ -336,11 +305,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            }
 | 
			
		||||
            secret_keyidlen = (size_t)ltmp;
 | 
			
		||||
        } else if (!strcmp(*args, "-pwri_password")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            args++;
 | 
			
		||||
            pwri_pass = (unsigned char *)*args;
 | 
			
		||||
        } else if (!strcmp(*args, "-econtent_type")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto argerr;
 | 
			
		||||
@@ -387,29 +351,19 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
            if (signerfile) {
 | 
			
		||||
                if (!sksigners)
 | 
			
		||||
                    sksigners = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                sk_OPENSSL_STRING_push(sksigners, signerfile);
 | 
			
		||||
                    sksigners = sk_new_null();
 | 
			
		||||
                sk_push(sksigners, signerfile);
 | 
			
		||||
                if (!keyfile)
 | 
			
		||||
                    keyfile = signerfile;
 | 
			
		||||
                if (!skkeys)
 | 
			
		||||
                    skkeys = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                sk_OPENSSL_STRING_push(skkeys, keyfile);
 | 
			
		||||
                    skkeys = sk_new_null();
 | 
			
		||||
                sk_push(skkeys, keyfile);
 | 
			
		||||
                keyfile = NULL;
 | 
			
		||||
            }
 | 
			
		||||
            signerfile = *++args;
 | 
			
		||||
        } else if (!strcmp(*args, "-recip")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            if (operation == SMIME_ENCRYPT) {
 | 
			
		||||
                if (!encerts)
 | 
			
		||||
                    encerts = sk_X509_new_null();
 | 
			
		||||
                cert = load_cert(bio_err, *++args, FORMAT_PEM,
 | 
			
		||||
                                 NULL, e, "recipient certificate file");
 | 
			
		||||
                if (!cert)
 | 
			
		||||
                    goto end;
 | 
			
		||||
                sk_X509_push(encerts, cert);
 | 
			
		||||
                cert = NULL;
 | 
			
		||||
            } else
 | 
			
		||||
            recipfile = *++args;
 | 
			
		||||
        } else if (!strcmp(*args, "-certsout")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
@@ -433,48 +387,18 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                    goto argerr;
 | 
			
		||||
                }
 | 
			
		||||
                if (!sksigners)
 | 
			
		||||
                    sksigners = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                sk_OPENSSL_STRING_push(sksigners, signerfile);
 | 
			
		||||
                    sksigners = sk_new_null();
 | 
			
		||||
                sk_push(sksigners, signerfile);
 | 
			
		||||
                signerfile = NULL;
 | 
			
		||||
                if (!skkeys)
 | 
			
		||||
                    skkeys = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                sk_OPENSSL_STRING_push(skkeys, keyfile);
 | 
			
		||||
                    skkeys = sk_new_null();
 | 
			
		||||
                sk_push(skkeys, keyfile);
 | 
			
		||||
            }
 | 
			
		||||
            keyfile = *++args;
 | 
			
		||||
        } else if (!strcmp(*args, "-keyform")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            keyform = str2fmt(*++args);
 | 
			
		||||
        } else if (!strcmp(*args, "-keyopt")) {
 | 
			
		||||
            int keyidx = -1;
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            if (operation == SMIME_ENCRYPT) {
 | 
			
		||||
                if (encerts)
 | 
			
		||||
                    keyidx += sk_X509_num(encerts);
 | 
			
		||||
            } else {
 | 
			
		||||
                if (keyfile || signerfile)
 | 
			
		||||
                    keyidx++;
 | 
			
		||||
                if (skkeys)
 | 
			
		||||
                    keyidx += sk_OPENSSL_STRING_num(skkeys);
 | 
			
		||||
            }
 | 
			
		||||
            if (keyidx < 0) {
 | 
			
		||||
                BIO_printf(bio_err, "No key specified\n");
 | 
			
		||||
                goto argerr;
 | 
			
		||||
            }
 | 
			
		||||
            if (key_param == NULL || key_param->idx != keyidx) {
 | 
			
		||||
                cms_key_param *nparam;
 | 
			
		||||
                nparam = OPENSSL_malloc(sizeof(cms_key_param));
 | 
			
		||||
                nparam->idx = keyidx;
 | 
			
		||||
                nparam->param = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                nparam->next = NULL;
 | 
			
		||||
                if (key_first == NULL)
 | 
			
		||||
                    key_first = nparam;
 | 
			
		||||
                else
 | 
			
		||||
                    key_param->next = nparam;
 | 
			
		||||
                key_param = nparam;
 | 
			
		||||
            }
 | 
			
		||||
            sk_OPENSSL_STRING_push(key_param->param, *++args);
 | 
			
		||||
        } else if (!strcmp(*args, "-rctform")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto argerr;
 | 
			
		||||
@@ -540,13 +464,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        /* Check to see if any final signer needs to be appended */
 | 
			
		||||
        if (signerfile) {
 | 
			
		||||
            if (!sksigners)
 | 
			
		||||
                sksigners = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            sk_OPENSSL_STRING_push(sksigners, signerfile);
 | 
			
		||||
                sksigners = sk_new_null();
 | 
			
		||||
            sk_push(sksigners, signerfile);
 | 
			
		||||
            if (!skkeys)
 | 
			
		||||
                skkeys = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                skkeys = sk_new_null();
 | 
			
		||||
            if (!keyfile)
 | 
			
		||||
                keyfile = signerfile;
 | 
			
		||||
            sk_OPENSSL_STRING_push(skkeys, keyfile);
 | 
			
		||||
            sk_push(skkeys, keyfile);
 | 
			
		||||
        }
 | 
			
		||||
        if (!sksigners) {
 | 
			
		||||
            BIO_printf(bio_err, "No signer certificate specified\n");
 | 
			
		||||
@@ -558,13 +482,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    else if (operation == SMIME_DECRYPT) {
 | 
			
		||||
        if (!recipfile && !keyfile && !secret_key && !pwri_pass) {
 | 
			
		||||
        if (!recipfile && !keyfile && !secret_key) {
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "No recipient certificate or key specified\n");
 | 
			
		||||
            badarg = 1;
 | 
			
		||||
        }
 | 
			
		||||
    } else if (operation == SMIME_ENCRYPT) {
 | 
			
		||||
        if (!*args && !secret_key && !pwri_pass && !encerts) {
 | 
			
		||||
        if (!*args && !secret_key) {
 | 
			
		||||
            BIO_printf(bio_err, "No recipient(s) certificate(s) specified\n");
 | 
			
		||||
            badarg = 1;
 | 
			
		||||
        }
 | 
			
		||||
@@ -629,7 +553,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-inkey file    input private key (if not signer or recipient)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-keyform arg   input private key format (PEM or ENGINE)\n");
 | 
			
		||||
        BIO_printf(bio_err, "-keyopt nm:v   set public key parameters\n");
 | 
			
		||||
        BIO_printf(bio_err, "-out file      output file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-outform arg   output format SMIME (default), PEM or DER\n");
 | 
			
		||||
@@ -643,8 +566,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-CApath dir    trusted certificates directory\n");
 | 
			
		||||
        BIO_printf(bio_err, "-CAfile file   trusted certificates file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-trusted_first use locally trusted certificates first when building trust chain\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-crl_check     check revocation status of signer's certificate using CRLs\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
@@ -711,11 +632,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (secret_key && !secret_keyid) {
 | 
			
		||||
            BIO_printf(bio_err, "No secret key id\n");
 | 
			
		||||
            BIO_printf(bio_err, "No sectre key id\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (*args && !encerts)
 | 
			
		||||
        if (*args)
 | 
			
		||||
            encerts = sk_X509_new_null();
 | 
			
		||||
        while (*args) {
 | 
			
		||||
            if (!(cert = load_cert(bio_err, *args, FORMAT_PEM,
 | 
			
		||||
@@ -853,7 +774,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if ((operation == SMIME_VERIFY) || (operation == SMIME_VERIFY_RECEIPT)) {
 | 
			
		||||
        if (!(store = setup_verify(bio_err, CAfile, CApath)))
 | 
			
		||||
            goto end;
 | 
			
		||||
        X509_STORE_set_verify_cb(store, cms_cb);
 | 
			
		||||
        X509_STORE_set_verify_cb_func(store, cms_cb);
 | 
			
		||||
        if (vpm)
 | 
			
		||||
            X509_STORE_set1_param(store, vpm);
 | 
			
		||||
    }
 | 
			
		||||
@@ -867,39 +788,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    } else if (operation == SMIME_COMPRESS) {
 | 
			
		||||
        cms = CMS_compress(in, -1, flags);
 | 
			
		||||
    } else if (operation == SMIME_ENCRYPT) {
 | 
			
		||||
        int i;
 | 
			
		||||
        flags |= CMS_PARTIAL;
 | 
			
		||||
        cms = CMS_encrypt(NULL, in, cipher, flags);
 | 
			
		||||
        cms = CMS_encrypt(encerts, in, cipher, flags);
 | 
			
		||||
        if (!cms)
 | 
			
		||||
            goto end;
 | 
			
		||||
        for (i = 0; i < sk_X509_num(encerts); i++) {
 | 
			
		||||
            CMS_RecipientInfo *ri;
 | 
			
		||||
            cms_key_param *kparam;
 | 
			
		||||
            int tflags = flags;
 | 
			
		||||
            X509 *x = sk_X509_value(encerts, i);
 | 
			
		||||
            for (kparam = key_first; kparam; kparam = kparam->next) {
 | 
			
		||||
                if (kparam->idx == i) {
 | 
			
		||||
                    tflags |= CMS_KEY_PARAM;
 | 
			
		||||
                    break;
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
            ri = CMS_add1_recipient_cert(cms, x, tflags);
 | 
			
		||||
            if (!ri)
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (kparam) {
 | 
			
		||||
                EVP_PKEY_CTX *pctx;
 | 
			
		||||
                pctx = CMS_RecipientInfo_get0_pkey_ctx(ri);
 | 
			
		||||
                if (!cms_set_pkey_param(pctx, kparam->param))
 | 
			
		||||
                    goto end;
 | 
			
		||||
            }
 | 
			
		||||
            if (CMS_RecipientInfo_type(ri) == CMS_RECIPINFO_AGREE
 | 
			
		||||
                && wrap_cipher) {
 | 
			
		||||
                EVP_CIPHER_CTX *wctx;
 | 
			
		||||
                wctx = CMS_RecipientInfo_kari_get0_ctx(ri);
 | 
			
		||||
                EVP_EncryptInit_ex(wctx, wrap_cipher, NULL, NULL, NULL);
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (secret_key) {
 | 
			
		||||
            if (!CMS_add0_recipient_key(cms, NID_undef,
 | 
			
		||||
                                        secret_key, secret_keylen,
 | 
			
		||||
@@ -910,16 +802,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            secret_key = NULL;
 | 
			
		||||
            secret_keyid = NULL;
 | 
			
		||||
        }
 | 
			
		||||
        if (pwri_pass) {
 | 
			
		||||
            pwri_tmp = (unsigned char *)BUF_strdup((char *)pwri_pass);
 | 
			
		||||
            if (!pwri_tmp)
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (!CMS_add0_recipient_password(cms,
 | 
			
		||||
                                             -1, NID_undef, NID_undef,
 | 
			
		||||
                                             pwri_tmp, -1, NULL))
 | 
			
		||||
                goto end;
 | 
			
		||||
            pwri_tmp = NULL;
 | 
			
		||||
        }
 | 
			
		||||
        if (!(flags & CMS_STREAM)) {
 | 
			
		||||
            if (!CMS_final(cms, in, NULL, flags))
 | 
			
		||||
                goto end;
 | 
			
		||||
@@ -970,13 +852,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            }
 | 
			
		||||
        } else
 | 
			
		||||
            flags |= CMS_REUSE_DIGEST;
 | 
			
		||||
        for (i = 0; i < sk_OPENSSL_STRING_num(sksigners); i++) {
 | 
			
		||||
        for (i = 0; i < sk_num(sksigners); i++) {
 | 
			
		||||
            CMS_SignerInfo *si;
 | 
			
		||||
            cms_key_param *kparam;
 | 
			
		||||
            int tflags = flags;
 | 
			
		||||
            signerfile = sk_OPENSSL_STRING_value(sksigners, i);
 | 
			
		||||
            keyfile = sk_OPENSSL_STRING_value(skkeys, i);
 | 
			
		||||
 | 
			
		||||
            signerfile = sk_value(sksigners, i);
 | 
			
		||||
            keyfile = sk_value(skkeys, i);
 | 
			
		||||
            signer = load_cert(bio_err, signerfile, FORMAT_PEM, NULL,
 | 
			
		||||
                               e, "signer certificate");
 | 
			
		||||
            if (!signer)
 | 
			
		||||
@@ -985,21 +864,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                           "signing key file");
 | 
			
		||||
            if (!key)
 | 
			
		||||
                goto end;
 | 
			
		||||
            for (kparam = key_first; kparam; kparam = kparam->next) {
 | 
			
		||||
                if (kparam->idx == i) {
 | 
			
		||||
                    tflags |= CMS_KEY_PARAM;
 | 
			
		||||
                    break;
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
            si = CMS_add1_signer(cms, signer, key, sign_md, tflags);
 | 
			
		||||
            si = CMS_add1_signer(cms, signer, key, sign_md, flags);
 | 
			
		||||
            if (!si)
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (kparam) {
 | 
			
		||||
                EVP_PKEY_CTX *pctx;
 | 
			
		||||
                pctx = CMS_SignerInfo_get0_pkey_ctx(si);
 | 
			
		||||
                if (!cms_set_pkey_param(pctx, kparam->param))
 | 
			
		||||
                    goto end;
 | 
			
		||||
            }
 | 
			
		||||
            if (rr && !CMS_add1_ReceiptRequest(si, rr))
 | 
			
		||||
                goto end;
 | 
			
		||||
            X509_free(signer);
 | 
			
		||||
@@ -1040,13 +907,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (pwri_pass) {
 | 
			
		||||
            if (!CMS_decrypt_set1_password(cms, pwri_pass, -1)) {
 | 
			
		||||
                BIO_puts(bio_err, "Error decrypting CMS using password\n");
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (!CMS_decrypt(cms, NULL, NULL, indata, out, flags)) {
 | 
			
		||||
            BIO_printf(bio_err, "Error decrypting CMS structure\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
@@ -1073,8 +933,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            BIO_printf(bio_err, "Verification successful\n");
 | 
			
		||||
        else {
 | 
			
		||||
            BIO_printf(bio_err, "Verification failure\n");
 | 
			
		||||
            if (verify_retcode)
 | 
			
		||||
                ret = verify_err + 32;
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        if (signerfile) {
 | 
			
		||||
@@ -1099,10 +957,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        if (noout) {
 | 
			
		||||
            if (print)
 | 
			
		||||
                CMS_ContentInfo_print_ctx(out, cms, 0, NULL);
 | 
			
		||||
        } else if (outformat == FORMAT_SMIME) {
 | 
			
		||||
        if (outformat == FORMAT_SMIME) {
 | 
			
		||||
            if (to)
 | 
			
		||||
                BIO_printf(out, "To: %s\n", to);
 | 
			
		||||
            if (from)
 | 
			
		||||
@@ -1114,9 +969,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            else
 | 
			
		||||
                ret = SMIME_write_CMS(out, cms, in, flags);
 | 
			
		||||
        } else if (outformat == FORMAT_PEM)
 | 
			
		||||
            ret = PEM_write_bio_CMS_stream(out, cms, in, flags);
 | 
			
		||||
            ret = PEM_write_bio_CMS(out, cms);
 | 
			
		||||
        else if (outformat == FORMAT_ASN1)
 | 
			
		||||
            ret = i2d_CMS_bio_stream(out, cms, in, flags);
 | 
			
		||||
            ret = i2d_CMS_bio(out, cms);
 | 
			
		||||
        else {
 | 
			
		||||
            BIO_printf(bio_err, "Bad output format for CMS file\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
@@ -1137,30 +992,21 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (vpm)
 | 
			
		||||
        X509_VERIFY_PARAM_free(vpm);
 | 
			
		||||
    if (sksigners)
 | 
			
		||||
        sk_OPENSSL_STRING_free(sksigners);
 | 
			
		||||
        sk_free(sksigners);
 | 
			
		||||
    if (skkeys)
 | 
			
		||||
        sk_OPENSSL_STRING_free(skkeys);
 | 
			
		||||
        sk_free(skkeys);
 | 
			
		||||
    if (secret_key)
 | 
			
		||||
        OPENSSL_free(secret_key);
 | 
			
		||||
    if (secret_keyid)
 | 
			
		||||
        OPENSSL_free(secret_keyid);
 | 
			
		||||
    if (pwri_tmp)
 | 
			
		||||
        OPENSSL_free(pwri_tmp);
 | 
			
		||||
    if (econtent_type)
 | 
			
		||||
        ASN1_OBJECT_free(econtent_type);
 | 
			
		||||
    if (rr)
 | 
			
		||||
        CMS_ReceiptRequest_free(rr);
 | 
			
		||||
    if (rr_to)
 | 
			
		||||
        sk_OPENSSL_STRING_free(rr_to);
 | 
			
		||||
        sk_free(rr_to);
 | 
			
		||||
    if (rr_from)
 | 
			
		||||
        sk_OPENSSL_STRING_free(rr_from);
 | 
			
		||||
    for (key_param = key_first; key_param;) {
 | 
			
		||||
        cms_key_param *tparam;
 | 
			
		||||
        sk_OPENSSL_STRING_free(key_param->param);
 | 
			
		||||
        tparam = key_param->next;
 | 
			
		||||
        OPENSSL_free(key_param);
 | 
			
		||||
        key_param = tparam;
 | 
			
		||||
    }
 | 
			
		||||
        sk_free(rr_from);
 | 
			
		||||
    X509_STORE_free(store);
 | 
			
		||||
    X509_free(cert);
 | 
			
		||||
    X509_free(recip);
 | 
			
		||||
@@ -1200,8 +1046,6 @@ static int cms_cb(int ok, X509_STORE_CTX *ctx)
 | 
			
		||||
 | 
			
		||||
    error = X509_STORE_CTX_get_error(ctx);
 | 
			
		||||
 | 
			
		||||
    verify_err = error;
 | 
			
		||||
 | 
			
		||||
    if ((error != X509_V_ERR_NO_EXPLICIT_POLICY)
 | 
			
		||||
        && ((error != X509_V_OK) || (ok != 2)))
 | 
			
		||||
        return ok;
 | 
			
		||||
@@ -1275,7 +1119,7 @@ static void receipt_request_print(BIO *out, CMS_ContentInfo *cms)
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static STACK_OF(GENERAL_NAMES) *make_names_stack(STACK_OF(OPENSSL_STRING) *ns)
 | 
			
		||||
static STACK_OF(GENERAL_NAMES) *make_names_stack(STACK * ns)
 | 
			
		||||
{
 | 
			
		||||
    int i;
 | 
			
		||||
    STACK_OF(GENERAL_NAMES) *ret;
 | 
			
		||||
@@ -1284,9 +1128,11 @@ static STACK_OF(GENERAL_NAMES) *make_names_stack(STACK_OF(OPENSSL_STRING) *ns)
 | 
			
		||||
    ret = sk_GENERAL_NAMES_new_null();
 | 
			
		||||
    if (!ret)
 | 
			
		||||
        goto err;
 | 
			
		||||
    for (i = 0; i < sk_OPENSSL_STRING_num(ns); i++) {
 | 
			
		||||
        char *str = sk_OPENSSL_STRING_value(ns, i);
 | 
			
		||||
        gen = a2i_GENERAL_NAME(NULL, NULL, NULL, GEN_EMAIL, str, 0);
 | 
			
		||||
    for (i = 0; i < sk_num(ns); i++) {
 | 
			
		||||
        CONF_VALUE cnf;
 | 
			
		||||
        cnf.name = "email";
 | 
			
		||||
        cnf.value = sk_value(ns, i);
 | 
			
		||||
        gen = v2i_GENERAL_NAME(NULL, NULL, &cnf);
 | 
			
		||||
        if (!gen)
 | 
			
		||||
            goto err;
 | 
			
		||||
        gens = GENERAL_NAMES_new();
 | 
			
		||||
@@ -1312,9 +1158,9 @@ static STACK_OF(GENERAL_NAMES) *make_names_stack(STACK_OF(OPENSSL_STRING) *ns)
 | 
			
		||||
    return NULL;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static CMS_ReceiptRequest *make_receipt_request(STACK_OF(OPENSSL_STRING)
 | 
			
		||||
                                                *rr_to, int rr_allorfirst, STACK_OF(OPENSSL_STRING)
 | 
			
		||||
                                                *rr_from)
 | 
			
		||||
static CMS_ReceiptRequest *make_receipt_request(STACK * rr_to,
 | 
			
		||||
                                                int rr_allorfirst,
 | 
			
		||||
                                                STACK * rr_from)
 | 
			
		||||
{
 | 
			
		||||
    STACK_OF(GENERAL_NAMES) *rct_to, *rct_from;
 | 
			
		||||
    CMS_ReceiptRequest *rr;
 | 
			
		||||
@@ -1334,22 +1180,4 @@ static CMS_ReceiptRequest *make_receipt_request(STACK_OF(OPENSSL_STRING)
 | 
			
		||||
    return NULL;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int cms_set_pkey_param(EVP_PKEY_CTX *pctx,
 | 
			
		||||
                              STACK_OF(OPENSSL_STRING) *param)
 | 
			
		||||
{
 | 
			
		||||
    char *keyopt;
 | 
			
		||||
    int i;
 | 
			
		||||
    if (sk_OPENSSL_STRING_num(param) <= 0)
 | 
			
		||||
        return 1;
 | 
			
		||||
    for (i = 0; i < sk_OPENSSL_STRING_num(param); i++) {
 | 
			
		||||
        keyopt = sk_OPENSSL_STRING_value(param, i);
 | 
			
		||||
        if (pkey_ctrl_string(pctx, keyopt) <= 0) {
 | 
			
		||||
            BIO_printf(bio_err, "parameter error \"%s\"\n", keyopt);
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            return 0;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										108
									
								
								apps/crl.c
									
									
									
									
									
								
							
							
						
						
									
										108
									
								
								apps/crl.c
									
									
									
									
									
								
							@@ -81,9 +81,6 @@ static const char *crl_usage[] = {
 | 
			
		||||
    " -in arg         - input file - default stdin\n",
 | 
			
		||||
    " -out arg        - output file - default stdout\n",
 | 
			
		||||
    " -hash           - print hash value\n",
 | 
			
		||||
#ifndef OPENSSL_NO_MD5
 | 
			
		||||
    " -hash_old       - print old-style (MD5) hash value\n",
 | 
			
		||||
#endif
 | 
			
		||||
    " -fingerprint    - print the crl fingerprint\n",
 | 
			
		||||
    " -issuer         - print issuer DN\n",
 | 
			
		||||
    " -lastupdate     - lastUpdate field\n",
 | 
			
		||||
@@ -96,6 +93,7 @@ static const char *crl_usage[] = {
 | 
			
		||||
    NULL
 | 
			
		||||
};
 | 
			
		||||
 | 
			
		||||
static X509_CRL *load_crl(char *file, int format);
 | 
			
		||||
static BIO *bio_out = NULL;
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
@@ -105,15 +103,12 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    unsigned long nmflag = 0;
 | 
			
		||||
    X509_CRL *x = NULL;
 | 
			
		||||
    char *CAfile = NULL, *CApath = NULL;
 | 
			
		||||
    int ret = 1, i, num, badops = 0, badsig = 0;
 | 
			
		||||
    int ret = 1, i, num, badops = 0;
 | 
			
		||||
    BIO *out = NULL;
 | 
			
		||||
    int informat, outformat, keyformat;
 | 
			
		||||
    char *infile = NULL, *outfile = NULL, *crldiff = NULL, *keyfile = NULL;
 | 
			
		||||
    int informat, outformat;
 | 
			
		||||
    char *infile = NULL, *outfile = NULL;
 | 
			
		||||
    int hash = 0, issuer = 0, lastupdate = 0, nextupdate = 0, noout =
 | 
			
		||||
        0, text = 0;
 | 
			
		||||
#ifndef OPENSSL_NO_MD5
 | 
			
		||||
    int hash_old = 0;
 | 
			
		||||
#endif
 | 
			
		||||
    int fingerprint = 0, crlnumber = 0;
 | 
			
		||||
    const char **pp;
 | 
			
		||||
    X509_STORE *store = NULL;
 | 
			
		||||
@@ -146,7 +141,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    informat = FORMAT_PEM;
 | 
			
		||||
    outformat = FORMAT_PEM;
 | 
			
		||||
    keyformat = FORMAT_PEM;
 | 
			
		||||
 | 
			
		||||
    argc--;
 | 
			
		||||
    argv++;
 | 
			
		||||
@@ -173,18 +167,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            infile = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-gendelta") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            crldiff = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-key") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            keyfile = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-keyform") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            keyformat = str2fmt(*(++argv));
 | 
			
		||||
        } else if (strcmp(*argv, "-out") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
@@ -205,10 +187,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            text = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-hash") == 0)
 | 
			
		||||
            hash = ++num;
 | 
			
		||||
#ifndef OPENSSL_NO_MD5
 | 
			
		||||
        else if (strcmp(*argv, "-hash_old") == 0)
 | 
			
		||||
            hash_old = ++num;
 | 
			
		||||
#endif
 | 
			
		||||
        else if (strcmp(*argv, "-nameopt") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
@@ -226,8 +204,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            fingerprint = ++num;
 | 
			
		||||
        else if (strcmp(*argv, "-crlnumber") == 0)
 | 
			
		||||
            crlnumber = ++num;
 | 
			
		||||
        else if (strcmp(*argv, "-badsig") == 0)
 | 
			
		||||
            badsig = 1;
 | 
			
		||||
        else if ((md_alg = EVP_get_digestbyname(*argv + 1))) {
 | 
			
		||||
            /* ok */
 | 
			
		||||
            digest = md_alg;
 | 
			
		||||
@@ -295,33 +271,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            BIO_printf(bio_err, "verify OK\n");
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (crldiff) {
 | 
			
		||||
        X509_CRL *newcrl, *delta;
 | 
			
		||||
        if (!keyfile) {
 | 
			
		||||
            BIO_puts(bio_err, "Missing CRL signing key\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        newcrl = load_crl(crldiff, informat);
 | 
			
		||||
        if (!newcrl)
 | 
			
		||||
            goto end;
 | 
			
		||||
        pkey = load_key(bio_err, keyfile, keyformat, 0, NULL, NULL,
 | 
			
		||||
                        "CRL signing key");
 | 
			
		||||
        if (!pkey) {
 | 
			
		||||
            X509_CRL_free(newcrl);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        delta = X509_CRL_diff(x, newcrl, pkey, digest, 0);
 | 
			
		||||
        X509_CRL_free(newcrl);
 | 
			
		||||
        EVP_PKEY_free(pkey);
 | 
			
		||||
        if (delta) {
 | 
			
		||||
            X509_CRL_free(x);
 | 
			
		||||
            x = delta;
 | 
			
		||||
        } else {
 | 
			
		||||
            BIO_puts(bio_err, "Error creating delta CRL\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (num) {
 | 
			
		||||
        for (i = 1; i <= num; i++) {
 | 
			
		||||
            if (issuer == i) {
 | 
			
		||||
@@ -343,12 +292,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                BIO_printf(bio_out, "%08lx\n",
 | 
			
		||||
                           X509_NAME_hash(X509_CRL_get_issuer(x)));
 | 
			
		||||
            }
 | 
			
		||||
#ifndef OPENSSL_NO_MD5
 | 
			
		||||
            if (hash_old == i) {
 | 
			
		||||
                BIO_printf(bio_out, "%08lx\n",
 | 
			
		||||
                           X509_NAME_hash_old(X509_CRL_get_issuer(x)));
 | 
			
		||||
            }
 | 
			
		||||
#endif
 | 
			
		||||
            if (lastupdate == i) {
 | 
			
		||||
                BIO_printf(bio_out, "lastUpdate=");
 | 
			
		||||
                ASN1_TIME_print(bio_out, X509_CRL_get_lastUpdate(x));
 | 
			
		||||
@@ -410,9 +353,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (badsig)
 | 
			
		||||
        x->signature->data[x->signature->length - 1] ^= 0x1;
 | 
			
		||||
 | 
			
		||||
    if (outformat == FORMAT_ASN1)
 | 
			
		||||
        i = (int)i2d_X509_CRL_bio(out, x);
 | 
			
		||||
    else if (outformat == FORMAT_PEM)
 | 
			
		||||
@@ -427,8 +367,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 end:
 | 
			
		||||
    if (ret != 0)
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    BIO_free_all(bio_out);
 | 
			
		||||
    bio_out = NULL;
 | 
			
		||||
@@ -440,3 +378,41 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static X509_CRL *load_crl(char *infile, int format)
 | 
			
		||||
{
 | 
			
		||||
    X509_CRL *x = NULL;
 | 
			
		||||
    BIO *in = NULL;
 | 
			
		||||
 | 
			
		||||
    in = BIO_new(BIO_s_file());
 | 
			
		||||
    if (in == NULL) {
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (infile == NULL)
 | 
			
		||||
        BIO_set_fp(in, stdin, BIO_NOCLOSE);
 | 
			
		||||
    else {
 | 
			
		||||
        if (BIO_read_filename(in, infile) <= 0) {
 | 
			
		||||
            perror(infile);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    if (format == FORMAT_ASN1)
 | 
			
		||||
        x = d2i_X509_CRL_bio(in, NULL);
 | 
			
		||||
    else if (format == FORMAT_PEM)
 | 
			
		||||
        x = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL);
 | 
			
		||||
    else {
 | 
			
		||||
        BIO_printf(bio_err, "bad input format specified for input crl\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    if (x == NULL) {
 | 
			
		||||
        BIO_printf(bio_err, "unable to load CRL\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
    return (x);
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -65,6 +65,7 @@
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#include <sys/types.h>
 | 
			
		||||
#include <sys/stat.h>
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#include <openssl/evp.h>
 | 
			
		||||
@@ -95,7 +96,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    PKCS7 *p7 = NULL;
 | 
			
		||||
    PKCS7_SIGNED *p7s = NULL;
 | 
			
		||||
    X509_CRL *crl = NULL;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *certflst = NULL;
 | 
			
		||||
    STACK *certflst = NULL;
 | 
			
		||||
    STACK_OF(X509_CRL) *crl_stack = NULL;
 | 
			
		||||
    STACK_OF(X509) *cert_stack = NULL;
 | 
			
		||||
    int ret = 1, nocrl = 0;
 | 
			
		||||
@@ -137,11 +138,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            if (!certflst)
 | 
			
		||||
                certflst = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                certflst = sk_new_null();
 | 
			
		||||
            if (!certflst)
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (!sk_OPENSSL_STRING_push(certflst, *(++argv))) {
 | 
			
		||||
                sk_OPENSSL_STRING_free(certflst);
 | 
			
		||||
            if (!sk_push(certflst, *(++argv))) {
 | 
			
		||||
                sk_free(certflst);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        } else {
 | 
			
		||||
@@ -227,8 +228,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    p7s->cert = cert_stack;
 | 
			
		||||
 | 
			
		||||
    if (certflst)
 | 
			
		||||
        for (i = 0; i < sk_OPENSSL_STRING_num(certflst); i++) {
 | 
			
		||||
            certfile = sk_OPENSSL_STRING_value(certflst, i);
 | 
			
		||||
        for (i = 0; i < sk_num(certflst); i++) {
 | 
			
		||||
            certfile = sk_value(certflst, i);
 | 
			
		||||
            if (add_certs_from_file(cert_stack, certfile) < 0) {
 | 
			
		||||
                BIO_printf(bio_err, "error loading certificates\n");
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
@@ -236,7 +237,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
    sk_OPENSSL_STRING_free(certflst);
 | 
			
		||||
    sk_free(certflst);
 | 
			
		||||
 | 
			
		||||
    if (outfile == NULL) {
 | 
			
		||||
        BIO_set_fp(out, stdout, BIO_NOCLOSE);
 | 
			
		||||
@@ -293,12 +294,18 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 */
 | 
			
		||||
static int add_certs_from_file(STACK_OF(X509) *stack, char *certfile)
 | 
			
		||||
{
 | 
			
		||||
    struct stat st;
 | 
			
		||||
    BIO *in = NULL;
 | 
			
		||||
    int count = 0;
 | 
			
		||||
    int ret = -1;
 | 
			
		||||
    STACK_OF(X509_INFO) *sk = NULL;
 | 
			
		||||
    X509_INFO *xi;
 | 
			
		||||
 | 
			
		||||
    if ((stat(certfile, &st) != 0)) {
 | 
			
		||||
        BIO_printf(bio_err, "unable to load the file, %s\n", certfile);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    in = BIO_new(BIO_s_file());
 | 
			
		||||
    if ((in == NULL) || (BIO_read_filename(in, certfile) <= 0)) {
 | 
			
		||||
        BIO_printf(bio_err, "error opening the file, %s\n", certfile);
 | 
			
		||||
 
 | 
			
		||||
@@ -1,6 +0,0 @@
 | 
			
		||||
# This is a file that will be filled by the openssl srp routine.
 | 
			
		||||
# You can initialize the file with additional groups, these are
 | 
			
		||||
# records starting with a I followed by the g and N values and the id.
 | 
			
		||||
# The exact values ... you have to dig this out from the source of srp.c
 | 
			
		||||
# or srp_vfy.c
 | 
			
		||||
# The last value of an I is used as the default group for new users.  
 | 
			
		||||
@@ -1 +0,0 @@
 | 
			
		||||
unique_subject = yes
 | 
			
		||||
							
								
								
									
										335
									
								
								apps/dgst.c
									
									
									
									
									
								
							
							
						
						
									
										335
									
								
								apps/dgst.c
									
									
									
									
									
								
							@@ -75,41 +75,22 @@
 | 
			
		||||
#define PROG    dgst_main
 | 
			
		||||
 | 
			
		||||
int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout,
 | 
			
		||||
          EVP_PKEY *key, unsigned char *sigin, int siglen,
 | 
			
		||||
          const char *sig_name, const char *md_name,
 | 
			
		||||
          const char *file, BIO *bmd);
 | 
			
		||||
 | 
			
		||||
static void list_md_fn(const EVP_MD *m,
 | 
			
		||||
                       const char *from, const char *to, void *arg)
 | 
			
		||||
{
 | 
			
		||||
    const char *mname;
 | 
			
		||||
    /* Skip aliases */
 | 
			
		||||
    if (!m)
 | 
			
		||||
        return;
 | 
			
		||||
    mname = OBJ_nid2ln(EVP_MD_type(m));
 | 
			
		||||
    /* Skip shortnames */
 | 
			
		||||
    if (strcmp(from, mname))
 | 
			
		||||
        return;
 | 
			
		||||
    /* Skip clones */
 | 
			
		||||
    if (EVP_MD_flags(m) & EVP_MD_FLAG_PKEY_DIGEST)
 | 
			
		||||
        return;
 | 
			
		||||
    if (strchr(mname, ' '))
 | 
			
		||||
        mname = EVP_MD_name(m);
 | 
			
		||||
    BIO_printf(arg, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
               mname, mname);
 | 
			
		||||
}
 | 
			
		||||
          EVP_PKEY *key, unsigned char *sigin, int siglen, const char *title,
 | 
			
		||||
          const char *file, BIO *bmd, const char *hmac_key,
 | 
			
		||||
          int non_fips_allow);
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    ENGINE *e = NULL, *impl = NULL;
 | 
			
		||||
    ENGINE *e = NULL;
 | 
			
		||||
    unsigned char *buf = NULL;
 | 
			
		||||
    int i, err = 1;
 | 
			
		||||
    const EVP_MD *md = NULL, *m;
 | 
			
		||||
    BIO *in = NULL, *inp;
 | 
			
		||||
    BIO *bmd = NULL;
 | 
			
		||||
    BIO *out = NULL;
 | 
			
		||||
    const char *name;
 | 
			
		||||
#define PROG_NAME_SIZE  39
 | 
			
		||||
    char pname[PROG_NAME_SIZE + 1];
 | 
			
		||||
    int separator = 0;
 | 
			
		||||
@@ -121,18 +102,16 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    EVP_PKEY *sigkey = NULL;
 | 
			
		||||
    unsigned char *sigbuf = NULL;
 | 
			
		||||
    int siglen = 0;
 | 
			
		||||
    unsigned int sig_flags = 0;
 | 
			
		||||
    char *passargin = NULL, *passin = NULL;
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
    int engine_impl = 0;
 | 
			
		||||
#endif
 | 
			
		||||
    char *hmac_key = NULL;
 | 
			
		||||
    char *mac_name = NULL;
 | 
			
		||||
    int non_fips_allow = 0;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *sigopts = NULL, *macopts = NULL;
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
    ERR_load_crypto_strings();
 | 
			
		||||
    if ((buf = (unsigned char *)OPENSSL_malloc(BUFSIZE)) == NULL) {
 | 
			
		||||
        BIO_printf(bio_err, "out of memory\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
@@ -156,8 +135,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            break;
 | 
			
		||||
        if (strcmp(*argv, "-c") == 0)
 | 
			
		||||
            separator = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-r") == 0)
 | 
			
		||||
            separator = 2;
 | 
			
		||||
        else if (strcmp(*argv, "-rand") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
@@ -185,6 +162,24 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                break;
 | 
			
		||||
            keyfile = *(++argv);
 | 
			
		||||
            do_verify = 1;
 | 
			
		||||
        } else if (strcmp(*argv, "-x931") == 0)
 | 
			
		||||
            sig_flags = EVP_MD_CTX_FLAG_PAD_X931;
 | 
			
		||||
        else if (strcmp(*argv, "-pss_saltlen") == 0) {
 | 
			
		||||
            int saltlen;
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
            saltlen = atoi(*(++argv));
 | 
			
		||||
            if (saltlen == -1)
 | 
			
		||||
                sig_flags = EVP_MD_CTX_FLAG_PSS_MREC;
 | 
			
		||||
            else if (saltlen == -2)
 | 
			
		||||
                sig_flags = EVP_MD_CTX_FLAG_PSS_MDLEN;
 | 
			
		||||
            else if (saltlen < -2 || saltlen >= 0xFFFE) {
 | 
			
		||||
                BIO_printf(bio_err, "Invalid PSS salt length %d\n", saltlen);
 | 
			
		||||
                goto end;
 | 
			
		||||
            } else
 | 
			
		||||
                sig_flags = saltlen;
 | 
			
		||||
            sig_flags <<= 16;
 | 
			
		||||
            sig_flags |= EVP_MD_CTX_FLAG_PAD_PSS;
 | 
			
		||||
        } else if (strcmp(*argv, "-signature") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
@@ -199,9 +194,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
            engine = *(++argv);
 | 
			
		||||
            e = setup_engine(bio_err, engine, 0);
 | 
			
		||||
        } else if (strcmp(*argv, "-engine_impl") == 0)
 | 
			
		||||
            engine_impl = 1;
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
        else if (strcmp(*argv, "-hex") == 0)
 | 
			
		||||
            out_bin = 0;
 | 
			
		||||
@@ -209,32 +202,14 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            out_bin = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-d") == 0)
 | 
			
		||||
            debug = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-fips-fingerprint"))
 | 
			
		||||
            hmac_key = "etaonrishdlcupfm";
 | 
			
		||||
        else if (strcmp(*argv, "-non-fips-allow") == 0)
 | 
			
		||||
            non_fips_allow = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-fips-fingerprint"))
 | 
			
		||||
            hmac_key = "etaonrishdlcupfm";
 | 
			
		||||
        else if (!strcmp(*argv, "-hmac")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
            hmac_key = *++argv;
 | 
			
		||||
        } else if (!strcmp(*argv, "-mac")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
            mac_name = *++argv;
 | 
			
		||||
        } else if (strcmp(*argv, "-sigopt") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
            if (!sigopts)
 | 
			
		||||
                sigopts = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            if (!sigopts || !sk_OPENSSL_STRING_push(sigopts, *(++argv)))
 | 
			
		||||
                break;
 | 
			
		||||
        } else if (strcmp(*argv, "-macopt") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                break;
 | 
			
		||||
            if (!macopts)
 | 
			
		||||
                macopts = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            if (!macopts || !sk_OPENSSL_STRING_push(macopts, *(++argv)))
 | 
			
		||||
                break;
 | 
			
		||||
        } else if ((m = EVP_get_digestbyname(&((*argv)[1]))) != NULL)
 | 
			
		||||
            md = m;
 | 
			
		||||
        else
 | 
			
		||||
@@ -243,9 +218,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        argv++;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (md == NULL)
 | 
			
		||||
        md = EVP_md5();
 | 
			
		||||
 | 
			
		||||
    if (do_verify && !sigfile) {
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "No signature to verify: use the -signature option\n");
 | 
			
		||||
        err = 1;
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -254,13 +233,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        BIO_printf(bio_err, "options are\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-c              to output the digest with separating colons\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-r              to output the digest in coreutils format\n");
 | 
			
		||||
        BIO_printf(bio_err, "-d              to output debug info\n");
 | 
			
		||||
        BIO_printf(bio_err, "-hex            output as hex dump\n");
 | 
			
		||||
        BIO_printf(bio_err, "-binary         output in binary form\n");
 | 
			
		||||
        BIO_printf(bio_err, "-hmac arg       set the HMAC key to arg\n");
 | 
			
		||||
        BIO_printf(bio_err, "-non-fips-allow allow use of non FIPS digest\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-sign   file    sign digest using private key in file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
@@ -269,26 +244,48 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-prverify file  verify a signature using private key in file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-keyform arg    key file format (PEM or ENGINE)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-out filename   output to filename rather than stdout\n");
 | 
			
		||||
        BIO_printf(bio_err, "-signature file signature to verify\n");
 | 
			
		||||
        BIO_printf(bio_err, "-sigopt nm:v    signature parameter\n");
 | 
			
		||||
        BIO_printf(bio_err, "-binary         output in binary form\n");
 | 
			
		||||
        BIO_printf(bio_err, "-hmac key       create hashed MAC with key\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-mac algorithm  create MAC (not neccessarily HMAC)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-macopt nm:v    MAC algorithm parameters or key\n");
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-engine e       use engine e, possibly a hardware device.\n");
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
        EVP_MD_do_all_sorted(list_md_fn, bio_err);
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-%-14s to use the %s message digest algorithm (default)\n",
 | 
			
		||||
                   LN_md5, LN_md5);
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_md4, LN_md4);
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_md2, LN_md2);
 | 
			
		||||
#ifndef OPENSSL_NO_SHA
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_sha1, LN_sha1);
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_sha, LN_sha);
 | 
			
		||||
# ifndef OPENSSL_NO_SHA256
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_sha224, LN_sha224);
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_sha256, LN_sha256);
 | 
			
		||||
# endif
 | 
			
		||||
# ifndef OPENSSL_NO_SHA512
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_sha384, LN_sha384);
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_sha512, LN_sha512);
 | 
			
		||||
# endif
 | 
			
		||||
#endif
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_mdc2, LN_mdc2);
 | 
			
		||||
        BIO_printf(bio_err, "-%-14s to use the %s message digest algorithm\n",
 | 
			
		||||
                   LN_ripemd160, LN_ripemd160);
 | 
			
		||||
        err = 1;
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    if (engine_impl)
 | 
			
		||||
        impl = e;
 | 
			
		||||
    e = setup_engine(bio_err, engine, 0);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    in = BIO_new(BIO_s_file());
 | 
			
		||||
@@ -340,10 +337,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    if ((! !mac_name + ! !keyfile + ! !hmac_key) > 1) {
 | 
			
		||||
        BIO_printf(bio_err, "MAC and Signing key cannot both be specified\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (keyfile) {
 | 
			
		||||
        if (want_pub)
 | 
			
		||||
@@ -360,96 +353,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (mac_name) {
 | 
			
		||||
        EVP_PKEY_CTX *mac_ctx = NULL;
 | 
			
		||||
        int r = 0;
 | 
			
		||||
        if (!init_gen_str(bio_err, &mac_ctx, mac_name, impl, 0))
 | 
			
		||||
            goto mac_end;
 | 
			
		||||
        if (macopts) {
 | 
			
		||||
            char *macopt;
 | 
			
		||||
            for (i = 0; i < sk_OPENSSL_STRING_num(macopts); i++) {
 | 
			
		||||
                macopt = sk_OPENSSL_STRING_value(macopts, i);
 | 
			
		||||
                if (pkey_ctrl_string(mac_ctx, macopt) <= 0) {
 | 
			
		||||
                    BIO_printf(bio_err,
 | 
			
		||||
                               "MAC parameter error \"%s\"\n", macopt);
 | 
			
		||||
                    ERR_print_errors(bio_err);
 | 
			
		||||
                    goto mac_end;
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
        if (EVP_PKEY_keygen(mac_ctx, &sigkey) <= 0) {
 | 
			
		||||
            BIO_puts(bio_err, "Error generating key\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto mac_end;
 | 
			
		||||
        }
 | 
			
		||||
        r = 1;
 | 
			
		||||
 mac_end:
 | 
			
		||||
        if (mac_ctx)
 | 
			
		||||
            EVP_PKEY_CTX_free(mac_ctx);
 | 
			
		||||
        if (r == 0)
 | 
			
		||||
            goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (non_fips_allow) {
 | 
			
		||||
        EVP_MD_CTX *md_ctx;
 | 
			
		||||
        BIO_get_md_ctx(bmd, &md_ctx);
 | 
			
		||||
        EVP_MD_CTX_set_flags(md_ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (hmac_key) {
 | 
			
		||||
        sigkey = EVP_PKEY_new_mac_key(EVP_PKEY_HMAC, impl,
 | 
			
		||||
                                      (unsigned char *)hmac_key, -1);
 | 
			
		||||
        if (!sigkey)
 | 
			
		||||
            goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (sigkey) {
 | 
			
		||||
        EVP_MD_CTX *mctx = NULL;
 | 
			
		||||
        EVP_PKEY_CTX *pctx = NULL;
 | 
			
		||||
        int r;
 | 
			
		||||
        if (!BIO_get_md_ctx(bmd, &mctx)) {
 | 
			
		||||
            BIO_printf(bio_err, "Error getting context\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        if (do_verify)
 | 
			
		||||
            r = EVP_DigestVerifyInit(mctx, &pctx, md, impl, sigkey);
 | 
			
		||||
        else
 | 
			
		||||
            r = EVP_DigestSignInit(mctx, &pctx, md, impl, sigkey);
 | 
			
		||||
        if (!r) {
 | 
			
		||||
            BIO_printf(bio_err, "Error setting context\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        if (sigopts) {
 | 
			
		||||
            char *sigopt;
 | 
			
		||||
            for (i = 0; i < sk_OPENSSL_STRING_num(sigopts); i++) {
 | 
			
		||||
                sigopt = sk_OPENSSL_STRING_value(sigopts, i);
 | 
			
		||||
                if (pkey_ctrl_string(pctx, sigopt) <= 0) {
 | 
			
		||||
                    BIO_printf(bio_err, "parameter error \"%s\"\n", sigopt);
 | 
			
		||||
                    ERR_print_errors(bio_err);
 | 
			
		||||
                    goto end;
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    /* we use md as a filter, reading from 'in' */
 | 
			
		||||
    else {
 | 
			
		||||
        EVP_MD_CTX *mctx = NULL;
 | 
			
		||||
        if (!BIO_get_md_ctx(bmd, &mctx)) {
 | 
			
		||||
            BIO_printf(bio_err, "Error getting context\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        if (md == NULL)
 | 
			
		||||
            md = EVP_md5();
 | 
			
		||||
        if (!EVP_DigestInit_ex(mctx, md, impl)) {
 | 
			
		||||
            BIO_printf(bio_err, "Error setting digest %s\n", pname);
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (sigfile && sigkey) {
 | 
			
		||||
        BIO *sigbio;
 | 
			
		||||
        sigbio = BIO_new_file(sigfile, "rb");
 | 
			
		||||
@@ -468,43 +371,58 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    inp = BIO_push(bmd, in);
 | 
			
		||||
 | 
			
		||||
    if (md == NULL) {
 | 
			
		||||
        EVP_MD_CTX *tctx;
 | 
			
		||||
        BIO_get_md_ctx(bmd, &tctx);
 | 
			
		||||
        md = EVP_MD_CTX_md(tctx);
 | 
			
		||||
    if (non_fips_allow) {
 | 
			
		||||
        EVP_MD_CTX *md_ctx;
 | 
			
		||||
        BIO_get_md_ctx(bmd, &md_ctx);
 | 
			
		||||
        EVP_MD_CTX_set_flags(md_ctx, EVP_MD_CTX_FLAG_NON_FIPS_ALLOW);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (sig_flags) {
 | 
			
		||||
        EVP_MD_CTX *md_ctx;
 | 
			
		||||
        BIO_get_md_ctx(bmd, &md_ctx);
 | 
			
		||||
        EVP_MD_CTX_set_flags(md_ctx, sig_flags);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    /* we use md as a filter, reading from 'in' */
 | 
			
		||||
    if (!BIO_set_md(bmd, md)) {
 | 
			
		||||
        BIO_printf(bio_err, "Error setting digest %s\n", pname);
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    inp = BIO_push(bmd, in);
 | 
			
		||||
 | 
			
		||||
    if (argc == 0) {
 | 
			
		||||
        BIO_set_fp(in, stdin, BIO_NOCLOSE);
 | 
			
		||||
        err = do_fp(out, buf, inp, separator, out_bin, sigkey, sigbuf,
 | 
			
		||||
                    siglen, NULL, NULL, "stdin", bmd);
 | 
			
		||||
                    siglen, "", "(stdin)", bmd, hmac_key, non_fips_allow);
 | 
			
		||||
    } else {
 | 
			
		||||
        const char *md_name = NULL, *sig_name = NULL;
 | 
			
		||||
        if (!out_bin) {
 | 
			
		||||
            if (sigkey) {
 | 
			
		||||
                const EVP_PKEY_ASN1_METHOD *ameth;
 | 
			
		||||
                ameth = EVP_PKEY_get0_asn1(sigkey);
 | 
			
		||||
                if (ameth)
 | 
			
		||||
                    EVP_PKEY_asn1_get0_info(NULL, NULL,
 | 
			
		||||
                                            NULL, NULL, &sig_name, ameth);
 | 
			
		||||
            }
 | 
			
		||||
            if (md)
 | 
			
		||||
                md_name = EVP_MD_name(md);
 | 
			
		||||
        }
 | 
			
		||||
        name = OBJ_nid2sn(md->type);
 | 
			
		||||
        err = 0;
 | 
			
		||||
        for (i = 0; i < argc; i++) {
 | 
			
		||||
            char *tmp, *tofree = NULL;
 | 
			
		||||
            int r;
 | 
			
		||||
 | 
			
		||||
            if (BIO_read_filename(in, argv[i]) <= 0) {
 | 
			
		||||
                perror(argv[i]);
 | 
			
		||||
                err++;
 | 
			
		||||
                continue;
 | 
			
		||||
            }
 | 
			
		||||
            if (!out_bin) {
 | 
			
		||||
                size_t len =
 | 
			
		||||
                    strlen(name) + strlen(argv[i]) + (hmac_key ? 5 : 0) + 5;
 | 
			
		||||
                tmp = tofree = OPENSSL_malloc(len);
 | 
			
		||||
                BIO_snprintf(tmp, len, "%s%s(%s)= ",
 | 
			
		||||
                             hmac_key ? "HMAC-" : "", name, argv[i]);
 | 
			
		||||
            } else
 | 
			
		||||
                tmp = "";
 | 
			
		||||
            r = do_fp(out, buf, inp, separator, out_bin, sigkey, sigbuf,
 | 
			
		||||
                          siglen, sig_name, md_name, argv[i], bmd);
 | 
			
		||||
                      siglen, tmp, argv[i], bmd, hmac_key, non_fips_allow);
 | 
			
		||||
            if (r)
 | 
			
		||||
                err = r;
 | 
			
		||||
            if (tofree)
 | 
			
		||||
                OPENSSL_free(tofree);
 | 
			
		||||
            (void)BIO_reset(bmd);
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
@@ -519,10 +437,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        OPENSSL_free(passin);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    EVP_PKEY_free(sigkey);
 | 
			
		||||
    if (sigopts)
 | 
			
		||||
        sk_OPENSSL_STRING_free(sigopts);
 | 
			
		||||
    if (macopts)
 | 
			
		||||
        sk_OPENSSL_STRING_free(macopts);
 | 
			
		||||
    if (sigbuf)
 | 
			
		||||
        OPENSSL_free(sigbuf);
 | 
			
		||||
    if (bmd != NULL)
 | 
			
		||||
@@ -532,13 +446,24 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout,
 | 
			
		||||
          EVP_PKEY *key, unsigned char *sigin, int siglen,
 | 
			
		||||
          const char *sig_name, const char *md_name,
 | 
			
		||||
          const char *file, BIO *bmd)
 | 
			
		||||
          EVP_PKEY *key, unsigned char *sigin, int siglen, const char *title,
 | 
			
		||||
          const char *file, BIO *bmd, const char *hmac_key,
 | 
			
		||||
          int non_fips_allow)
 | 
			
		||||
{
 | 
			
		||||
    size_t len;
 | 
			
		||||
    unsigned int len;
 | 
			
		||||
    int i;
 | 
			
		||||
    EVP_MD_CTX *md_ctx;
 | 
			
		||||
    HMAC_CTX hmac_ctx;
 | 
			
		||||
 | 
			
		||||
    if (hmac_key) {
 | 
			
		||||
        EVP_MD *md;
 | 
			
		||||
 | 
			
		||||
        BIO_get_md(bmd, &md);
 | 
			
		||||
        HMAC_CTX_init(&hmac_ctx);
 | 
			
		||||
        HMAC_Init_ex(&hmac_ctx, hmac_key, strlen(hmac_key), md, NULL);
 | 
			
		||||
        BIO_get_md_ctx(bmd, &md_ctx);
 | 
			
		||||
        BIO_set_md_ctx(bmd, &hmac_ctx.md_ctx);
 | 
			
		||||
    }
 | 
			
		||||
    for (;;) {
 | 
			
		||||
        i = BIO_read(bp, (char *)buf, BUFSIZE);
 | 
			
		||||
        if (i < 0) {
 | 
			
		||||
@@ -552,7 +477,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout,
 | 
			
		||||
    if (sigin) {
 | 
			
		||||
        EVP_MD_CTX *ctx;
 | 
			
		||||
        BIO_get_md_ctx(bp, &ctx);
 | 
			
		||||
        i = EVP_DigestVerifyFinal(ctx, sigin, (unsigned int)siglen);
 | 
			
		||||
        i = EVP_VerifyFinal(ctx, sigin, (unsigned int)siglen, key);
 | 
			
		||||
        if (i > 0)
 | 
			
		||||
            BIO_printf(out, "Verified OK\n");
 | 
			
		||||
        else if (i == 0) {
 | 
			
		||||
@@ -568,36 +493,21 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout,
 | 
			
		||||
    if (key) {
 | 
			
		||||
        EVP_MD_CTX *ctx;
 | 
			
		||||
        BIO_get_md_ctx(bp, &ctx);
 | 
			
		||||
        len = BUFSIZE;
 | 
			
		||||
        if (!EVP_DigestSignFinal(ctx, buf, &len)) {
 | 
			
		||||
        if (!EVP_SignFinal(ctx, buf, (unsigned int *)&len, key)) {
 | 
			
		||||
            BIO_printf(bio_err, "Error Signing Data\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            return 1;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
    } else if (hmac_key) {
 | 
			
		||||
        HMAC_Final(&hmac_ctx, buf, &len);
 | 
			
		||||
        HMAC_CTX_cleanup(&hmac_ctx);
 | 
			
		||||
    } else
 | 
			
		||||
        len = BIO_gets(bp, (char *)buf, BUFSIZE);
 | 
			
		||||
        if ((int)len < 0) {
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            return 1;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (binout)
 | 
			
		||||
        BIO_write(out, buf, len);
 | 
			
		||||
    else if (sep == 2) {
 | 
			
		||||
        for (i = 0; i < (int)len; i++)
 | 
			
		||||
            BIO_printf(out, "%02x", buf[i]);
 | 
			
		||||
        BIO_printf(out, " *%s\n", file);
 | 
			
		||||
    } else {
 | 
			
		||||
        if (sig_name) {
 | 
			
		||||
            BIO_puts(out, sig_name);
 | 
			
		||||
            if (md_name)
 | 
			
		||||
                BIO_printf(out, "-%s", md_name);
 | 
			
		||||
            BIO_printf(out, "(%s)= ", file);
 | 
			
		||||
        } else if (md_name)
 | 
			
		||||
            BIO_printf(out, "%s(%s)= ", md_name, file);
 | 
			
		||||
        else
 | 
			
		||||
            BIO_printf(out, "(%s)= ", file);
 | 
			
		||||
    else {
 | 
			
		||||
        BIO_write(out, title, strlen(title));
 | 
			
		||||
        for (i = 0; i < (int)len; i++) {
 | 
			
		||||
            if (sep && (i != 0))
 | 
			
		||||
                BIO_printf(out, ":");
 | 
			
		||||
@@ -605,5 +515,8 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout,
 | 
			
		||||
        }
 | 
			
		||||
        BIO_printf(out, "\n");
 | 
			
		||||
    }
 | 
			
		||||
    if (hmac_key) {
 | 
			
		||||
        BIO_set_md_ctx(bmd, md_ctx);
 | 
			
		||||
    }
 | 
			
		||||
    return 0;
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -328,10 +328,4 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
#else                           /* !OPENSSL_NO_DH */
 | 
			
		||||
 | 
			
		||||
# if PEDANTIC
 | 
			
		||||
static void *dummy = &dummy;
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
@@ -130,7 +130,7 @@
 | 
			
		||||
# undef PROG
 | 
			
		||||
# define PROG    dhparam_main
 | 
			
		||||
 | 
			
		||||
# define DEFBITS 2048
 | 
			
		||||
# define DEFBITS 512
 | 
			
		||||
 | 
			
		||||
/*-
 | 
			
		||||
 * -inform arg  - input format - default PEM (DER or PEM)
 | 
			
		||||
@@ -144,7 +144,7 @@
 | 
			
		||||
 * -C
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
static int dh_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
static int MS_CALLBACK dh_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
@@ -254,7 +254,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   " -5            generate parameters using  5 as the generator value\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   " numbits       number of bits in to generate (default 2048)\n");
 | 
			
		||||
                   " numbits       number of bits in to generate (default 512)\n");
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   " -engine e     use engine e, possibly a hardware device.\n");
 | 
			
		||||
@@ -294,14 +294,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    if (num) {
 | 
			
		||||
 | 
			
		||||
        BN_GENCB *cb;
 | 
			
		||||
        cb = BN_GENCB_new();
 | 
			
		||||
        if (!cb) {
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        BN_GENCB_set(cb, dh_cb, bio_err);
 | 
			
		||||
        BN_GENCB cb;
 | 
			
		||||
        BN_GENCB_set(&cb, dh_cb, bio_err);
 | 
			
		||||
        if (!app_RAND_load_file(NULL, bio_err, 1) && inrand == NULL) {
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "warning, not much extra random data, consider using the -rand option\n");
 | 
			
		||||
@@ -318,10 +312,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                       "Generating DSA parameters, %d bit long prime\n", num);
 | 
			
		||||
            if (!dsa
 | 
			
		||||
                || !DSA_generate_parameters_ex(dsa, num, NULL, 0, NULL, NULL,
 | 
			
		||||
                                               cb)) {
 | 
			
		||||
                                               &cb)) {
 | 
			
		||||
                if (dsa)
 | 
			
		||||
                    DSA_free(dsa);
 | 
			
		||||
                BN_GENCB_free(cb);
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
@@ -329,7 +322,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            dh = DSA_dup_DH(dsa);
 | 
			
		||||
            DSA_free(dsa);
 | 
			
		||||
            if (dh == NULL) {
 | 
			
		||||
                BN_GENCB_free(cb);
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
@@ -341,14 +333,12 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                       "Generating DH parameters, %d bit long safe prime, generator %d\n",
 | 
			
		||||
                       num, g);
 | 
			
		||||
            BIO_printf(bio_err, "This is going to take a long time\n");
 | 
			
		||||
            if (!dh || !DH_generate_parameters_ex(dh, num, g, cb)) {
 | 
			
		||||
                BN_GENCB_free(cb);
 | 
			
		||||
            if (!dh || !DH_generate_parameters_ex(dh, num, g, &cb)) {
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        BN_GENCB_free(cb);
 | 
			
		||||
        app_RAND_write_file(NULL, bio_err);
 | 
			
		||||
    } else {
 | 
			
		||||
 | 
			
		||||
@@ -499,12 +489,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (!noout) {
 | 
			
		||||
        if (outformat == FORMAT_ASN1)
 | 
			
		||||
            i = i2d_DHparams_bio(out, dh);
 | 
			
		||||
        else if (outformat == FORMAT_PEM) {
 | 
			
		||||
            if (dh->q)
 | 
			
		||||
                i = PEM_write_bio_DHxparams(out, dh);
 | 
			
		||||
            else
 | 
			
		||||
        else if (outformat == FORMAT_PEM)
 | 
			
		||||
            i = PEM_write_bio_DHparams(out, dh);
 | 
			
		||||
        } else {
 | 
			
		||||
        else {
 | 
			
		||||
            BIO_printf(bio_err, "bad output format specified for outfile\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
@@ -527,7 +514,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
/* dh_cb is identical to dsa_cb in apps/dsaparam.c */
 | 
			
		||||
static int dh_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
static int MS_CALLBACK dh_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
{
 | 
			
		||||
    char c = '*';
 | 
			
		||||
 | 
			
		||||
@@ -539,15 +526,12 @@ static int dh_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
        c = '*';
 | 
			
		||||
    if (p == 3)
 | 
			
		||||
        c = '\n';
 | 
			
		||||
    BIO_write(BN_GENCB_get_arg(cb), &c, 1);
 | 
			
		||||
    (void)BIO_flush(BN_GENCB_get_arg(cb));
 | 
			
		||||
    BIO_write(cb->arg, &c, 1);
 | 
			
		||||
    (void)BIO_flush(cb->arg);
 | 
			
		||||
# ifdef LINT
 | 
			
		||||
    p = n;
 | 
			
		||||
# endif
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#else                           /* !OPENSSL_NO_DH */
 | 
			
		||||
 | 
			
		||||
# if PEDANTIC
 | 
			
		||||
static void *dummy = &dummy;
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										50
									
								
								apps/dsa.c
									
									
									
									
									
								
							
							
						
						
									
										50
									
								
								apps/dsa.c
									
									
									
									
									
								
							@@ -65,11 +65,11 @@
 | 
			
		||||
# include "apps.h"
 | 
			
		||||
# include <openssl/bio.h>
 | 
			
		||||
# include <openssl/err.h>
 | 
			
		||||
# include <openssl/dsa.h>
 | 
			
		||||
# include <openssl/evp.h>
 | 
			
		||||
# include <openssl/x509.h>
 | 
			
		||||
# include <openssl/pem.h>
 | 
			
		||||
# include <openssl/bn.h>
 | 
			
		||||
# include <openssl/dsa.h>
 | 
			
		||||
 | 
			
		||||
# undef PROG
 | 
			
		||||
# define PROG    dsa_main
 | 
			
		||||
@@ -113,8 +113,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    char *passin = NULL, *passout = NULL;
 | 
			
		||||
    int modulus = 0;
 | 
			
		||||
 | 
			
		||||
    int pvk_encr = 2;
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
@@ -168,12 +166,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            engine = *(++argv);
 | 
			
		||||
        }
 | 
			
		||||
# endif
 | 
			
		||||
        else if (strcmp(*argv, "-pvk-strong") == 0)
 | 
			
		||||
            pvk_encr = 2;
 | 
			
		||||
        else if (strcmp(*argv, "-pvk-weak") == 0)
 | 
			
		||||
            pvk_encr = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-pvk-none") == 0)
 | 
			
		||||
            pvk_encr = 0;
 | 
			
		||||
        else if (strcmp(*argv, "-noout") == 0)
 | 
			
		||||
            noout = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-text") == 0)
 | 
			
		||||
@@ -248,27 +240,15 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    in = BIO_new(BIO_s_file());
 | 
			
		||||
    out = BIO_new(BIO_s_file());
 | 
			
		||||
    if ((in == NULL) || (out == NULL)) {
 | 
			
		||||
    if (out == NULL) {
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (infile == NULL)
 | 
			
		||||
        BIO_set_fp(in, stdin, BIO_NOCLOSE);
 | 
			
		||||
    else {
 | 
			
		||||
        if (BIO_read_filename(in, infile) <= 0) {
 | 
			
		||||
            perror(infile);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    BIO_printf(bio_err, "read DSA key\n");
 | 
			
		||||
 | 
			
		||||
    {
 | 
			
		||||
        EVP_PKEY *pkey;
 | 
			
		||||
 | 
			
		||||
        if (pubin)
 | 
			
		||||
            pkey = load_pubkey(bio_err, infile, informat, 1,
 | 
			
		||||
                               passin, e, "Public Key");
 | 
			
		||||
@@ -276,11 +256,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            pkey = load_key(bio_err, infile, informat, 1,
 | 
			
		||||
                            passin, e, "Private Key");
 | 
			
		||||
 | 
			
		||||
        if (pkey) {
 | 
			
		||||
            dsa = EVP_PKEY_get1_DSA(pkey);
 | 
			
		||||
        if (pkey != NULL)
 | 
			
		||||
            dsa = pkey == NULL ? NULL : EVP_PKEY_get1_DSA(pkey);
 | 
			
		||||
        EVP_PKEY_free(pkey);
 | 
			
		||||
    }
 | 
			
		||||
    }
 | 
			
		||||
    if (dsa == NULL) {
 | 
			
		||||
        BIO_printf(bio_err, "unable to load Key\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
@@ -329,24 +308,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        else
 | 
			
		||||
            i = PEM_write_bio_DSAPrivateKey(out, dsa, enc,
 | 
			
		||||
                                            NULL, 0, NULL, passout);
 | 
			
		||||
# if !defined(OPENSSL_NO_RSA) && !defined(OPENSSL_NO_RC4)
 | 
			
		||||
    } else if (outformat == FORMAT_MSBLOB || outformat == FORMAT_PVK) {
 | 
			
		||||
        EVP_PKEY *pk;
 | 
			
		||||
        pk = EVP_PKEY_new();
 | 
			
		||||
        EVP_PKEY_set1_DSA(pk, dsa);
 | 
			
		||||
        if (outformat == FORMAT_PVK)
 | 
			
		||||
            i = i2b_PVK_bio(out, pk, pvk_encr, 0, passout);
 | 
			
		||||
        else if (pubin || pubout)
 | 
			
		||||
            i = i2b_PublicKey_bio(out, pk);
 | 
			
		||||
        else
 | 
			
		||||
            i = i2b_PrivateKey_bio(out, pk);
 | 
			
		||||
        EVP_PKEY_free(pk);
 | 
			
		||||
# endif
 | 
			
		||||
    } else {
 | 
			
		||||
        BIO_printf(bio_err, "bad output format specified for outfile\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    if (i <= 0) {
 | 
			
		||||
    if (!i) {
 | 
			
		||||
        BIO_printf(bio_err, "unable to write private key\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
    } else
 | 
			
		||||
@@ -365,10 +331,4 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
#else                           /* !OPENSSL_NO_DSA */
 | 
			
		||||
 | 
			
		||||
# if PEDANTIC
 | 
			
		||||
static void *dummy = &dummy;
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
@@ -57,6 +57,13 @@
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
#include <openssl/opensslconf.h> /* for OPENSSL_NO_DSA */
 | 
			
		||||
/*
 | 
			
		||||
 * Until the key-gen callbacks are modified to use newer prototypes, we allow
 | 
			
		||||
 * deprecated functions for openssl-internal code
 | 
			
		||||
 */
 | 
			
		||||
#ifdef OPENSSL_NO_DEPRECATED
 | 
			
		||||
# undef OPENSSL_NO_DEPRECATED
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
# include <assert.h>
 | 
			
		||||
@@ -101,7 +108,7 @@ static void timebomb_sigalarm(int foo)
 | 
			
		||||
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
static int dsa_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
static int MS_CALLBACK dsa_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
@@ -114,8 +121,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    char *infile, *outfile, *prog, *inrand = NULL;
 | 
			
		||||
    int numbits = -1, num, genkey = 0;
 | 
			
		||||
    int need_rand = 0;
 | 
			
		||||
    int non_fips_allow = 0;
 | 
			
		||||
    BN_GENCB *cb = NULL;
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
# endif
 | 
			
		||||
@@ -186,8 +191,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            need_rand = 1;
 | 
			
		||||
        } else if (strcmp(*argv, "-noout") == 0)
 | 
			
		||||
            noout = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-non-fips-allow") == 0)
 | 
			
		||||
            non_fips_allow = 1;
 | 
			
		||||
        else if (sscanf(*argv, "%d", &num) == 1) {
 | 
			
		||||
            /* generate a key */
 | 
			
		||||
            numbits = num;
 | 
			
		||||
@@ -272,20 +275,14 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (numbits > 0) {
 | 
			
		||||
        cb = BN_GENCB_new();
 | 
			
		||||
        if (!cb) {
 | 
			
		||||
            BIO_printf(bio_err, "Error allocating BN_GENCB object\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        BN_GENCB_set(cb, dsa_cb, bio_err);
 | 
			
		||||
        BN_GENCB cb;
 | 
			
		||||
        BN_GENCB_set(&cb, dsa_cb, bio_err);
 | 
			
		||||
        assert(need_rand);
 | 
			
		||||
        dsa = DSA_new();
 | 
			
		||||
        if (!dsa) {
 | 
			
		||||
            BIO_printf(bio_err, "Error allocating DSA object\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        if (non_fips_allow)
 | 
			
		||||
            dsa->flags |= DSA_FLAG_NON_FIPS_ALLOW;
 | 
			
		||||
        BIO_printf(bio_err, "Generating DSA parameters, %d bit long prime\n",
 | 
			
		||||
                   num);
 | 
			
		||||
        BIO_printf(bio_err, "This could take some time\n");
 | 
			
		||||
@@ -304,7 +301,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            alarm(timebomb);
 | 
			
		||||
        }
 | 
			
		||||
# endif
 | 
			
		||||
        if (!DSA_generate_parameters_ex(dsa, num, NULL, 0, NULL, NULL, cb)) {
 | 
			
		||||
        if (!DSA_generate_parameters_ex(dsa, num, NULL, 0, NULL, NULL, &cb)) {
 | 
			
		||||
# ifdef GENCB_TEST
 | 
			
		||||
            if (stop_keygen_flag) {
 | 
			
		||||
                BIO_printf(bio_err, "DSA key generation time-stopped\n");
 | 
			
		||||
@@ -313,7 +310,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
# endif
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            BIO_printf(bio_err, "Error, DSA key generation failed\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
@@ -409,13 +405,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        assert(need_rand);
 | 
			
		||||
        if ((dsakey = DSAparams_dup(dsa)) == NULL)
 | 
			
		||||
            goto end;
 | 
			
		||||
        if (non_fips_allow)
 | 
			
		||||
            dsakey->flags |= DSA_FLAG_NON_FIPS_ALLOW;
 | 
			
		||||
        if (!DSA_generate_key(dsakey)) {
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            DSA_free(dsakey);
 | 
			
		||||
        if (!DSA_generate_key(dsakey))
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        if (outformat == FORMAT_ASN1)
 | 
			
		||||
            i = i2d_DSAPrivateKey_bio(out, dsakey);
 | 
			
		||||
        else if (outformat == FORMAT_PEM)
 | 
			
		||||
@@ -423,7 +414,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                                            NULL);
 | 
			
		||||
        else {
 | 
			
		||||
            BIO_printf(bio_err, "bad output format specified for outfile\n");
 | 
			
		||||
            DSA_free(dsakey);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        DSA_free(dsakey);
 | 
			
		||||
@@ -432,8 +422,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        app_RAND_write_file(NULL, bio_err);
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 end:
 | 
			
		||||
    if (cb != NULL)
 | 
			
		||||
        BN_GENCB_free(cb);
 | 
			
		||||
    if (in != NULL)
 | 
			
		||||
        BIO_free(in);
 | 
			
		||||
    if (out != NULL)
 | 
			
		||||
@@ -444,7 +432,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int dsa_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
static int MS_CALLBACK dsa_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
{
 | 
			
		||||
    char c = '*';
 | 
			
		||||
 | 
			
		||||
@@ -456,8 +444,11 @@ static int dsa_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
        c = '*';
 | 
			
		||||
    if (p == 3)
 | 
			
		||||
        c = '\n';
 | 
			
		||||
    BIO_write(BN_GENCB_get_arg(cb), &c, 1);
 | 
			
		||||
    (void)BIO_flush(BN_GENCB_get_arg(cb));
 | 
			
		||||
    BIO_write(cb->arg, &c, 1);
 | 
			
		||||
    (void)BIO_flush(cb->arg);
 | 
			
		||||
# ifdef LINT
 | 
			
		||||
    p = n;
 | 
			
		||||
# endif
 | 
			
		||||
# ifdef GENCB_TEST
 | 
			
		||||
    if (stop_keygen_flag)
 | 
			
		||||
        return 0;
 | 
			
		||||
 
 | 
			
		||||
@@ -356,10 +356,4 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
#else                           /* !OPENSSL_NO_EC */
 | 
			
		||||
 | 
			
		||||
# if PEDANTIC
 | 
			
		||||
static void *dummy = &dummy;
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
@@ -106,7 +106,7 @@
 | 
			
		||||
 *                    in the asn1 der encoding
 | 
			
		||||
 *                    possible values: named_curve (default)
 | 
			
		||||
 *                                     explicit
 | 
			
		||||
 * -no_seed         - if 'explicit' parameters are chosen do not use the seed
 | 
			
		||||
 * -no_seed         - if 'explicit' parameters are choosen do not use the seed
 | 
			
		||||
 * -genkey          - generate ec key
 | 
			
		||||
 * -rand file       - files to use for random number input
 | 
			
		||||
 * -engine e        - use engine e, possibly a hardware device
 | 
			
		||||
@@ -270,7 +270,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        BIO_printf(bio_err, "                                   "
 | 
			
		||||
                   " explicit\n");
 | 
			
		||||
        BIO_printf(bio_err, " -no_seed          if 'explicit'"
 | 
			
		||||
                   " parameters are chosen do not" " use the seed\n");
 | 
			
		||||
                   " parameters are choosen do not" " use the seed\n");
 | 
			
		||||
        BIO_printf(bio_err, " -genkey           generate ec" " key\n");
 | 
			
		||||
        BIO_printf(bio_err, " -rand file        files to use for"
 | 
			
		||||
                   " random number input\n");
 | 
			
		||||
@@ -370,9 +370,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        } else
 | 
			
		||||
            nid = OBJ_sn2nid(curve_name);
 | 
			
		||||
 | 
			
		||||
        if (nid == 0)
 | 
			
		||||
            nid = EC_curve_nist2nid(curve_name);
 | 
			
		||||
 | 
			
		||||
        if (nid == 0) {
 | 
			
		||||
            BIO_printf(bio_err, "unknown curve name (%s)\n", curve_name);
 | 
			
		||||
            goto end;
 | 
			
		||||
@@ -653,10 +650,4 @@ static int ecparam_print_var(BIO *out, BIGNUM *in, const char *var,
 | 
			
		||||
    BIO_printf(out, "\n\t};\n\n");
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
#else                           /* !OPENSSL_NO_EC */
 | 
			
		||||
 | 
			
		||||
# if PEDANTIC
 | 
			
		||||
static void *dummy = &dummy;
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										70
									
								
								apps/enc.c
									
									
									
									
									
								
							
							
						
						
									
										70
									
								
								apps/enc.c
									
									
									
									
									
								
							@@ -67,9 +67,6 @@
 | 
			
		||||
#include <openssl/x509.h>
 | 
			
		||||
#include <openssl/rand.h>
 | 
			
		||||
#include <openssl/pem.h>
 | 
			
		||||
#ifndef OPENSSL_NO_COMP
 | 
			
		||||
# include <openssl/comp.h>
 | 
			
		||||
#endif
 | 
			
		||||
#include <ctype.h>
 | 
			
		||||
 | 
			
		||||
int set_hex(char *in, unsigned char *out, int size);
 | 
			
		||||
@@ -114,10 +111,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    char *hkey = NULL, *hiv = NULL, *hsalt = NULL;
 | 
			
		||||
    char *md = NULL;
 | 
			
		||||
    int enc = 1, printkey = 0, i, base64 = 0;
 | 
			
		||||
#ifdef ZLIB
 | 
			
		||||
    int do_zlib = 0;
 | 
			
		||||
    BIO *bzl = NULL;
 | 
			
		||||
#endif
 | 
			
		||||
    int debug = 0, olb64 = 0, nosalt = 0;
 | 
			
		||||
    const EVP_CIPHER *cipher = NULL, *c;
 | 
			
		||||
    EVP_CIPHER_CTX *ctx = NULL;
 | 
			
		||||
@@ -145,19 +138,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    program_name(argv[0], pname, sizeof pname);
 | 
			
		||||
    if (strcmp(pname, "base64") == 0)
 | 
			
		||||
        base64 = 1;
 | 
			
		||||
#ifdef ZLIB
 | 
			
		||||
    if (strcmp(pname, "zlib") == 0)
 | 
			
		||||
        do_zlib = 1;
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    cipher = EVP_get_cipherbyname(pname);
 | 
			
		||||
#ifdef ZLIB
 | 
			
		||||
    if (!do_zlib && !base64 && (cipher == NULL)
 | 
			
		||||
        && (strcmp(pname, "enc") != 0))
 | 
			
		||||
#else
 | 
			
		||||
    if (!base64 && (cipher == NULL) && (strcmp(pname, "enc") != 0))
 | 
			
		||||
#endif
 | 
			
		||||
    {
 | 
			
		||||
    if (!base64 && (cipher == NULL) && (strcmp(pname, "enc") != 0)) {
 | 
			
		||||
        BIO_printf(bio_err, "%s is an unknown cipher\n", pname);
 | 
			
		||||
        goto bad;
 | 
			
		||||
    }
 | 
			
		||||
@@ -209,10 +192,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            base64 = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-base64") == 0)
 | 
			
		||||
            base64 = 1;
 | 
			
		||||
#ifdef ZLIB
 | 
			
		||||
        else if (strcmp(*argv, "-z") == 0)
 | 
			
		||||
            do_zlib = 1;
 | 
			
		||||
#endif
 | 
			
		||||
        else if (strcmp(*argv, "-bufsize") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
@@ -296,15 +275,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "%-14s   from a passphrase.  One of md2, md5, sha or sha1\n",
 | 
			
		||||
                       "");
 | 
			
		||||
            BIO_printf(bio_err, "%-14s salt in hex is the next argument\n",
 | 
			
		||||
                       "-S");
 | 
			
		||||
            BIO_printf(bio_err, "%-14s key/iv in hex is the next argument\n",
 | 
			
		||||
                       "-K/-iv");
 | 
			
		||||
            BIO_printf(bio_err, "%-14s print the iv/key (then exit if -P)\n",
 | 
			
		||||
                       "-[pP]");
 | 
			
		||||
            BIO_printf(bio_err, "%-14s buffer size\n", "-bufsize <n>");
 | 
			
		||||
            BIO_printf(bio_err, "%-14s disable standard block padding\n",
 | 
			
		||||
                       "-nopad");
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
            BIO_printf(bio_err,
 | 
			
		||||
                       "%-14s use engine e, possibly a hardware device.\n",
 | 
			
		||||
@@ -326,24 +301,15 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    setup_engine(bio_err, engine, 0);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    if (cipher && EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) {
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "AEAD ciphers not supported by the enc utility\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (cipher && (EVP_CIPHER_mode(cipher) == EVP_CIPH_XTS_MODE)) {
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "Ciphers in XTS mode are not supported by the enc utility\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (md && (dgst = EVP_get_digestbyname(md)) == NULL) {
 | 
			
		||||
        BIO_printf(bio_err, "%s is an unsupported message digest type\n", md);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (dgst == NULL) {
 | 
			
		||||
        if (in_FIPS_mode)
 | 
			
		||||
            dgst = EVP_sha1();
 | 
			
		||||
        else
 | 
			
		||||
            dgst = EVP_md5();
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -396,10 +362,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (inf == NULL) {
 | 
			
		||||
#ifndef OPENSSL_NO_SETVBUF_IONBF
 | 
			
		||||
        if (bufsize != NULL)
 | 
			
		||||
            setvbuf(stdin, (char *)NULL, _IONBF, 0);
 | 
			
		||||
#endif                          /* ndef OPENSSL_NO_SETVBUF_IONBF */
 | 
			
		||||
        BIO_set_fp(in, stdin, BIO_NOCLOSE);
 | 
			
		||||
    } else {
 | 
			
		||||
        if (BIO_read_filename(in, inf) <= 0) {
 | 
			
		||||
@@ -442,10 +406,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    if (outf == NULL) {
 | 
			
		||||
        BIO_set_fp(out, stdout, BIO_NOCLOSE);
 | 
			
		||||
#ifndef OPENSSL_NO_SETVBUF_IONBF
 | 
			
		||||
        if (bufsize != NULL)
 | 
			
		||||
            setvbuf(stdout, (char *)NULL, _IONBF, 0);
 | 
			
		||||
#endif                          /* ndef OPENSSL_NO_SETVBUF_IONBF */
 | 
			
		||||
#ifdef OPENSSL_SYS_VMS
 | 
			
		||||
        {
 | 
			
		||||
            BIO *tmpbio = BIO_new(BIO_f_linebuffer());
 | 
			
		||||
@@ -462,18 +424,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    rbio = in;
 | 
			
		||||
    wbio = out;
 | 
			
		||||
 | 
			
		||||
#ifdef ZLIB
 | 
			
		||||
 | 
			
		||||
    if (do_zlib) {
 | 
			
		||||
        if ((bzl = BIO_new(BIO_f_zlib())) == NULL)
 | 
			
		||||
            goto end;
 | 
			
		||||
        if (enc)
 | 
			
		||||
            wbio = BIO_push(bzl, wbio);
 | 
			
		||||
        else
 | 
			
		||||
            rbio = BIO_push(bzl, rbio);
 | 
			
		||||
    }
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    if (base64) {
 | 
			
		||||
        if ((b64 = BIO_new(BIO_f_base64())) == NULL)
 | 
			
		||||
            goto end;
 | 
			
		||||
@@ -537,12 +487,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                sptr = salt;
 | 
			
		||||
            }
 | 
			
		||||
 | 
			
		||||
            if (!EVP_BytesToKey(cipher, dgst, sptr,
 | 
			
		||||
                                (unsigned char *)str,
 | 
			
		||||
                                strlen(str), 1, key, iv)) {
 | 
			
		||||
                BIO_printf(bio_err, "EVP_BytesToKey failed\n");
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
            EVP_BytesToKey(cipher, dgst, sptr,
 | 
			
		||||
                           (unsigned char *)str, strlen(str), 1, key, iv);
 | 
			
		||||
            /*
 | 
			
		||||
             * zero the complete buffer or the string passed from the command
 | 
			
		||||
             * line bug picked up by Larry J. Hughes Jr. <hughes@indiana.edu>
 | 
			
		||||
@@ -669,10 +615,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        BIO_free(benc);
 | 
			
		||||
    if (b64 != NULL)
 | 
			
		||||
        BIO_free(b64);
 | 
			
		||||
#ifdef ZLIB
 | 
			
		||||
    if (bzl != NULL)
 | 
			
		||||
        BIO_free(bzl);
 | 
			
		||||
#endif
 | 
			
		||||
    if (pass)
 | 
			
		||||
        OPENSSL_free(pass);
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
 
 | 
			
		||||
@@ -60,6 +60,9 @@
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <stdlib.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#ifdef OPENSSL_NO_STDIO
 | 
			
		||||
# define APPS_WIN16
 | 
			
		||||
#endif
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
@@ -89,7 +92,7 @@ static const char *engine_usage[] = {
 | 
			
		||||
    NULL
 | 
			
		||||
};
 | 
			
		||||
 | 
			
		||||
static void identity(char *ptr)
 | 
			
		||||
static void identity(void *ptr)
 | 
			
		||||
{
 | 
			
		||||
    return;
 | 
			
		||||
}
 | 
			
		||||
@@ -142,6 +145,10 @@ static int util_flags(BIO *bio_out, unsigned int flags, const char *indent)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (flags & ENGINE_CMD_FLAG_NUMERIC) {
 | 
			
		||||
        if (started) {
 | 
			
		||||
            BIO_printf(bio_out, "|");
 | 
			
		||||
            err = 1;
 | 
			
		||||
        }
 | 
			
		||||
        BIO_printf(bio_out, "NUMERIC");
 | 
			
		||||
        started = 1;
 | 
			
		||||
    }
 | 
			
		||||
@@ -192,7 +199,7 @@ static int util_verbose(ENGINE *e, int verbose, BIO *bio_out,
 | 
			
		||||
    char *desc = NULL;
 | 
			
		||||
    int flags;
 | 
			
		||||
    int xpos = 0;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *cmds = NULL;
 | 
			
		||||
    STACK *cmds = NULL;
 | 
			
		||||
    if (!ENGINE_ctrl(e, ENGINE_CTRL_HAS_CTRL_FUNCTION, 0, NULL, NULL) ||
 | 
			
		||||
        ((num = ENGINE_ctrl(e, ENGINE_CTRL_GET_FIRST_CMD_TYPE,
 | 
			
		||||
                            0, NULL, NULL)) <= 0)) {
 | 
			
		||||
@@ -202,7 +209,7 @@ static int util_verbose(ENGINE *e, int verbose, BIO *bio_out,
 | 
			
		||||
        return 1;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    cmds = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
    cmds = sk_new_null();
 | 
			
		||||
 | 
			
		||||
    if (!cmds)
 | 
			
		||||
        goto err;
 | 
			
		||||
@@ -274,7 +281,7 @@ static int util_verbose(ENGINE *e, int verbose, BIO *bio_out,
 | 
			
		||||
    ret = 1;
 | 
			
		||||
 err:
 | 
			
		||||
    if (cmds)
 | 
			
		||||
        sk_OPENSSL_STRING_pop_free(cmds, identity);
 | 
			
		||||
        sk_pop_free(cmds, identity);
 | 
			
		||||
    if (name)
 | 
			
		||||
        OPENSSL_free(name);
 | 
			
		||||
    if (desc)
 | 
			
		||||
@@ -282,11 +289,10 @@ static int util_verbose(ENGINE *e, int verbose, BIO *bio_out,
 | 
			
		||||
    return ret;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static void util_do_cmds(ENGINE *e, STACK_OF(OPENSSL_STRING) *cmds,
 | 
			
		||||
                         BIO *bio_out, const char *indent)
 | 
			
		||||
static void util_do_cmds(ENGINE *e, STACK * cmds, BIO *bio_out,
 | 
			
		||||
                         const char *indent)
 | 
			
		||||
{
 | 
			
		||||
    int loop, res, num = sk_OPENSSL_STRING_num(cmds);
 | 
			
		||||
 | 
			
		||||
    int loop, res, num = sk_num(cmds);
 | 
			
		||||
    if (num < 0) {
 | 
			
		||||
        BIO_printf(bio_out, "[Error]: internal stack error\n");
 | 
			
		||||
        return;
 | 
			
		||||
@@ -294,7 +300,7 @@ static void util_do_cmds(ENGINE *e, STACK_OF(OPENSSL_STRING) *cmds,
 | 
			
		||||
    for (loop = 0; loop < num; loop++) {
 | 
			
		||||
        char buf[256];
 | 
			
		||||
        const char *cmd, *arg;
 | 
			
		||||
        cmd = sk_OPENSSL_STRING_value(cmds, loop);
 | 
			
		||||
        cmd = sk_value(cmds, loop);
 | 
			
		||||
        res = 1;                /* assume success */
 | 
			
		||||
        /* Check if this command has no ":arg" */
 | 
			
		||||
        if ((arg = strstr(cmd, ":")) == NULL) {
 | 
			
		||||
@@ -329,9 +335,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    const char **pp;
 | 
			
		||||
    int verbose = 0, list_cap = 0, test_avail = 0, test_avail_noise = 0;
 | 
			
		||||
    ENGINE *e;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *engines = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *pre_cmds = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *post_cmds = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
    STACK *engines = sk_new_null();
 | 
			
		||||
    STACK *pre_cmds = sk_new_null();
 | 
			
		||||
    STACK *post_cmds = sk_new_null();
 | 
			
		||||
    int badops = 1;
 | 
			
		||||
    BIO *bio_out = NULL;
 | 
			
		||||
    const char *indent = "     ";
 | 
			
		||||
@@ -373,18 +379,18 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            argv++;
 | 
			
		||||
            if (argc == 0)
 | 
			
		||||
                goto skip_arg_loop;
 | 
			
		||||
            sk_OPENSSL_STRING_push(pre_cmds, *argv);
 | 
			
		||||
            sk_push(pre_cmds, *argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-post") == 0) {
 | 
			
		||||
            argc--;
 | 
			
		||||
            argv++;
 | 
			
		||||
            if (argc == 0)
 | 
			
		||||
                goto skip_arg_loop;
 | 
			
		||||
            sk_OPENSSL_STRING_push(post_cmds, *argv);
 | 
			
		||||
            sk_push(post_cmds, *argv);
 | 
			
		||||
        } else if ((strncmp(*argv, "-h", 2) == 0) ||
 | 
			
		||||
                   (strcmp(*argv, "-?") == 0))
 | 
			
		||||
            goto skip_arg_loop;
 | 
			
		||||
        else
 | 
			
		||||
            sk_OPENSSL_STRING_push(engines, *argv);
 | 
			
		||||
            sk_push(engines, *argv);
 | 
			
		||||
        argc--;
 | 
			
		||||
        argv++;
 | 
			
		||||
    }
 | 
			
		||||
@@ -398,14 +404,14 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (sk_OPENSSL_STRING_num(engines) == 0) {
 | 
			
		||||
    if (sk_num(engines) == 0) {
 | 
			
		||||
        for (e = ENGINE_get_first(); e != NULL; e = ENGINE_get_next(e)) {
 | 
			
		||||
            sk_OPENSSL_STRING_push(engines, (char *)ENGINE_get_id(e));
 | 
			
		||||
            sk_push(engines, (char *)ENGINE_get_id(e));
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    for (i = 0; i < sk_OPENSSL_STRING_num(engines); i++) {
 | 
			
		||||
        const char *id = sk_OPENSSL_STRING_value(engines, i);
 | 
			
		||||
    for (i = 0; i < sk_num(engines); i++) {
 | 
			
		||||
        const char *id = sk_value(engines, i);
 | 
			
		||||
        if ((e = ENGINE_by_id(id)) != NULL) {
 | 
			
		||||
            const char *name = ENGINE_get_name(e);
 | 
			
		||||
            /*
 | 
			
		||||
@@ -424,7 +430,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                const int *nids;
 | 
			
		||||
                ENGINE_CIPHERS_PTR fn_c;
 | 
			
		||||
                ENGINE_DIGESTS_PTR fn_d;
 | 
			
		||||
                ENGINE_PKEY_METHS_PTR fn_pk;
 | 
			
		||||
 | 
			
		||||
                if (ENGINE_get_RSA(e) != NULL
 | 
			
		||||
                    && !append_buf(&cap_buf, "RSA", &cap_size, 256))
 | 
			
		||||
@@ -459,15 +464,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                        goto end;
 | 
			
		||||
 | 
			
		||||
 skip_digests:
 | 
			
		||||
                fn_pk = ENGINE_get_pkey_meths(e);
 | 
			
		||||
                if (!fn_pk)
 | 
			
		||||
                    goto skip_pmeths;
 | 
			
		||||
                n = fn_pk(e, NULL, &nids, 0);
 | 
			
		||||
                for (k = 0; k < n; ++k)
 | 
			
		||||
                    if (!append_buf(&cap_buf,
 | 
			
		||||
                                    OBJ_nid2sn(nids[k]), &cap_size, 256))
 | 
			
		||||
                        goto end;
 | 
			
		||||
 skip_pmeths:
 | 
			
		||||
                if (cap_buf && (*cap_buf != '\0'))
 | 
			
		||||
                    BIO_printf(bio_out, " [%s]\n", cap_buf);
 | 
			
		||||
 | 
			
		||||
@@ -497,9 +493,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 end:
 | 
			
		||||
 | 
			
		||||
    ERR_print_errors(bio_err);
 | 
			
		||||
    sk_OPENSSL_STRING_pop_free(engines, identity);
 | 
			
		||||
    sk_OPENSSL_STRING_pop_free(pre_cmds, identity);
 | 
			
		||||
    sk_OPENSSL_STRING_pop_free(post_cmds, identity);
 | 
			
		||||
    sk_pop_free(engines, identity);
 | 
			
		||||
    sk_pop_free(pre_cmds, identity);
 | 
			
		||||
    sk_pop_free(post_cmds, identity);
 | 
			
		||||
    if (bio_out != NULL)
 | 
			
		||||
        BIO_free_all(bio_out);
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
 
 | 
			
		||||
@@ -95,10 +95,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                out = BIO_push(tmpbio, out);
 | 
			
		||||
            }
 | 
			
		||||
#endif
 | 
			
		||||
            lh_ERR_STRING_DATA_node_stats_bio(ERR_get_string_table(), out);
 | 
			
		||||
            lh_ERR_STRING_DATA_stats_bio(ERR_get_string_table(), out);
 | 
			
		||||
            lh_ERR_STRING_DATA_node_usage_stats_bio(ERR_get_string_table(),
 | 
			
		||||
                                                    out);
 | 
			
		||||
            lh_node_stats_bio((LHASH *)ERR_get_string_table(), out);
 | 
			
		||||
            lh_stats_bio((LHASH *)ERR_get_string_table(), out);
 | 
			
		||||
            lh_node_usage_stats_bio((LHASH *)
 | 
			
		||||
                                    ERR_get_string_table(), out);
 | 
			
		||||
        }
 | 
			
		||||
        if (out != NULL)
 | 
			
		||||
            BIO_free_all(out);
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										39
									
								
								apps/gendh.c
									
									
									
									
									
								
							
							
						
						
									
										39
									
								
								apps/gendh.c
									
									
									
									
									
								
							@@ -58,6 +58,13 @@
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
#include <openssl/opensslconf.h>
 | 
			
		||||
/*
 | 
			
		||||
 * Until the key-gen callbacks are modified to use newer prototypes, we allow
 | 
			
		||||
 * deprecated functions for openssl-internal code
 | 
			
		||||
 */
 | 
			
		||||
#ifdef OPENSSL_NO_DEPRECATED
 | 
			
		||||
# undef OPENSSL_NO_DEPRECATED
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#ifndef OPENSSL_NO_DH
 | 
			
		||||
# include <stdio.h>
 | 
			
		||||
@@ -73,17 +80,17 @@
 | 
			
		||||
# include <openssl/x509.h>
 | 
			
		||||
# include <openssl/pem.h>
 | 
			
		||||
 | 
			
		||||
# define DEFBITS 2048
 | 
			
		||||
# define DEFBITS 512
 | 
			
		||||
# undef PROG
 | 
			
		||||
# define PROG gendh_main
 | 
			
		||||
 | 
			
		||||
static int dh_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
static int MS_CALLBACK dh_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    BN_GENCB *cb = NULL;
 | 
			
		||||
    BN_GENCB cb;
 | 
			
		||||
    DH *dh = NULL;
 | 
			
		||||
    int ret = 1, num = DEFBITS;
 | 
			
		||||
    int g = 2;
 | 
			
		||||
@@ -96,16 +103,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
    BN_GENCB_set(&cb, dh_cb, bio_err);
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        if ((bio_err = BIO_new(BIO_s_file())) != NULL)
 | 
			
		||||
            BIO_set_fp(bio_err, stderr, BIO_NOCLOSE | BIO_FP_TEXT);
 | 
			
		||||
 | 
			
		||||
    cb = BN_GENCB_new();
 | 
			
		||||
    if (!cb)
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    BN_GENCB_set(cb, dh_cb, bio_err);
 | 
			
		||||
 | 
			
		||||
    if (!load_config(bio_err, NULL))
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
@@ -199,7 +201,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    BIO_printf(bio_err, "This is going to take a long time\n");
 | 
			
		||||
 | 
			
		||||
    if (((dh = DH_new()) == NULL)
 | 
			
		||||
        || !DH_generate_parameters_ex(dh, num, g, cb))
 | 
			
		||||
        || !DH_generate_parameters_ex(dh, num, g, &cb))
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    app_RAND_write_file(NULL, bio_err);
 | 
			
		||||
@@ -214,13 +216,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        BIO_free_all(out);
 | 
			
		||||
    if (dh != NULL)
 | 
			
		||||
        DH_free(dh);
 | 
			
		||||
    if (cb != NULL)
 | 
			
		||||
        BN_GENCB_free(cb);
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int dh_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
static int MS_CALLBACK dh_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
{
 | 
			
		||||
    char c = '*';
 | 
			
		||||
 | 
			
		||||
@@ -232,14 +232,11 @@ static int dh_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
        c = '*';
 | 
			
		||||
    if (p == 3)
 | 
			
		||||
        c = '\n';
 | 
			
		||||
    BIO_write(BN_GENCB_get_arg(cb), &c, 1);
 | 
			
		||||
    (void)BIO_flush(BN_GENCB_get_arg(cb));
 | 
			
		||||
    BIO_write(cb->arg, &c, 1);
 | 
			
		||||
    (void)BIO_flush(cb->arg);
 | 
			
		||||
# ifdef LINT
 | 
			
		||||
    p = n;
 | 
			
		||||
# endif
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
#else                           /* !OPENSSL_NO_DH */
 | 
			
		||||
 | 
			
		||||
# if PEDANTIC
 | 
			
		||||
static void *dummy = &dummy;
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										402
									
								
								apps/genpkey.c
									
									
									
									
									
								
							
							
						
						
									
										402
									
								
								apps/genpkey.c
									
									
									
									
									
								
							@@ -1,402 +0,0 @@
 | 
			
		||||
/* apps/genpkey.c */
 | 
			
		||||
/*
 | 
			
		||||
 * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL project
 | 
			
		||||
 * 2006
 | 
			
		||||
 */
 | 
			
		||||
/* ====================================================================
 | 
			
		||||
 * Copyright (c) 2006 The OpenSSL Project.  All rights reserved.
 | 
			
		||||
 *
 | 
			
		||||
 * Redistribution and use in source and binary forms, with or without
 | 
			
		||||
 * modification, are permitted provided that the following conditions
 | 
			
		||||
 * are met:
 | 
			
		||||
 *
 | 
			
		||||
 * 1. Redistributions of source code must retain the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer.
 | 
			
		||||
 *
 | 
			
		||||
 * 2. Redistributions in binary form must reproduce the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer in
 | 
			
		||||
 *    the documentation and/or other materials provided with the
 | 
			
		||||
 *    distribution.
 | 
			
		||||
 *
 | 
			
		||||
 * 3. All advertising materials mentioning features or use of this
 | 
			
		||||
 *    software must display the following acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
 | 
			
		||||
 *    endorse or promote products derived from this software without
 | 
			
		||||
 *    prior written permission. For written permission, please contact
 | 
			
		||||
 *    licensing@OpenSSL.org.
 | 
			
		||||
 *
 | 
			
		||||
 * 5. Products derived from this software may not be called "OpenSSL"
 | 
			
		||||
 *    nor may "OpenSSL" appear in their names without prior written
 | 
			
		||||
 *    permission of the OpenSSL Project.
 | 
			
		||||
 *
 | 
			
		||||
 * 6. Redistributions of any form whatsoever must retain the following
 | 
			
		||||
 *    acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
 | 
			
		||||
 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 | 
			
		||||
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
 | 
			
		||||
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
 | 
			
		||||
 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
 | 
			
		||||
 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
 | 
			
		||||
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
 | 
			
		||||
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 | 
			
		||||
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
 | 
			
		||||
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
 | 
			
		||||
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
 | 
			
		||||
 * OF THE POSSIBILITY OF SUCH DAMAGE.
 | 
			
		||||
 * ====================================================================
 | 
			
		||||
 *
 | 
			
		||||
 * This product includes cryptographic software written by Eric Young
 | 
			
		||||
 * (eay@cryptsoft.com).  This product includes software written by Tim
 | 
			
		||||
 * Hudson (tjh@cryptsoft.com).
 | 
			
		||||
 *
 | 
			
		||||
 */
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/pem.h>
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#include <openssl/evp.h>
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
# include <openssl/engine.h>
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
static int init_keygen_file(BIO *err, EVP_PKEY_CTX **pctx,
 | 
			
		||||
                            const char *file, ENGINE *e);
 | 
			
		||||
static int genpkey_cb(EVP_PKEY_CTX *ctx);
 | 
			
		||||
 | 
			
		||||
#define PROG genpkey_main
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    ENGINE *e = NULL;
 | 
			
		||||
    char **args, *outfile = NULL;
 | 
			
		||||
    char *passarg = NULL;
 | 
			
		||||
    BIO *in = NULL, *out = NULL;
 | 
			
		||||
    const EVP_CIPHER *cipher = NULL;
 | 
			
		||||
    int outformat;
 | 
			
		||||
    int text = 0;
 | 
			
		||||
    EVP_PKEY *pkey = NULL;
 | 
			
		||||
    EVP_PKEY_CTX *ctx = NULL;
 | 
			
		||||
    char *pass = NULL;
 | 
			
		||||
    int badarg = 0;
 | 
			
		||||
    int ret = 1, rv;
 | 
			
		||||
 | 
			
		||||
    int do_param = 0;
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        bio_err = BIO_new_fp(stderr, BIO_NOCLOSE);
 | 
			
		||||
 | 
			
		||||
    if (!load_config(bio_err, NULL))
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    outformat = FORMAT_PEM;
 | 
			
		||||
 | 
			
		||||
    ERR_load_crypto_strings();
 | 
			
		||||
    OpenSSL_add_all_algorithms();
 | 
			
		||||
    args = argv + 1;
 | 
			
		||||
    while (!badarg && *args && *args[0] == '-') {
 | 
			
		||||
        if (!strcmp(*args, "-outform")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                outformat = str2fmt(*args);
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-pass")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            passarg = *(++args);
 | 
			
		||||
        }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        else if (strcmp(*args, "-engine") == 0) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            e = setup_engine(bio_err, *(++args), 0);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
        else if (!strcmp(*args, "-paramfile")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            args++;
 | 
			
		||||
            if (do_param == 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            if (!init_keygen_file(bio_err, &ctx, *args, e))
 | 
			
		||||
                goto end;
 | 
			
		||||
        } else if (!strcmp(*args, "-out")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                outfile = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (strcmp(*args, "-algorithm") == 0) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            if (!init_gen_str(bio_err, &ctx, *(++args), e, do_param))
 | 
			
		||||
                goto end;
 | 
			
		||||
        } else if (strcmp(*args, "-pkeyopt") == 0) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            if (!ctx) {
 | 
			
		||||
                BIO_puts(bio_err, "No keytype specified\n");
 | 
			
		||||
                goto bad;
 | 
			
		||||
            } else if (pkey_ctrl_string(ctx, *(++args)) <= 0) {
 | 
			
		||||
                BIO_puts(bio_err, "parameter setting error\n");
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        } else if (strcmp(*args, "-genparam") == 0) {
 | 
			
		||||
            if (ctx)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            do_param = 1;
 | 
			
		||||
        } else if (strcmp(*args, "-text") == 0)
 | 
			
		||||
            text = 1;
 | 
			
		||||
        else {
 | 
			
		||||
            cipher = EVP_get_cipherbyname(*args + 1);
 | 
			
		||||
            if (!cipher) {
 | 
			
		||||
                BIO_printf(bio_err, "Unknown cipher %s\n", *args + 1);
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            }
 | 
			
		||||
            if (do_param == 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        }
 | 
			
		||||
        args++;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!ctx)
 | 
			
		||||
        badarg = 1;
 | 
			
		||||
 | 
			
		||||
    if (badarg) {
 | 
			
		||||
 bad:
 | 
			
		||||
        BIO_printf(bio_err, "Usage: genpkey [options]\n");
 | 
			
		||||
        BIO_printf(bio_err, "where options may be\n");
 | 
			
		||||
        BIO_printf(bio_err, "-out file          output file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-outform X         output format (DER or PEM)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-pass arg          output file pass phrase source\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-<cipher>          use cipher <cipher> to encrypt the key\n");
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-engine e          use engine e, possibly a hardware device.\n");
 | 
			
		||||
#endif
 | 
			
		||||
        BIO_printf(bio_err, "-paramfile file    parameters file\n");
 | 
			
		||||
        BIO_printf(bio_err, "-algorithm alg     the public key algorithm\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-pkeyopt opt:value set the public key algorithm option <opt>\n"
 | 
			
		||||
                   "                   to value <value>\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-genparam          generate parameters, not key\n");
 | 
			
		||||
        BIO_printf(bio_err, "-text              print the in text\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "NB: options order may be important!  See the manual page.\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!app_passwd(bio_err, passarg, NULL, &pass, NULL)) {
 | 
			
		||||
        BIO_puts(bio_err, "Error getting password\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (outfile) {
 | 
			
		||||
        if (!(out = BIO_new_file(outfile, "wb"))) {
 | 
			
		||||
            BIO_printf(bio_err, "Can't open output file %s\n", outfile);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        out = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
#ifdef OPENSSL_SYS_VMS
 | 
			
		||||
        {
 | 
			
		||||
            BIO *tmpbio = BIO_new(BIO_f_linebuffer());
 | 
			
		||||
            out = BIO_push(tmpbio, out);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    EVP_PKEY_CTX_set_cb(ctx, genpkey_cb);
 | 
			
		||||
    EVP_PKEY_CTX_set_app_data(ctx, bio_err);
 | 
			
		||||
 | 
			
		||||
    if (do_param) {
 | 
			
		||||
        if (EVP_PKEY_paramgen(ctx, &pkey) <= 0) {
 | 
			
		||||
            BIO_puts(bio_err, "Error generating parameters\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        if (EVP_PKEY_keygen(ctx, &pkey) <= 0) {
 | 
			
		||||
            BIO_puts(bio_err, "Error generating key\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (do_param)
 | 
			
		||||
        rv = PEM_write_bio_Parameters(out, pkey);
 | 
			
		||||
    else if (outformat == FORMAT_PEM)
 | 
			
		||||
        rv = PEM_write_bio_PrivateKey(out, pkey, cipher, NULL, 0, NULL, pass);
 | 
			
		||||
    else if (outformat == FORMAT_ASN1)
 | 
			
		||||
        rv = i2d_PrivateKey_bio(out, pkey);
 | 
			
		||||
    else {
 | 
			
		||||
        BIO_printf(bio_err, "Bad format specified for key\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (rv <= 0) {
 | 
			
		||||
        BIO_puts(bio_err, "Error writing key\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (text) {
 | 
			
		||||
        if (do_param)
 | 
			
		||||
            rv = EVP_PKEY_print_params(out, pkey, 0, NULL);
 | 
			
		||||
        else
 | 
			
		||||
            rv = EVP_PKEY_print_private(out, pkey, 0, NULL);
 | 
			
		||||
 | 
			
		||||
        if (rv <= 0) {
 | 
			
		||||
            BIO_puts(bio_err, "Error printing key\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
    if (pkey)
 | 
			
		||||
        EVP_PKEY_free(pkey);
 | 
			
		||||
    if (ctx)
 | 
			
		||||
        EVP_PKEY_CTX_free(ctx);
 | 
			
		||||
    if (out)
 | 
			
		||||
        BIO_free_all(out);
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
    if (pass)
 | 
			
		||||
        OPENSSL_free(pass);
 | 
			
		||||
 | 
			
		||||
    return ret;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int init_keygen_file(BIO *err, EVP_PKEY_CTX **pctx,
 | 
			
		||||
                            const char *file, ENGINE *e)
 | 
			
		||||
{
 | 
			
		||||
    BIO *pbio;
 | 
			
		||||
    EVP_PKEY *pkey = NULL;
 | 
			
		||||
    EVP_PKEY_CTX *ctx = NULL;
 | 
			
		||||
    if (*pctx) {
 | 
			
		||||
        BIO_puts(err, "Parameters already set!\n");
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    pbio = BIO_new_file(file, "r");
 | 
			
		||||
    if (!pbio) {
 | 
			
		||||
        BIO_printf(err, "Can't open parameter file %s\n", file);
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    pkey = PEM_read_bio_Parameters(pbio, NULL);
 | 
			
		||||
    BIO_free(pbio);
 | 
			
		||||
 | 
			
		||||
    if (!pkey) {
 | 
			
		||||
        BIO_printf(bio_err, "Error reading parameter file %s\n", file);
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ctx = EVP_PKEY_CTX_new(pkey, e);
 | 
			
		||||
    if (!ctx)
 | 
			
		||||
        goto err;
 | 
			
		||||
    if (EVP_PKEY_keygen_init(ctx) <= 0)
 | 
			
		||||
        goto err;
 | 
			
		||||
    EVP_PKEY_free(pkey);
 | 
			
		||||
    *pctx = ctx;
 | 
			
		||||
    return 1;
 | 
			
		||||
 | 
			
		||||
 err:
 | 
			
		||||
    BIO_puts(err, "Error initializing context\n");
 | 
			
		||||
    ERR_print_errors(err);
 | 
			
		||||
    if (ctx)
 | 
			
		||||
        EVP_PKEY_CTX_free(ctx);
 | 
			
		||||
    if (pkey)
 | 
			
		||||
        EVP_PKEY_free(pkey);
 | 
			
		||||
    return 0;
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
int init_gen_str(BIO *err, EVP_PKEY_CTX **pctx,
 | 
			
		||||
                 const char *algname, ENGINE *e, int do_param)
 | 
			
		||||
{
 | 
			
		||||
    EVP_PKEY_CTX *ctx = NULL;
 | 
			
		||||
    const EVP_PKEY_ASN1_METHOD *ameth;
 | 
			
		||||
    ENGINE *tmpeng = NULL;
 | 
			
		||||
    int pkey_id;
 | 
			
		||||
 | 
			
		||||
    if (*pctx) {
 | 
			
		||||
        BIO_puts(err, "Algorithm already set!\n");
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ameth = EVP_PKEY_asn1_find_str(&tmpeng, algname, -1);
 | 
			
		||||
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    if (!ameth && e)
 | 
			
		||||
        ameth = ENGINE_get_pkey_asn1_meth_str(e, algname, -1);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    if (!ameth) {
 | 
			
		||||
        BIO_printf(bio_err, "Algorithm %s not found\n", algname);
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ERR_clear_error();
 | 
			
		||||
 | 
			
		||||
    EVP_PKEY_asn1_get0_info(&pkey_id, NULL, NULL, NULL, NULL, ameth);
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    if (tmpeng)
 | 
			
		||||
        ENGINE_finish(tmpeng);
 | 
			
		||||
#endif
 | 
			
		||||
    ctx = EVP_PKEY_CTX_new_id(pkey_id, e);
 | 
			
		||||
 | 
			
		||||
    if (!ctx)
 | 
			
		||||
        goto err;
 | 
			
		||||
    if (do_param) {
 | 
			
		||||
        if (EVP_PKEY_paramgen_init(ctx) <= 0)
 | 
			
		||||
            goto err;
 | 
			
		||||
    } else {
 | 
			
		||||
        if (EVP_PKEY_keygen_init(ctx) <= 0)
 | 
			
		||||
            goto err;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    *pctx = ctx;
 | 
			
		||||
    return 1;
 | 
			
		||||
 | 
			
		||||
 err:
 | 
			
		||||
    BIO_printf(err, "Error initializing %s context\n", algname);
 | 
			
		||||
    ERR_print_errors(err);
 | 
			
		||||
    if (ctx)
 | 
			
		||||
        EVP_PKEY_CTX_free(ctx);
 | 
			
		||||
    return 0;
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int genpkey_cb(EVP_PKEY_CTX *ctx)
 | 
			
		||||
{
 | 
			
		||||
    char c = '*';
 | 
			
		||||
    BIO *b = EVP_PKEY_CTX_get_app_data(ctx);
 | 
			
		||||
    int p;
 | 
			
		||||
    p = EVP_PKEY_CTX_get_keygen_info(ctx, 0);
 | 
			
		||||
    if (p == 0)
 | 
			
		||||
        c = '.';
 | 
			
		||||
    if (p == 1)
 | 
			
		||||
        c = '+';
 | 
			
		||||
    if (p == 2)
 | 
			
		||||
        c = '*';
 | 
			
		||||
    if (p == 3)
 | 
			
		||||
        c = '\n';
 | 
			
		||||
    BIO_write(b, &c, 1);
 | 
			
		||||
    (void)BIO_flush(b);
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
@@ -57,6 +57,13 @@
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
#include <openssl/opensslconf.h>
 | 
			
		||||
/*
 | 
			
		||||
 * Until the key-gen callbacks are modified to use newer prototypes, we allow
 | 
			
		||||
 * deprecated functions for openssl-internal code
 | 
			
		||||
 */
 | 
			
		||||
#ifdef OPENSSL_NO_DEPRECATED
 | 
			
		||||
# undef OPENSSL_NO_DEPRECATED
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#ifndef OPENSSL_NO_RSA
 | 
			
		||||
# include <stdio.h>
 | 
			
		||||
@@ -73,28 +80,25 @@
 | 
			
		||||
# include <openssl/pem.h>
 | 
			
		||||
# include <openssl/rand.h>
 | 
			
		||||
 | 
			
		||||
# define DEFBITS 2048
 | 
			
		||||
# define DEFBITS 512
 | 
			
		||||
# undef PROG
 | 
			
		||||
# define PROG genrsa_main
 | 
			
		||||
 | 
			
		||||
static int genrsa_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
static int MS_CALLBACK genrsa_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    BN_GENCB *cb = NULL;
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    ENGINE *e = NULL;
 | 
			
		||||
# endif
 | 
			
		||||
    BN_GENCB cb;
 | 
			
		||||
    int ret = 1;
 | 
			
		||||
    int non_fips_allow = 0;
 | 
			
		||||
    int num = DEFBITS;
 | 
			
		||||
    int i, num = DEFBITS;
 | 
			
		||||
    long l;
 | 
			
		||||
    int use_x931 = 0;
 | 
			
		||||
    const EVP_CIPHER *enc = NULL;
 | 
			
		||||
    unsigned long f4 = RSA_F4;
 | 
			
		||||
    char *outfile = NULL;
 | 
			
		||||
    char *passargout = NULL, *passout = NULL;
 | 
			
		||||
    char *hexe, *dece;
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
# endif
 | 
			
		||||
@@ -102,16 +106,12 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    BIO *out = NULL;
 | 
			
		||||
    BIGNUM *bn = BN_new();
 | 
			
		||||
    RSA *rsa = NULL;
 | 
			
		||||
 | 
			
		||||
    if (!bn)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    cb = BN_GENCB_new();
 | 
			
		||||
    if (!cb)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
    BN_GENCB_set(cb, genrsa_cb, bio_err);
 | 
			
		||||
    BN_GENCB_set(&cb, genrsa_cb, bio_err);
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        if ((bio_err = BIO_new(BIO_s_file())) != NULL)
 | 
			
		||||
@@ -137,6 +137,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            f4 = 3;
 | 
			
		||||
        else if (strcmp(*argv, "-F4") == 0 || strcmp(*argv, "-f4") == 0)
 | 
			
		||||
            f4 = RSA_F4;
 | 
			
		||||
        else if (strcmp(*argv, "-x931") == 0)
 | 
			
		||||
            use_x931 = 1;
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        else if (strcmp(*argv, "-engine") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
@@ -183,9 +185,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            passargout = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-non-fips-allow") == 0)
 | 
			
		||||
            non_fips_allow = 1;
 | 
			
		||||
        else
 | 
			
		||||
        } else
 | 
			
		||||
            break;
 | 
			
		||||
        argv++;
 | 
			
		||||
        argc--;
 | 
			
		||||
@@ -241,7 +241,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto err;
 | 
			
		||||
    }
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    e = setup_engine(bio_err, engine, 0);
 | 
			
		||||
    setup_engine(bio_err, engine, 0);
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
    if (outfile == NULL) {
 | 
			
		||||
@@ -270,31 +270,38 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    BIO_printf(bio_err, "Generating RSA private key, %d bit long modulus\n",
 | 
			
		||||
               num);
 | 
			
		||||
# ifdef OPENSSL_NO_ENGINE
 | 
			
		||||
 | 
			
		||||
    rsa = RSA_new();
 | 
			
		||||
# else
 | 
			
		||||
    rsa = RSA_new_method(e);
 | 
			
		||||
# endif
 | 
			
		||||
    if (!rsa)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    if (non_fips_allow)
 | 
			
		||||
        rsa->flags |= RSA_FLAG_NON_FIPS_ALLOW;
 | 
			
		||||
 | 
			
		||||
    if (!BN_set_word(bn, f4) || !RSA_generate_key_ex(rsa, num, bn, cb))
 | 
			
		||||
    if (use_x931) {
 | 
			
		||||
        BIGNUM *pubexp;
 | 
			
		||||
        pubexp = BN_new();
 | 
			
		||||
        if (!BN_set_word(pubexp, f4))
 | 
			
		||||
            goto err;
 | 
			
		||||
        if (!RSA_X931_generate_key_ex(rsa, num, pubexp, &cb))
 | 
			
		||||
            goto err;
 | 
			
		||||
        BN_free(pubexp);
 | 
			
		||||
    } else if (!BN_set_word(bn, f4)
 | 
			
		||||
               || !RSA_generate_key_ex(rsa, num, bn, &cb))
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    app_RAND_write_file(NULL, bio_err);
 | 
			
		||||
 | 
			
		||||
    hexe = BN_bn2hex(rsa->e);
 | 
			
		||||
    dece = BN_bn2dec(rsa->e);
 | 
			
		||||
    if (hexe && dece) {
 | 
			
		||||
        BIO_printf(bio_err, "e is %s (0x%s)\n", dece, hexe);
 | 
			
		||||
    /*
 | 
			
		||||
     * We need to do the following for when the base number size is < long,
 | 
			
		||||
     * esp windows 3.1 :-(.
 | 
			
		||||
     */
 | 
			
		||||
    l = 0L;
 | 
			
		||||
    for (i = 0; i < rsa->e->top; i++) {
 | 
			
		||||
# ifndef SIXTY_FOUR_BIT
 | 
			
		||||
        l <<= BN_BITS4;
 | 
			
		||||
        l <<= BN_BITS4;
 | 
			
		||||
# endif
 | 
			
		||||
        l += rsa->e->d[i];
 | 
			
		||||
    }
 | 
			
		||||
    if (hexe)
 | 
			
		||||
        OPENSSL_free(hexe);
 | 
			
		||||
    if (dece)
 | 
			
		||||
        OPENSSL_free(dece);
 | 
			
		||||
    BIO_printf(bio_err, "e is %ld (0x%lX)\n", l, l);
 | 
			
		||||
    {
 | 
			
		||||
        PW_CB_DATA cb_data;
 | 
			
		||||
        cb_data.password = passout;
 | 
			
		||||
@@ -309,8 +316,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 err:
 | 
			
		||||
    if (bn)
 | 
			
		||||
        BN_free(bn);
 | 
			
		||||
    if (cb)
 | 
			
		||||
        BN_GENCB_free(cb);
 | 
			
		||||
    if (rsa)
 | 
			
		||||
        RSA_free(rsa);
 | 
			
		||||
    if (out)
 | 
			
		||||
@@ -323,7 +328,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int genrsa_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
static int MS_CALLBACK genrsa_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
{
 | 
			
		||||
    char c = '*';
 | 
			
		||||
 | 
			
		||||
@@ -335,8 +340,11 @@ static int genrsa_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
        c = '*';
 | 
			
		||||
    if (p == 3)
 | 
			
		||||
        c = '\n';
 | 
			
		||||
    BIO_write(BN_GENCB_get_arg(cb), &c, 1);
 | 
			
		||||
    (void)BIO_flush(BN_GENCB_get_arg(cb));
 | 
			
		||||
    BIO_write(cb->arg, &c, 1);
 | 
			
		||||
    (void)BIO_flush(cb->arg);
 | 
			
		||||
# ifdef LINT
 | 
			
		||||
    p = n;
 | 
			
		||||
# endif
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
#else                           /* !OPENSSL_NO_RSA */
 | 
			
		||||
 
 | 
			
		||||
@@ -1,107 +0,0 @@
 | 
			
		||||
$! INSTALL.COM -- Installs the files in a given directory tree
 | 
			
		||||
$!
 | 
			
		||||
$! Author: Richard Levitte <richard@levitte.org>
 | 
			
		||||
$! Time of creation: 22-MAY-1998 10:13
 | 
			
		||||
$!
 | 
			
		||||
$! P1  root of the directory tree
 | 
			
		||||
$! P2  "64" for 64-bit pointers.
 | 
			
		||||
$!
 | 
			
		||||
$!
 | 
			
		||||
$! Announce/identify.
 | 
			
		||||
$!
 | 
			
		||||
$ proc = f$environment( "procedure")
 | 
			
		||||
$ write sys$output "@@@ "+ -
 | 
			
		||||
   f$parse( proc, , , "name")+ f$parse( proc, , , "type")
 | 
			
		||||
$!
 | 
			
		||||
$ on error then goto tidy
 | 
			
		||||
$ on control_c then goto tidy
 | 
			
		||||
$!
 | 
			
		||||
$ if (p1 .eqs. "")
 | 
			
		||||
$ then
 | 
			
		||||
$   write sys$output "First argument missing."
 | 
			
		||||
$   write sys$output -
 | 
			
		||||
     "It should be the directory where you want things installed."
 | 
			
		||||
$   exit
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$getsyi("cpu") .lt. 128)
 | 
			
		||||
$ then
 | 
			
		||||
$   arch = "VAX"
 | 
			
		||||
$ else
 | 
			
		||||
$   arch = f$edit( f$getsyi( "arch_name"), "upcase")
 | 
			
		||||
$   if (arch .eqs. "") then arch = "UNK"
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ archd = arch
 | 
			
		||||
$!
 | 
			
		||||
$ if (p2 .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$   if (p2 .eqs. "64")
 | 
			
		||||
$   then
 | 
			
		||||
$     archd = arch+ "_64"
 | 
			
		||||
$   else
 | 
			
		||||
$     if (p2 .nes. "32")
 | 
			
		||||
$     then
 | 
			
		||||
$       write sys$output "Second argument invalid."
 | 
			
		||||
$       write sys$output "It should be "32", "64", or nothing."
 | 
			
		||||
$       exit
 | 
			
		||||
$     endif
 | 
			
		||||
$   endif
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$ root = f$parse( p1, "[]A.;0", , , "syntax_only, no_conceal") - "A.;0"
 | 
			
		||||
$ root_dev = f$parse(root,,,"device","syntax_only")
 | 
			
		||||
$ root_dir = f$parse(root,,,"directory","syntax_only") - -
 | 
			
		||||
   "[000000." - "][" - "[" - "]"
 | 
			
		||||
$ root = root_dev + "[" + root_dir
 | 
			
		||||
$!
 | 
			
		||||
$ define /nolog wrk_sslroot 'root'.] /trans=conc
 | 
			
		||||
$ define /nolog wrk_sslxexe wrk_sslroot:['archd'_exe]
 | 
			
		||||
$!
 | 
			
		||||
$ if f$parse("wrk_sslroot:[000000]") .eqs. "" then -
 | 
			
		||||
   create /directory /log wrk_sslroot:[000000]
 | 
			
		||||
$ if f$parse("wrk_sslxexe:") .eqs. "" then -
 | 
			
		||||
   create /directory /log wrk_sslxexe:
 | 
			
		||||
$!
 | 
			
		||||
$ exe := openssl
 | 
			
		||||
$!
 | 
			
		||||
$ exe_dir := [-.'archd'.exe.apps]
 | 
			
		||||
$!
 | 
			
		||||
$! Executables.
 | 
			
		||||
$!
 | 
			
		||||
$ i = 0
 | 
			
		||||
$ loop_exe:
 | 
			
		||||
$   e = f$edit(f$element( i, ",", exe), "trim")
 | 
			
		||||
$   i = i + 1
 | 
			
		||||
$   if e .eqs. "," then goto loop_exe_end
 | 
			
		||||
$   set noon
 | 
			
		||||
$   file = exe_dir+ e+ ".exe"
 | 
			
		||||
$   if f$search( file) .nes. ""
 | 
			
		||||
$   then
 | 
			
		||||
$     copy /protection = w:re 'file' wrk_sslxexe: /log
 | 
			
		||||
$   endif
 | 
			
		||||
$   set on
 | 
			
		||||
$ goto loop_exe
 | 
			
		||||
$ loop_exe_end:
 | 
			
		||||
$!
 | 
			
		||||
$! Miscellaneous.
 | 
			
		||||
$!
 | 
			
		||||
$ set noon
 | 
			
		||||
$ copy /protection = w:re ca.com wrk_sslxexe:ca.com /log
 | 
			
		||||
$ copy /protection = w:re openssl-vms.cnf wrk_sslroot:[000000]openssl.cnf /log
 | 
			
		||||
$ set on
 | 
			
		||||
$!
 | 
			
		||||
$ tidy:
 | 
			
		||||
$!
 | 
			
		||||
$ call deass wrk_sslroot
 | 
			
		||||
$ call deass wrk_sslxexe
 | 
			
		||||
$!
 | 
			
		||||
$ exit
 | 
			
		||||
$!
 | 
			
		||||
$ deass: subroutine
 | 
			
		||||
$ if (f$trnlnm( p1, "LNM$PROCESS") .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$   deassign /process 'p1'
 | 
			
		||||
$ endif
 | 
			
		||||
$ endsubroutine
 | 
			
		||||
$!
 | 
			
		||||
							
								
								
									
										65
									
								
								apps/install.com
									
									
									
									
									
										Normal file
									
								
							
							
						
						
									
										65
									
								
								apps/install.com
									
									
									
									
									
										Normal file
									
								
							@@ -0,0 +1,65 @@
 | 
			
		||||
$! INSTALL.COM -- Installs the files in a given directory tree
 | 
			
		||||
$!
 | 
			
		||||
$! Author: Richard Levitte <richard@levitte.org>
 | 
			
		||||
$! Time of creation: 22-MAY-1998 10:13
 | 
			
		||||
$!
 | 
			
		||||
$! P1	root of the directory tree
 | 
			
		||||
$!
 | 
			
		||||
$
 | 
			
		||||
$	IF P1 .EQS. ""
 | 
			
		||||
$	THEN
 | 
			
		||||
$	    WRITE SYS$OUTPUT "First argument missing."
 | 
			
		||||
$	    WRITE SYS$OUTPUT -
 | 
			
		||||
		  "Should be the directory where you want things installed."
 | 
			
		||||
$	    EXIT
 | 
			
		||||
$	ENDIF
 | 
			
		||||
$
 | 
			
		||||
$	IF (F$GETSYI("CPU").LT.128)
 | 
			
		||||
$	THEN
 | 
			
		||||
$	    ARCH := VAX
 | 
			
		||||
$	ELSE
 | 
			
		||||
$	    ARCH = F$EDIT( F$GETSYI( "ARCH_NAME"), "UPCASE")
 | 
			
		||||
$	    IF (ARCH .EQS. "") THEN ARCH = "UNK"
 | 
			
		||||
$	ENDIF
 | 
			
		||||
$
 | 
			
		||||
$	ROOT = F$PARSE(P1,"[]A.;0",,,"SYNTAX_ONLY,NO_CONCEAL") - "A.;0"
 | 
			
		||||
$	ROOT_DEV = F$PARSE(ROOT,,,"DEVICE","SYNTAX_ONLY")
 | 
			
		||||
$	ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
 | 
			
		||||
		   - "[000000." - "][" - "[" - "]"
 | 
			
		||||
$	ROOT = ROOT_DEV + "[" + ROOT_DIR
 | 
			
		||||
$
 | 
			
		||||
$	DEFINE/NOLOG WRK_SSLROOT 'ROOT'.] /TRANS=CONC
 | 
			
		||||
$	DEFINE/NOLOG WRK_SSLEXE WRK_SSLROOT:['ARCH'_EXE]
 | 
			
		||||
$
 | 
			
		||||
$	IF F$PARSE("WRK_SSLROOT:[000000]") .EQS. "" THEN -
 | 
			
		||||
	   CREATE/DIR/LOG WRK_SSLROOT:[000000]
 | 
			
		||||
$	IF F$PARSE("WRK_SSLEXE:") .EQS. "" THEN -
 | 
			
		||||
	   CREATE/DIR/LOG WRK_SSLEXE:
 | 
			
		||||
$
 | 
			
		||||
$	EXE := openssl
 | 
			
		||||
$
 | 
			
		||||
$	EXE_DIR := [-.'ARCH'.EXE.APPS]
 | 
			
		||||
$
 | 
			
		||||
$	I = 0
 | 
			
		||||
$ LOOP_EXE: 
 | 
			
		||||
$	E = F$EDIT(F$ELEMENT(I, ",", EXE),"TRIM")
 | 
			
		||||
$	I = I + 1
 | 
			
		||||
$	IF E .EQS. "," THEN GOTO LOOP_EXE_END
 | 
			
		||||
$	SET NOON
 | 
			
		||||
$	IF F$SEARCH(EXE_DIR+E+".EXE") .NES. ""
 | 
			
		||||
$	THEN
 | 
			
		||||
$	  COPY 'EXE_DIR''E'.EXE WRK_SSLEXE:'E'.EXE/log
 | 
			
		||||
$	  SET FILE/PROT=W:RE WRK_SSLEXE:'E'.EXE
 | 
			
		||||
$	ENDIF
 | 
			
		||||
$	SET ON
 | 
			
		||||
$	GOTO LOOP_EXE
 | 
			
		||||
$ LOOP_EXE_END:
 | 
			
		||||
$
 | 
			
		||||
$	SET NOON
 | 
			
		||||
$	COPY CA.COM WRK_SSLEXE:CA.COM/LOG
 | 
			
		||||
$	SET FILE/PROT=W:RE WRK_SSLEXE:CA.COM
 | 
			
		||||
$	COPY OPENSSL-VMS.CNF WRK_SSLROOT:[000000]OPENSSL.CNF/LOG
 | 
			
		||||
$	SET FILE/PROT=W:R WRK_SSLROOT:[000000]OPENSSL.CNF
 | 
			
		||||
$	SET ON
 | 
			
		||||
$
 | 
			
		||||
$	EXIT
 | 
			
		||||
@@ -25,7 +25,7 @@ $!	   VAXC	 For VAX C.
 | 
			
		||||
$!	   DECC	 For DEC C.
 | 
			
		||||
$!	   GNUC	 For GNU C.
 | 
			
		||||
$!
 | 
			
		||||
$!  If you don't specify a compiler, it will try to determine which
 | 
			
		||||
$!  If you don't speficy a compiler, it will try to determine which
 | 
			
		||||
$!  "C" compiler to use.
 | 
			
		||||
$!
 | 
			
		||||
$!  P3, if defined, sets a TCP/IP library to use, through one of the following
 | 
			
		||||
@@ -39,35 +39,11 @@ $!  P4, if defined, sets a compiler thread NOT needed on OpenVMS 7.1 (and up)
 | 
			
		||||
$!
 | 
			
		||||
$!  P5, if defined, sets a choice of programs to compile.
 | 
			
		||||
$!
 | 
			
		||||
$!  P6, if defined, specifies the C pointer size.  Ignored on VAX.
 | 
			
		||||
$!      ("64=ARGV" gives more efficient code with HP C V7.3 or newer.)
 | 
			
		||||
$!      Supported values are:
 | 
			
		||||
$!
 | 
			
		||||
$!      ""       Compile with default (/NOPOINTER_SIZE)
 | 
			
		||||
$!      32       Compile with /POINTER_SIZE=32 (SHORT)
 | 
			
		||||
$!      64       Compile with /POINTER_SIZE=64[=ARGV] (LONG[=ARGV])
 | 
			
		||||
$!               (Automatically select ARGV if compiler supports it.)
 | 
			
		||||
$!      64=      Compile with /POINTER_SIZE=64 (LONG).
 | 
			
		||||
$!      64=ARGV  Compile with /POINTER_SIZE=64=ARGV (LONG=ARGV).
 | 
			
		||||
$!
 | 
			
		||||
$!  P7, if defined, specifies a directory where ZLIB files (zlib.h,
 | 
			
		||||
$!  libz.olb) may be found.  Optionally, a non-default object library
 | 
			
		||||
$!  name may be included ("dev:[dir]libz_64.olb", for example).
 | 
			
		||||
$!
 | 
			
		||||
$!
 | 
			
		||||
$! Announce/identify.
 | 
			
		||||
$!
 | 
			
		||||
$ proc = f$environment( "procedure")
 | 
			
		||||
$ write sys$output "@@@ "+ -
 | 
			
		||||
   f$parse( proc, , , "name")+ f$parse( proc, , , "type")
 | 
			
		||||
$!
 | 
			
		||||
$ on control_c then goto exit
 | 
			
		||||
$!
 | 
			
		||||
$! Define A TCP/IP Library That We Will Need To Link To.
 | 
			
		||||
$! (That Is, If We Need To Link To One.)
 | 
			
		||||
$!
 | 
			
		||||
$ TCPIP_LIB = ""
 | 
			
		||||
$ ZLIB_LIB = ""
 | 
			
		||||
$!
 | 
			
		||||
$! Check What Architecture We Are Using.
 | 
			
		||||
$!
 | 
			
		||||
@@ -76,7 +52,7 @@ $ THEN
 | 
			
		||||
$!
 | 
			
		||||
$!  The Architecture Is VAX.
 | 
			
		||||
$!
 | 
			
		||||
$   ARCH = "VAX"
 | 
			
		||||
$   ARCH := VAX
 | 
			
		||||
$!
 | 
			
		||||
$! Else...
 | 
			
		||||
$!
 | 
			
		||||
@@ -91,45 +67,29 @@ $! End The Architecture Check.
 | 
			
		||||
$!
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$ ARCHD = ARCH
 | 
			
		||||
$ LIB32 = "32"
 | 
			
		||||
$ OPT_FILE = ""
 | 
			
		||||
$ POINTER_SIZE = ""
 | 
			
		||||
$!
 | 
			
		||||
$! Define what programs should be compiled
 | 
			
		||||
$!
 | 
			
		||||
$ PROGRAMS := OPENSSL
 | 
			
		||||
$!
 | 
			
		||||
$! Check To Make Sure We Have Valid Command Line Parameters.
 | 
			
		||||
$!
 | 
			
		||||
$ GOSUB CHECK_OPTIONS
 | 
			
		||||
$!
 | 
			
		||||
$! Define The CRYPTO Library.
 | 
			
		||||
$!
 | 
			
		||||
$ CRYPTO_LIB := SYS$DISK:[-.'ARCHD'.EXE.CRYPTO]SSL_LIBCRYPTO'LIB32'.OLB
 | 
			
		||||
$ CRYPTO_LIB := SYS$DISK:[-.'ARCH'.EXE.CRYPTO]LIBCRYPTO.OLB
 | 
			
		||||
$!
 | 
			
		||||
$! Define The SSL Library.
 | 
			
		||||
$!
 | 
			
		||||
$ SSL_LIB := SYS$DISK:[-.'ARCHD'.EXE.SSL]SSL_LIBSSL'LIB32'.OLB
 | 
			
		||||
$ SSL_LIB := SYS$DISK:[-.'ARCH'.EXE.SSL]LIBSSL.OLB
 | 
			
		||||
$!
 | 
			
		||||
$! Define The OBJ and EXE Directories.
 | 
			
		||||
$! Define The OBJ Directory.
 | 
			
		||||
$!
 | 
			
		||||
$ OBJ_DIR := SYS$DISK:[-.'ARCHD'.OBJ.APPS]
 | 
			
		||||
$ EXE_DIR := SYS$DISK:[-.'ARCHD'.EXE.APPS]
 | 
			
		||||
$ OBJ_DIR := SYS$DISK:[-.'ARCH'.OBJ.APPS]
 | 
			
		||||
$!
 | 
			
		||||
$! Specify the destination directory in any /MAP option.
 | 
			
		||||
$! Define The EXE Directory.
 | 
			
		||||
$!
 | 
			
		||||
$ if (LINKMAP .eqs. "MAP")
 | 
			
		||||
$ then
 | 
			
		||||
$   LINKMAP = LINKMAP+ "=''EXE_DIR'"
 | 
			
		||||
$ endif
 | 
			
		||||
$ EXE_DIR := SYS$DISK:[-.'ARCH'.EXE.APPS]
 | 
			
		||||
$!
 | 
			
		||||
$! Add the location prefix to the linker options file name.
 | 
			
		||||
$! Check To Make Sure We Have Valid Command Line Parameters.
 | 
			
		||||
$!
 | 
			
		||||
$ if (OPT_FILE .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$   OPT_FILE = EXE_DIR+ OPT_FILE
 | 
			
		||||
$ endif
 | 
			
		||||
$ GOSUB CHECK_OPTIONS
 | 
			
		||||
$!
 | 
			
		||||
$! Initialise logical names and such
 | 
			
		||||
$!
 | 
			
		||||
@@ -137,7 +97,7 @@ $ GOSUB INITIALISE
 | 
			
		||||
$!
 | 
			
		||||
$! Tell The User What Kind of Machine We Run On.
 | 
			
		||||
$!
 | 
			
		||||
$ WRITE SYS$OUTPUT "Host system architecture: ''ARCHD'"
 | 
			
		||||
$ WRITE SYS$OUTPUT "Compiling On A ",ARCH," Machine."
 | 
			
		||||
$!
 | 
			
		||||
$! Check To See If The OBJ Directory Exists.
 | 
			
		||||
$!
 | 
			
		||||
@@ -181,13 +141,10 @@ $!
 | 
			
		||||
$ LIB_OPENSSL = "VERIFY,ASN1PARS,REQ,DGST,DH,DHPARAM,ENC,PASSWD,GENDH,ERRSTR,"+-
 | 
			
		||||
		"CA,PKCS7,CRL2P7,CRL,"+-
 | 
			
		||||
		"RSA,RSAUTL,DSA,DSAPARAM,EC,ECPARAM,"+-
 | 
			
		||||
	      	"X509,GENRSA,GENDSA,GENPKEY,S_SERVER,S_CLIENT,SPEED,"+-
 | 
			
		||||
		"X509,GENRSA,GENDSA,S_SERVER,S_CLIENT,SPEED,"+-
 | 
			
		||||
		"S_TIME,APPS,S_CB,S_SOCKET,APP_RAND,VERSION,SESS_ID,"+-
 | 
			
		||||
	      	"CIPHERS,NSEQ,PKCS12,PKCS8,PKEY,PKEYPARAM,PKEYUTL,"+ -
 | 
			
		||||
	      	"SPKAC,SMIME,CMS,RAND,ENGINE,OCSP,PRIME,TS,SRP"
 | 
			
		||||
$!
 | 
			
		||||
$ LIB_OPENSSL = LIB_OPENSSL+ ",VMS_DECC_INIT"
 | 
			
		||||
$!
 | 
			
		||||
		"CIPHERS,NSEQ,PKCS12,PKCS8,SPKAC,SMIME,RAND,ENGINE,"+-
 | 
			
		||||
		"OCSP,PRIME,CMS"
 | 
			
		||||
$ TCPIP_PROGRAMS = ",,"
 | 
			
		||||
$ IF COMPILER .EQS. "VAXC" THEN -
 | 
			
		||||
     TCPIP_PROGRAMS = ",OPENSSL,"
 | 
			
		||||
@@ -332,18 +289,34 @@ $   GOTO NEXT_APP
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$! Link The Program.
 | 
			
		||||
$! Check To See If We Are To Link With A Specific TCP/IP Library.
 | 
			
		||||
$!
 | 
			
		||||
$ ON WARNING THEN GOTO NEXT_APP
 | 
			
		||||
$!
 | 
			
		||||
$ IF (TCPIP_LIB.NES."")
 | 
			
		||||
$ THEN
 | 
			
		||||
$!
 | 
			
		||||
$! Don't Link With The RSAREF Routines And TCP/IP Library.
 | 
			
		||||
$!
 | 
			
		||||
$ LINK /'DEBUGGER' /'LINKMAP' /'TRACEBACK' /EXE='EXE_FILE' -
 | 
			
		||||
  'EXE_DIR''CURRENT_APP'.OPT /OPTIONS, -
 | 
			
		||||
  'SSL_LIB' /LIBRARY, -
 | 
			
		||||
  'CRYPTO_LIB' /LIBRARY -
 | 
			
		||||
  'TCPIP_LIB' -
 | 
			
		||||
  'ZLIB_LIB' -
 | 
			
		||||
  ,'OPT_FILE' /OPTIONS
 | 
			
		||||
$   LINK/'DEBUGGER'/'TRACEBACK' /EXE='EXE_FILE' -
 | 
			
		||||
	'EXE_DIR''CURRENT_APP'.OPT/OPTION, -
 | 
			
		||||
        'SSL_LIB'/LIBRARY,'CRYPTO_LIB'/LIBRARY, -
 | 
			
		||||
        'TCPIP_LIB','OPT_FILE'/OPTION
 | 
			
		||||
$!
 | 
			
		||||
$! Else...
 | 
			
		||||
$!
 | 
			
		||||
$ ELSE
 | 
			
		||||
$!
 | 
			
		||||
$! Don't Link With The RSAREF Routines And Link With A TCP/IP Library.
 | 
			
		||||
$!
 | 
			
		||||
$   LINK/'DEBUGGER'/'TRACEBACK' /EXE='EXE_FILE' -
 | 
			
		||||
	'EXE_DIR''CURRENT_APP'.OPT/OPTION, -
 | 
			
		||||
        'SSL_LIB'/LIBRARY,'CRYPTO_LIB'/LIBRARY, -
 | 
			
		||||
        'OPT_FILE'/OPTION
 | 
			
		||||
$!
 | 
			
		||||
$! End The TCP/IP Library Check.
 | 
			
		||||
$!
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$! Go Back And Do It Again.
 | 
			
		||||
$!
 | 
			
		||||
@@ -378,7 +351,7 @@ $!
 | 
			
		||||
$     CREATE 'OPT_FILE'
 | 
			
		||||
$DECK
 | 
			
		||||
!
 | 
			
		||||
! Default System Options File To Link Against 
 | 
			
		||||
! Default System Options File To Link Agianst 
 | 
			
		||||
! The Sharable VAX C Runtime Library.
 | 
			
		||||
!
 | 
			
		||||
SYS$SHARE:VAXCRTL.EXE/SHARE
 | 
			
		||||
@@ -407,7 +380,7 @@ $!
 | 
			
		||||
$     CREATE 'OPT_FILE'
 | 
			
		||||
$DECK
 | 
			
		||||
!
 | 
			
		||||
! Default System Options File To Link Against 
 | 
			
		||||
! Default System Options File To Link Agianst 
 | 
			
		||||
! The Sharable C Runtime Library.
 | 
			
		||||
!
 | 
			
		||||
GNU_CC:[000000]GCCLIB/LIBRARY
 | 
			
		||||
@@ -442,7 +415,7 @@ $!
 | 
			
		||||
$       CREATE 'OPT_FILE'
 | 
			
		||||
$DECK
 | 
			
		||||
!
 | 
			
		||||
! Default System Options File To Link Against 
 | 
			
		||||
! Default System Options File To Link Agianst 
 | 
			
		||||
! The Sharable DEC C Runtime Library.
 | 
			
		||||
!
 | 
			
		||||
SYS$SHARE:DECC$SHR.EXE/SHARE
 | 
			
		||||
@@ -457,7 +430,7 @@ $!
 | 
			
		||||
$       CREATE 'OPT_FILE'
 | 
			
		||||
$DECK
 | 
			
		||||
!
 | 
			
		||||
! Default System Options File For non-VAX To Link Against 
 | 
			
		||||
! Default System Options File For non-VAX To Link Agianst 
 | 
			
		||||
! The Sharable C Runtime Library.
 | 
			
		||||
!
 | 
			
		||||
SYS$SHARE:CMA$OPEN_LIB_SHR/SHARE
 | 
			
		||||
@@ -544,7 +517,6 @@ $!
 | 
			
		||||
$!   P1 Is NODEBUG, So Compile Without Debugger Information.
 | 
			
		||||
$!
 | 
			
		||||
$    DEBUGGER  = "NODEBUG"
 | 
			
		||||
$   LINKMAP = "NOMAP"
 | 
			
		||||
$    TRACEBACK = "NOTRACEBACK" 
 | 
			
		||||
$    GCC_OPTIMIZE = "OPTIMIZE"
 | 
			
		||||
$    CC_OPTIMIZE = "OPTIMIZE"
 | 
			
		||||
@@ -563,7 +535,6 @@ $!
 | 
			
		||||
$!    Compile With Debugger Information.
 | 
			
		||||
$!
 | 
			
		||||
$     DEBUGGER  = "DEBUG"
 | 
			
		||||
$     LINKMAP = "MAP"
 | 
			
		||||
$     TRACEBACK = "TRACEBACK"
 | 
			
		||||
$     GCC_OPTIMIZE = "NOOPTIMIZE"
 | 
			
		||||
$     CC_OPTIMIZE = "NOOPTIMIZE"
 | 
			
		||||
@@ -571,7 +542,7 @@ $     WRITE SYS$OUTPUT "Debugger Information Will Be Produced During Compile."
 | 
			
		||||
$     WRITE SYS$OUTPUT "Compiling Without Compiler Optimization."
 | 
			
		||||
$   ELSE
 | 
			
		||||
$!
 | 
			
		||||
$!    Tell The User Entered An Invalid Option.
 | 
			
		||||
$!    Tell The User Entered An Invalid Option..
 | 
			
		||||
$!
 | 
			
		||||
$     WRITE SYS$OUTPUT ""
 | 
			
		||||
$     WRITE SYS$OUTPUT "The Option ",P1," Is Invalid.  The Valid Options Are:"
 | 
			
		||||
@@ -584,7 +555,7 @@ $!    Time To EXIT.
 | 
			
		||||
$!
 | 
			
		||||
$     EXIT
 | 
			
		||||
$!
 | 
			
		||||
$!  End The Valid Argument Check.
 | 
			
		||||
$!  End The Valid Arguement Check.
 | 
			
		||||
$!
 | 
			
		||||
$   ENDIF
 | 
			
		||||
$!
 | 
			
		||||
@@ -592,87 +563,6 @@ $! End The P1 Check.
 | 
			
		||||
$!
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$! Check P6 (POINTER_SIZE).
 | 
			
		||||
$!
 | 
			
		||||
$ IF (P6 .NES. "") .AND. (ARCH .NES. "VAX")
 | 
			
		||||
$ THEN
 | 
			
		||||
$!
 | 
			
		||||
$   IF (P6 .EQS. "32")
 | 
			
		||||
$   THEN
 | 
			
		||||
$     POINTER_SIZE = " /POINTER_SIZE=32"
 | 
			
		||||
$   ELSE
 | 
			
		||||
$     POINTER_SIZE = F$EDIT( P6, "COLLAPSE, UPCASE")
 | 
			
		||||
$     IF ((POINTER_SIZE .EQS. "64") .OR. -
 | 
			
		||||
       (POINTER_SIZE .EQS. "64=") .OR. -
 | 
			
		||||
       (POINTER_SIZE .EQS. "64=ARGV"))
 | 
			
		||||
$     THEN
 | 
			
		||||
$       ARCHD = ARCH+ "_64"
 | 
			
		||||
$       LIB32 = ""
 | 
			
		||||
$       IF (F$EXTRACT( 2, 1, POINTER_SIZE) .EQS. "=")
 | 
			
		||||
$       THEN
 | 
			
		||||
$!        Explicit user choice: "64" or "64=ARGV".
 | 
			
		||||
$         IF (POINTER_SIZE .EQS. "64=") THEN POINTER_SIZE = "64"
 | 
			
		||||
$       ELSE
 | 
			
		||||
$         SET NOON
 | 
			
		||||
$         DEFINE /USER_MODE SYS$OUTPUT NL:
 | 
			
		||||
$         DEFINE /USER_MODE SYS$ERROR NL:
 | 
			
		||||
$         CC /NOLIST /NOOBJECT /POINTER_SIZE=64=ARGV NL:
 | 
			
		||||
$         IF ($STATUS .AND. %X0FFF0000) .EQ. %X00030000
 | 
			
		||||
$         THEN
 | 
			
		||||
$           ! If we got here, it means DCL complained like this:
 | 
			
		||||
$           ! %DCL-W-NOVALU, value not allowed - remove value specification
 | 
			
		||||
$           !  \64=\
 | 
			
		||||
$           !
 | 
			
		||||
$           ! If the compiler was run, logicals defined in /USER would
 | 
			
		||||
$           ! have been deassigned automatically.  However, when DCL
 | 
			
		||||
$           ! complains, they aren't, so we do it here (it might be
 | 
			
		||||
$           ! unnecessary, but just in case there will be another error
 | 
			
		||||
$           ! message further on that we don't want to miss)
 | 
			
		||||
$           DEASSIGN /USER_MODE SYS$ERROR
 | 
			
		||||
$           DEASSIGN /USER_MODE SYS$OUTPUT
 | 
			
		||||
$         ELSE
 | 
			
		||||
$           POINTER_SIZE = POINTER_SIZE + "=ARGV"
 | 
			
		||||
$         ENDIF
 | 
			
		||||
$         SET ON
 | 
			
		||||
$       ENDIF
 | 
			
		||||
$       POINTER_SIZE = " /POINTER_SIZE=''POINTER_SIZE'"
 | 
			
		||||
$!
 | 
			
		||||
$     ELSE
 | 
			
		||||
$!
 | 
			
		||||
$!      Tell The User Entered An Invalid Option.
 | 
			
		||||
$!
 | 
			
		||||
$       WRITE SYS$OUTPUT ""
 | 
			
		||||
$       WRITE SYS$OUTPUT "The Option ", P6, -
 | 
			
		||||
         " Is Invalid.  The Valid Options Are:"
 | 
			
		||||
$       WRITE SYS$OUTPUT ""
 | 
			
		||||
$       WRITE SYS$OUTPUT -
 | 
			
		||||
         "    """"  :  Compile with default (short) pointers."
 | 
			
		||||
$       WRITE SYS$OUTPUT -
 | 
			
		||||
         "    32  :  Compile with 32-bit (short) pointers."
 | 
			
		||||
$       WRITE SYS$OUTPUT -
 | 
			
		||||
         "    64       :  Compile with 64-bit (long) pointers (auto ARGV)."
 | 
			
		||||
$       WRITE SYS$OUTPUT -
 | 
			
		||||
         "    64=      :  Compile with 64-bit (long) pointers (no ARGV)."
 | 
			
		||||
$       WRITE SYS$OUTPUT -
 | 
			
		||||
         "    64=ARGV  :  Compile with 64-bit (long) pointers (ARGV)."
 | 
			
		||||
$       WRITE SYS$OUTPUT ""
 | 
			
		||||
$! 
 | 
			
		||||
$!      Time To EXIT.
 | 
			
		||||
$!
 | 
			
		||||
$       EXIT
 | 
			
		||||
$!
 | 
			
		||||
$     ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$   ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$! End The P6 (POINTER_SIZE) Check.
 | 
			
		||||
$!
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$! Set basic C compiler /INCLUDE directories.
 | 
			
		||||
$!
 | 
			
		||||
$ CC_INCLUDES = "SYS$DISK:[-],SYS$DISK:[-.CRYPTO]"
 | 
			
		||||
$!
 | 
			
		||||
$! Check To See If P2 Is Blank.
 | 
			
		||||
$!
 | 
			
		||||
$ IF (P2.EQS."")
 | 
			
		||||
@@ -773,64 +663,11 @@ $ CCDEFS = "MONOLITH"
 | 
			
		||||
$ IF F$TYPE(USER_CCDEFS) .NES. "" THEN CCDEFS = CCDEFS + "," + USER_CCDEFS
 | 
			
		||||
$ CCEXTRAFLAGS = ""
 | 
			
		||||
$ IF F$TYPE(USER_CCFLAGS) .NES. "" THEN CCEXTRAFLAGS = USER_CCFLAGS
 | 
			
		||||
$ CCDISABLEWARNINGS = "" !!! "LONGLONGTYPE,LONGLONGSUFX,FOUNDCR"
 | 
			
		||||
$ CCDISABLEWARNINGS = "LONGLONGTYPE,LONGLONGSUFX,FOUNDCR"
 | 
			
		||||
$ IF F$TYPE(USER_CCDISABLEWARNINGS) .NES. "" THEN -
 | 
			
		||||
	CCDISABLEWARNINGS = CCDISABLEWARNINGS + "," + USER_CCDISABLEWARNINGS
 | 
			
		||||
$!
 | 
			
		||||
$! Check To See If We Have A ZLIB Option.
 | 
			
		||||
$!
 | 
			
		||||
$ ZLIB = P7
 | 
			
		||||
$ IF (ZLIB .NES. "")
 | 
			
		||||
$ THEN
 | 
			
		||||
$!
 | 
			
		||||
$!  Check for expected ZLIB files.
 | 
			
		||||
$!
 | 
			
		||||
$   err = 0
 | 
			
		||||
$   file1 = f$parse( "zlib.h", ZLIB, , , "SYNTAX_ONLY")
 | 
			
		||||
$   if (f$search( file1) .eqs. "")
 | 
			
		||||
$   then
 | 
			
		||||
$     WRITE SYS$OUTPUT ""
 | 
			
		||||
$     WRITE SYS$OUTPUT "The Option ", ZLIB, " Is Invalid."
 | 
			
		||||
$     WRITE SYS$OUTPUT "    Can't find header: ''file1'"
 | 
			
		||||
$     err = 1
 | 
			
		||||
$   endif
 | 
			
		||||
$   file1 = f$parse( "A.;", ZLIB)- "A.;"
 | 
			
		||||
$!
 | 
			
		||||
$   file2 = f$parse( ZLIB, "libz.olb", , , "SYNTAX_ONLY")
 | 
			
		||||
$   if (f$search( file2) .eqs. "")
 | 
			
		||||
$   then
 | 
			
		||||
$     if (err .eq. 0)
 | 
			
		||||
$     then
 | 
			
		||||
$       WRITE SYS$OUTPUT ""
 | 
			
		||||
$       WRITE SYS$OUTPUT "The Option ", ZLIB, " Is Invalid."
 | 
			
		||||
$     endif
 | 
			
		||||
$     WRITE SYS$OUTPUT "    Can't find library: ''file2'"
 | 
			
		||||
$     WRITE SYS$OUTPUT ""
 | 
			
		||||
$     err = err+ 2
 | 
			
		||||
$   endif
 | 
			
		||||
$   if (err .eq. 1)
 | 
			
		||||
$   then
 | 
			
		||||
$     WRITE SYS$OUTPUT ""
 | 
			
		||||
$   endif
 | 
			
		||||
$!
 | 
			
		||||
$   if (err .ne. 0)
 | 
			
		||||
$   then
 | 
			
		||||
$     EXIT
 | 
			
		||||
$   endif
 | 
			
		||||
$!
 | 
			
		||||
$   CCDEFS = """ZLIB=1"", "+ CCDEFS
 | 
			
		||||
$   CC_INCLUDES = CC_INCLUDES+ ", "+ file1
 | 
			
		||||
$   ZLIB_LIB = ", ''file2' /library"
 | 
			
		||||
$!
 | 
			
		||||
$!  Print info
 | 
			
		||||
$!
 | 
			
		||||
$   WRITE SYS$OUTPUT "ZLIB library spec: ", file2
 | 
			
		||||
$!
 | 
			
		||||
$! End The ZLIB Check.
 | 
			
		||||
$!
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$!  Check To See If The User Entered A Valid Parameter.
 | 
			
		||||
$!  Check To See If The User Entered A Valid Paramter.
 | 
			
		||||
$!
 | 
			
		||||
$ IF (P2.EQS."VAXC").OR.(P2.EQS."DECC").OR.(P2.EQS."GNUC")
 | 
			
		||||
$ THEN
 | 
			
		||||
@@ -853,13 +690,13 @@ $!
 | 
			
		||||
$     CC = "CC"
 | 
			
		||||
$     IF ARCH.EQS."VAX" .AND. F$TRNLNM("DECC$CC_DEFAULT").NES."/DECC" -
 | 
			
		||||
	 THEN CC = "CC/DECC"
 | 
			
		||||
$     CC = CC + " /''CC_OPTIMIZE' /''DEBUGGER' /STANDARD=RELAXED"+ -
 | 
			
		||||
       "''POINTER_SIZE' /NOLIST /PREFIX=ALL" + -
 | 
			
		||||
       " /INCLUDE=(''CC_INCLUDES') " + CCEXTRAFLAGS
 | 
			
		||||
$     CC = CC + "/''CC_OPTIMIZE'/''DEBUGGER'/STANDARD=ANSI89" + -
 | 
			
		||||
           "/NOLIST/PREFIX=ALL" + -
 | 
			
		||||
	   "/INCLUDE=(SYS$DISK:[-],SYS$DISK:[-.CRYPTO])" + CCEXTRAFLAGS
 | 
			
		||||
$!
 | 
			
		||||
$!    Define The Linker Options File Name.
 | 
			
		||||
$!
 | 
			
		||||
$     OPT_FILE = "VAX_DECC_OPTIONS.OPT"
 | 
			
		||||
$     OPT_FILE = "''EXE_DIR'VAX_DECC_OPTIONS.OPT"
 | 
			
		||||
$!
 | 
			
		||||
$!  End DECC Check.
 | 
			
		||||
$!
 | 
			
		||||
@@ -887,7 +724,7 @@ $	EXIT
 | 
			
		||||
$     ENDIF
 | 
			
		||||
$     IF F$TRNLNM("DECC$CC_DEFAULT").EQS."/DECC" THEN CC = "CC/VAXC"
 | 
			
		||||
$     CC = CC + "/''CC_OPTIMIZE'/''DEBUGGER'/NOLIST" + -
 | 
			
		||||
	   "/INCLUDE=(''CC_INCLUDES')" + CCEXTRAFLAGS
 | 
			
		||||
	   "/INCLUDE=(SYS$DISK:[-],SYS$DISK:[-.CRYPTO])" + CCEXTRAFLAGS
 | 
			
		||||
$     CCDEFS = CCDEFS + ",""VAXC"""
 | 
			
		||||
$!
 | 
			
		||||
$!    Define <sys> As SYS$COMMON:[SYSLIB]
 | 
			
		||||
@@ -896,7 +733,7 @@ $     DEFINE/NOLOG SYS SYS$COMMON:[SYSLIB]
 | 
			
		||||
$!
 | 
			
		||||
$!    Define The Linker Options File Name.
 | 
			
		||||
$!
 | 
			
		||||
$     OPT_FILE = "VAX_VAXC_OPTIONS.OPT"
 | 
			
		||||
$     OPT_FILE = "''EXE_DIR'VAX_VAXC_OPTIONS.OPT"
 | 
			
		||||
$!
 | 
			
		||||
$!  End VAXC Check
 | 
			
		||||
$!
 | 
			
		||||
@@ -919,11 +756,11 @@ $!    Use GNU C...
 | 
			
		||||
$!
 | 
			
		||||
$     IF F$TYPE(GCC) .EQS. "" THEN GCC := GCC
 | 
			
		||||
$     CC = GCC+"/NOCASE_HACK/''GCC_OPTIMIZE'/''DEBUGGER'/NOLIST" + -
 | 
			
		||||
	   "/INCLUDE=(''CC_INCLUDES')" + CCEXTRAFLAGS
 | 
			
		||||
	   "/INCLUDE=(SYS$DISK:[-],SYS$DISK:[-.CRYPTO])" + CCEXTRAFLAGS
 | 
			
		||||
$!
 | 
			
		||||
$!    Define The Linker Options File Name.
 | 
			
		||||
$!
 | 
			
		||||
$     OPT_FILE = "VAX_GNUC_OPTIONS.OPT"
 | 
			
		||||
$     OPT_FILE = "''EXE_DIR'VAX_GNUC_OPTIONS.OPT"
 | 
			
		||||
$!
 | 
			
		||||
$!  End The GNU C Check.
 | 
			
		||||
$!
 | 
			
		||||
@@ -933,7 +770,7 @@ $!  Set up default defines
 | 
			
		||||
$!
 | 
			
		||||
$   CCDEFS = """FLAT_INC=1""," + CCDEFS
 | 
			
		||||
$!
 | 
			
		||||
$!  Else The User Entered An Invalid Argument.
 | 
			
		||||
$!  Else The User Entered An Invalid Arguement.
 | 
			
		||||
$!
 | 
			
		||||
$ ELSE
 | 
			
		||||
$!
 | 
			
		||||
@@ -965,7 +802,7 @@ $   THEN
 | 
			
		||||
$!
 | 
			
		||||
$!    Set the library to use SOCKETSHR
 | 
			
		||||
$!
 | 
			
		||||
$     TCPIP_LIB = ",SYS$DISK:[-.VMS]SOCKETSHR_SHR.OPT /OPTIONS"
 | 
			
		||||
$     TCPIP_LIB = "SYS$DISK:[-.VMS]SOCKETSHR_SHR.OPT/OPT"
 | 
			
		||||
$!
 | 
			
		||||
$!    Done with SOCKETSHR
 | 
			
		||||
$!
 | 
			
		||||
@@ -991,13 +828,13 @@ $   THEN
 | 
			
		||||
$!
 | 
			
		||||
$!    Set the library to use UCX.
 | 
			
		||||
$!
 | 
			
		||||
$     TCPIP_LIB = ",SYS$DISK:[-.VMS]UCX_SHR_DECC.OPT /OPTIONS"
 | 
			
		||||
$     TCPIP_LIB = "SYS$DISK:[-.VMS]UCX_SHR_DECC.OPT/OPT"
 | 
			
		||||
$     IF F$TRNLNM("UCX$IPC_SHR") .NES. ""
 | 
			
		||||
$     THEN
 | 
			
		||||
$       TCPIP_LIB = ",SYS$DISK:[-.VMS]UCX_SHR_DECC_LOG.OPT /OPTIONS"
 | 
			
		||||
$       TCPIP_LIB = "SYS$DISK:[-.VMS]UCX_SHR_DECC_LOG.OPT/OPT"
 | 
			
		||||
$     ELSE
 | 
			
		||||
$       IF COMPILER .NES. "DECC" .AND. ARCH .EQS. "VAX" THEN -
 | 
			
		||||
	  TCPIP_LIB = ",SYS$DISK:[-.VMS]UCX_SHR_VAXC.OPT /OPTIONS"
 | 
			
		||||
	  TCPIP_LIB = "SYS$DISK:[-.VMS]UCX_SHR_VAXC.OPT/OPT"
 | 
			
		||||
$     ENDIF
 | 
			
		||||
$!
 | 
			
		||||
$!    Done with UCX
 | 
			
		||||
@@ -1011,7 +848,7 @@ $   THEN
 | 
			
		||||
$!
 | 
			
		||||
$!    Set the library to use TCPIP.
 | 
			
		||||
$!
 | 
			
		||||
$     TCPIP_LIB = ",SYS$DISK:[-.VMS]TCPIP_SHR_DECC.OPT /OPTIONS"
 | 
			
		||||
$     TCPIP_LIB = "SYS$DISK:[-.VMS]TCPIP_SHR_DECC.OPT/OPT"
 | 
			
		||||
$!
 | 
			
		||||
$!    Done with TCPIP
 | 
			
		||||
$!
 | 
			
		||||
@@ -1036,9 +873,9 @@ $   CCDEFS = CCDEFS + ",TCPIP_TYPE_''P3'"
 | 
			
		||||
$!
 | 
			
		||||
$!  Print info
 | 
			
		||||
$!
 | 
			
		||||
$   WRITE SYS$OUTPUT "TCP/IP library spec: ", TCPIP_LIB- ","
 | 
			
		||||
$   WRITE SYS$OUTPUT "TCP/IP library spec: ", TCPIP_LIB
 | 
			
		||||
$!
 | 
			
		||||
$!  Else The User Entered An Invalid Argument.
 | 
			
		||||
$!  Else The User Entered An Invalid Arguement.
 | 
			
		||||
$!
 | 
			
		||||
$ ELSE
 | 
			
		||||
$!
 | 
			
		||||
@@ -1146,24 +983,15 @@ $ RETURN
 | 
			
		||||
$!
 | 
			
		||||
$ CLEANUP:
 | 
			
		||||
$!
 | 
			
		||||
$! Restore the saved logical name OPENSSL, if it had a value.
 | 
			
		||||
$! Restore the logical name OPENSSL if it had a value
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$type( __SAVE_OPENSSL) .nes. "")
 | 
			
		||||
$ then
 | 
			
		||||
$ IF __SAVE_OPENSSL .EQS. ""
 | 
			
		||||
$ THEN
 | 
			
		||||
$   DEASSIGN OPENSSL
 | 
			
		||||
$ ELSE
 | 
			
		||||
$   DEFINE/NOLOG OPENSSL '__SAVE_OPENSSL'
 | 
			
		||||
$ ENDIF
 | 
			
		||||
$ endif
 | 
			
		||||
$!
 | 
			
		||||
$! Close any open files.
 | 
			
		||||
$!
 | 
			
		||||
$ if (f$trnlnm( "objects", "LNM$PROCESS", 0, "SUPERVISOR") .nes. "") then -
 | 
			
		||||
   close objects
 | 
			
		||||
$!
 | 
			
		||||
$! Done
 | 
			
		||||
$!
 | 
			
		||||
$ RETURN
 | 
			
		||||
$!
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										244
									
								
								apps/ocsp.c
									
									
									
									
									
								
							
							
						
						
									
										244
									
								
								apps/ocsp.c
									
									
									
									
									
								
							@@ -57,70 +57,38 @@
 | 
			
		||||
 *
 | 
			
		||||
 */
 | 
			
		||||
#ifndef OPENSSL_NO_OCSP
 | 
			
		||||
 | 
			
		||||
# ifdef OPENSSL_SYS_VMS
 | 
			
		||||
#  define _XOPEN_SOURCE_EXTENDED/* So fd_set and friends get properly defined
 | 
			
		||||
                                 * on OpenVMS */
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# define USE_SOCKETS
 | 
			
		||||
 | 
			
		||||
# include <stdio.h>
 | 
			
		||||
# include <stdlib.h>
 | 
			
		||||
# include <string.h>
 | 
			
		||||
# include <time.h>
 | 
			
		||||
# include "apps.h"              /* needs to be included before the openssl
 | 
			
		||||
                                 * headers! */
 | 
			
		||||
# include <openssl/e_os2.h>
 | 
			
		||||
# include <openssl/crypto.h>
 | 
			
		||||
# include <openssl/err.h>
 | 
			
		||||
# include <openssl/ssl.h>
 | 
			
		||||
# include <openssl/evp.h>
 | 
			
		||||
# include <openssl/bn.h>
 | 
			
		||||
# include <openssl/x509v3.h>
 | 
			
		||||
 | 
			
		||||
# if defined(NETWARE_CLIB)
 | 
			
		||||
#  ifdef NETWARE_BSDSOCK
 | 
			
		||||
#   include <sys/socket.h>
 | 
			
		||||
#   include <sys/bsdskt.h>
 | 
			
		||||
#  else
 | 
			
		||||
#   include <novsock2.h>
 | 
			
		||||
#  endif
 | 
			
		||||
# elif defined(NETWARE_LIBC)
 | 
			
		||||
#  ifdef NETWARE_BSDSOCK
 | 
			
		||||
#   include <sys/select.h>
 | 
			
		||||
#  else
 | 
			
		||||
#   include <novsock2.h>
 | 
			
		||||
#  endif
 | 
			
		||||
# endif
 | 
			
		||||
# include <openssl/err.h>
 | 
			
		||||
 | 
			
		||||
/* Maximum leeway in validity period: default 5 minutes */
 | 
			
		||||
# define MAX_VALIDITY_PERIOD     (5 * 60)
 | 
			
		||||
 | 
			
		||||
static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert,
 | 
			
		||||
                         const EVP_MD *cert_id_md, X509 *issuer,
 | 
			
		||||
static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert, X509 *issuer,
 | 
			
		||||
                         STACK_OF(OCSP_CERTID) *ids);
 | 
			
		||||
static int add_ocsp_serial(OCSP_REQUEST **req, char *serial,
 | 
			
		||||
                           const EVP_MD *cert_id_md, X509 *issuer,
 | 
			
		||||
static int add_ocsp_serial(OCSP_REQUEST **req, char *serial, X509 *issuer,
 | 
			
		||||
                           STACK_OF(OCSP_CERTID) *ids);
 | 
			
		||||
static int print_ocsp_summary(BIO *out, OCSP_BASICRESP *bs, OCSP_REQUEST *req,
 | 
			
		||||
                              STACK_OF(OPENSSL_STRING) *names,
 | 
			
		||||
                              STACK_OF(OCSP_CERTID) *ids, long nsec,
 | 
			
		||||
                              long maxage);
 | 
			
		||||
                              STACK * names, STACK_OF(OCSP_CERTID) *ids,
 | 
			
		||||
                              long nsec, long maxage);
 | 
			
		||||
 | 
			
		||||
static int make_ocsp_response(OCSP_RESPONSE **resp, OCSP_REQUEST *req,
 | 
			
		||||
                              CA_DB *db, X509 *ca, X509 *rcert,
 | 
			
		||||
                              EVP_PKEY *rkey, const EVP_MD *md,
 | 
			
		||||
                              STACK_OF(X509) *rother, unsigned long flags,
 | 
			
		||||
                              int nmin, int ndays, int badsig);
 | 
			
		||||
                              EVP_PKEY *rkey, STACK_OF(X509) *rother,
 | 
			
		||||
                              unsigned long flags, int nmin, int ndays);
 | 
			
		||||
 | 
			
		||||
static char **lookup_serial(CA_DB *db, ASN1_INTEGER *ser);
 | 
			
		||||
static BIO *init_responder(const char *port);
 | 
			
		||||
static BIO *init_responder(char *port);
 | 
			
		||||
static int do_responder(OCSP_REQUEST **preq, BIO **pcbio, BIO *acbio,
 | 
			
		||||
                        const char *port);
 | 
			
		||||
                        char *port);
 | 
			
		||||
static int send_ocsp_response(BIO *cbio, OCSP_RESPONSE *resp);
 | 
			
		||||
static OCSP_RESPONSE *query_responder(BIO *err, BIO *cbio, const char *path,
 | 
			
		||||
                                      const STACK_OF(CONF_VALUE) *headers,
 | 
			
		||||
static OCSP_RESPONSE *query_responder(BIO *err, BIO *cbio, char *path,
 | 
			
		||||
                                      OCSP_REQUEST *req, int req_timeout);
 | 
			
		||||
 | 
			
		||||
# undef PROG
 | 
			
		||||
@@ -140,7 +108,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    char *rsignfile = NULL, *rkeyfile = NULL;
 | 
			
		||||
    char *outfile = NULL;
 | 
			
		||||
    int add_nonce = 1, noverify = 0, use_ssl = -1;
 | 
			
		||||
    STACK_OF(CONF_VALUE) *headers = NULL;
 | 
			
		||||
    OCSP_REQUEST *req = NULL;
 | 
			
		||||
    OCSP_RESPONSE *resp = NULL;
 | 
			
		||||
    OCSP_BASICRESP *bs = NULL;
 | 
			
		||||
@@ -155,17 +122,15 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    long nsec = MAX_VALIDITY_PERIOD, maxage = -1;
 | 
			
		||||
    char *CAfile = NULL, *CApath = NULL;
 | 
			
		||||
    X509_STORE *store = NULL;
 | 
			
		||||
    X509_VERIFY_PARAM *vpm = NULL;
 | 
			
		||||
    STACK_OF(X509) *sign_other = NULL, *verify_other = NULL, *rother = NULL;
 | 
			
		||||
    char *sign_certfile = NULL, *verify_certfile = NULL, *rcertfile = NULL;
 | 
			
		||||
    unsigned long sign_flags = 0, verify_flags = 0, rflags = 0;
 | 
			
		||||
    int ret = 1;
 | 
			
		||||
    int accept_count = -1;
 | 
			
		||||
    int badarg = 0;
 | 
			
		||||
    int badsig = 0;
 | 
			
		||||
    int i;
 | 
			
		||||
    int ignore_err = 0;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *reqnames = NULL;
 | 
			
		||||
    STACK *reqnames = NULL;
 | 
			
		||||
    STACK_OF(OCSP_CERTID) *ids = NULL;
 | 
			
		||||
 | 
			
		||||
    X509 *rca_cert = NULL;
 | 
			
		||||
@@ -173,7 +138,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    char *rca_filename = NULL;
 | 
			
		||||
    CA_DB *rdb = NULL;
 | 
			
		||||
    int nmin = 0, ndays = -1;
 | 
			
		||||
    const EVP_MD *cert_id_md = NULL, *rsign_md = NULL;
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        bio_err = BIO_new_fp(stderr, BIO_NOCLOSE);
 | 
			
		||||
@@ -183,7 +147,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    SSL_load_error_strings();
 | 
			
		||||
    OpenSSL_add_ssl_algorithms();
 | 
			
		||||
    args = argv + 1;
 | 
			
		||||
    reqnames = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
    reqnames = sk_new_null();
 | 
			
		||||
    ids = sk_OCSP_CERTID_new_null();
 | 
			
		||||
    while (!badarg && *args && *args[0] == '-') {
 | 
			
		||||
        if (!strcmp(*args, "-out")) {
 | 
			
		||||
@@ -232,13 +196,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                port = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-header")) {
 | 
			
		||||
            if (args[1] && args[2]) {
 | 
			
		||||
                if (!X509V3_add_value(args[1], args[2], &headers))
 | 
			
		||||
                    goto end;
 | 
			
		||||
                args += 2;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-ignore_err"))
 | 
			
		||||
            ignore_err = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-noverify"))
 | 
			
		||||
@@ -267,8 +224,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            verify_flags |= OCSP_TRUSTOTHER;
 | 
			
		||||
        else if (!strcmp(*args, "-no_intern"))
 | 
			
		||||
            verify_flags |= OCSP_NOINTERN;
 | 
			
		||||
        else if (!strcmp(*args, "-badsig"))
 | 
			
		||||
            badsig = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-text")) {
 | 
			
		||||
            req_text = 1;
 | 
			
		||||
            resp_text = 1;
 | 
			
		||||
@@ -325,10 +280,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                CApath = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (args_verify(&args, NULL, &badarg, bio_err, &vpm)) {
 | 
			
		||||
            if (badarg)
 | 
			
		||||
                goto end;
 | 
			
		||||
            continue;
 | 
			
		||||
        } else if (!strcmp(*args, "-validity_period")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
@@ -392,22 +343,18 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                                 NULL, e, "certificate");
 | 
			
		||||
                if (!cert)
 | 
			
		||||
                    goto end;
 | 
			
		||||
                if (!cert_id_md)
 | 
			
		||||
                    cert_id_md = EVP_sha1();
 | 
			
		||||
                if (!add_ocsp_cert(&req, cert, cert_id_md, issuer, ids))
 | 
			
		||||
                if (!add_ocsp_cert(&req, cert, issuer, ids))
 | 
			
		||||
                    goto end;
 | 
			
		||||
                if (!sk_OPENSSL_STRING_push(reqnames, *args))
 | 
			
		||||
                if (!sk_push(reqnames, *args))
 | 
			
		||||
                    goto end;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-serial")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                if (!cert_id_md)
 | 
			
		||||
                    cert_id_md = EVP_sha1();
 | 
			
		||||
                if (!add_ocsp_serial(&req, *args, cert_id_md, issuer, ids))
 | 
			
		||||
                if (!add_ocsp_serial(&req, *args, issuer, ids))
 | 
			
		||||
                    goto end;
 | 
			
		||||
                if (!sk_OPENSSL_STRING_push(reqnames, *args))
 | 
			
		||||
                if (!sk_push(reqnames, *args))
 | 
			
		||||
                    goto end;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
@@ -474,17 +421,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                rcertfile = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-rmd")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                rsign_md = EVP_get_digestbyname(*args);
 | 
			
		||||
                if (!rsign_md)
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
        } else
 | 
			
		||||
            badarg = 1;
 | 
			
		||||
        } else if ((cert_id_md = EVP_get_digestbyname((*args) + 1)) == NULL) {
 | 
			
		||||
            badarg = 1;
 | 
			
		||||
        }
 | 
			
		||||
        args++;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -522,8 +460,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-reqin file        read DER encoded OCSP request from \"file\"\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-respin file       read DER encoded OCSP reponse from \"file\"\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-nonce               add OCSP nonce to request\n");
 | 
			
		||||
        BIO_printf(bio_err, "-nonce             add OCSP nonce to request\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-no_nonce          don't add OCSP nonce to request\n");
 | 
			
		||||
        BIO_printf(bio_err, "-url URL           OCSP responder URL\n");
 | 
			
		||||
@@ -533,10 +470,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-path              path to use in OCSP request\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-CApath dir        trusted certificates directory\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-CAfile file         trusted certificates file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-trusted_first       use locally trusted CA's first when building trust chain\n");
 | 
			
		||||
        BIO_printf(bio_err, "-CAfile file       trusted certificates file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-VAfile file       validator certificates file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
@@ -559,8 +493,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-no_chain          don't chain verify response\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-no_cert_checks    don't do additional checks on signing certificate\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-port num            port to run responder on\n");
 | 
			
		||||
        BIO_printf(bio_err, "-port num          port to run responder on\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-index file        certificate status index file\n");
 | 
			
		||||
        BIO_printf(bio_err, "-CA file           CA certificate\n");
 | 
			
		||||
@@ -580,10 +513,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-resp_key_id       identify reponse by signing certificate key ID\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-nrequest n        number of requests to accept (default unlimited)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-<dgst alg>          use specified digest in the request\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-timeout n           timeout connection to OCSP responder after n seconds\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -601,9 +530,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        add_nonce = 0;
 | 
			
		||||
 | 
			
		||||
    if (!req && reqin) {
 | 
			
		||||
        if (!strcmp(reqin, "-"))
 | 
			
		||||
            derbio = BIO_new_fp(stdin, BIO_NOCLOSE);
 | 
			
		||||
        else
 | 
			
		||||
        derbio = BIO_new_file(reqin, "rb");
 | 
			
		||||
        if (!derbio) {
 | 
			
		||||
            BIO_printf(bio_err, "Error Opening OCSP request file\n");
 | 
			
		||||
@@ -689,9 +615,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                       "signer private key");
 | 
			
		||||
        if (!key)
 | 
			
		||||
            goto end;
 | 
			
		||||
 | 
			
		||||
        if (!OCSP_request_sign
 | 
			
		||||
            (req, signer, key, NULL, sign_other, sign_flags)) {
 | 
			
		||||
            (req, signer, key, EVP_sha1(), sign_other, sign_flags)) {
 | 
			
		||||
            BIO_printf(bio_err, "Error signing OCSP request\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
@@ -701,9 +626,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        OCSP_REQUEST_print(out, req, 0);
 | 
			
		||||
 | 
			
		||||
    if (reqout) {
 | 
			
		||||
        if (!strcmp(reqout, "-"))
 | 
			
		||||
            derbio = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
        else
 | 
			
		||||
        derbio = BIO_new_file(reqout, "wb");
 | 
			
		||||
        if (!derbio) {
 | 
			
		||||
            BIO_printf(bio_err, "Error opening file %s\n", reqout);
 | 
			
		||||
@@ -729,13 +651,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    if (rdb) {
 | 
			
		||||
        i = make_ocsp_response(&resp, req, rdb, rca_cert, rsigner, rkey,
 | 
			
		||||
                               rsign_md, rother, rflags, nmin, ndays, badsig);
 | 
			
		||||
                               rother, rflags, nmin, ndays);
 | 
			
		||||
        if (cbio)
 | 
			
		||||
            send_ocsp_response(cbio, resp);
 | 
			
		||||
    } else if (host) {
 | 
			
		||||
# ifndef OPENSSL_NO_SOCK
 | 
			
		||||
        resp = process_responder(bio_err, req, host, path,
 | 
			
		||||
                                 port, use_ssl, headers, req_timeout);
 | 
			
		||||
                                 port, use_ssl, req_timeout);
 | 
			
		||||
        if (!resp)
 | 
			
		||||
            goto end;
 | 
			
		||||
# else
 | 
			
		||||
@@ -744,9 +666,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto end;
 | 
			
		||||
# endif
 | 
			
		||||
    } else if (respin) {
 | 
			
		||||
        if (!strcmp(respin, "-"))
 | 
			
		||||
            derbio = BIO_new_fp(stdin, BIO_NOCLOSE);
 | 
			
		||||
        else
 | 
			
		||||
        derbio = BIO_new_file(respin, "rb");
 | 
			
		||||
        if (!derbio) {
 | 
			
		||||
            BIO_printf(bio_err, "Error Opening OCSP response file\n");
 | 
			
		||||
@@ -767,9 +686,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 done_resp:
 | 
			
		||||
 | 
			
		||||
    if (respout) {
 | 
			
		||||
        if (!strcmp(respout, "-"))
 | 
			
		||||
            derbio = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
        else
 | 
			
		||||
        derbio = BIO_new_file(respout, "wb");
 | 
			
		||||
        if (!derbio) {
 | 
			
		||||
            BIO_printf(bio_err, "Error opening file %s\n", respout);
 | 
			
		||||
@@ -807,10 +723,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            resp = NULL;
 | 
			
		||||
            goto redo_accept;
 | 
			
		||||
        }
 | 
			
		||||
        ret = 0;
 | 
			
		||||
        goto end;
 | 
			
		||||
    } else if (ridx_filename) {
 | 
			
		||||
        ret = 0;
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -818,8 +730,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        store = setup_verify(bio_err, CAfile, CApath);
 | 
			
		||||
    if (!store)
 | 
			
		||||
        goto end;
 | 
			
		||||
    if (vpm)
 | 
			
		||||
        X509_STORE_set1_param(store, vpm);
 | 
			
		||||
    if (verify_certfile) {
 | 
			
		||||
        verify_other = load_certs(bio_err, verify_certfile, FORMAT_PEM,
 | 
			
		||||
                                  NULL, e, "validator certificate");
 | 
			
		||||
@@ -834,38 +744,37 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 | 
			
		||||
    if (!noverify) {
 | 
			
		||||
        if (req && ((i = OCSP_check_nonce(req, bs)) <= 0)) {
 | 
			
		||||
            if (i == -1)
 | 
			
		||||
                BIO_printf(bio_err, "WARNING: no nonce in response\n");
 | 
			
		||||
            else {
 | 
			
		||||
                BIO_printf(bio_err, "Nonce Verify error\n");
 | 
			
		||||
                ret = 1;
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        i = OCSP_basic_verify(bs, verify_other, store, verify_flags);
 | 
			
		||||
        if (i < 0)
 | 
			
		||||
            i = OCSP_basic_verify(bs, NULL, store, 0);
 | 
			
		||||
 | 
			
		||||
        if (i <= 0) {
 | 
			
		||||
            BIO_printf(bio_err, "Response Verify Failure\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            ret = 1;
 | 
			
		||||
        } else
 | 
			
		||||
            BIO_printf(bio_err, "Response verify OK\n");
 | 
			
		||||
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!print_ocsp_summary(out, bs, req, reqnames, ids, nsec, maxage))
 | 
			
		||||
        ret = 1;
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
    ERR_print_errors(bio_err);
 | 
			
		||||
    X509_free(signer);
 | 
			
		||||
    X509_STORE_free(store);
 | 
			
		||||
    if (vpm)
 | 
			
		||||
        X509_VERIFY_PARAM_free(vpm);
 | 
			
		||||
    EVP_PKEY_free(key);
 | 
			
		||||
    EVP_PKEY_free(rkey);
 | 
			
		||||
    X509_free(issuer);
 | 
			
		||||
@@ -879,11 +788,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    OCSP_REQUEST_free(req);
 | 
			
		||||
    OCSP_RESPONSE_free(resp);
 | 
			
		||||
    OCSP_BASICRESP_free(bs);
 | 
			
		||||
    sk_OPENSSL_STRING_free(reqnames);
 | 
			
		||||
    sk_free(reqnames);
 | 
			
		||||
    sk_OCSP_CERTID_free(ids);
 | 
			
		||||
    sk_X509_pop_free(sign_other, X509_free);
 | 
			
		||||
    sk_X509_pop_free(verify_other, X509_free);
 | 
			
		||||
    sk_CONF_VALUE_pop_free(headers, X509V3_conf_free);
 | 
			
		||||
 | 
			
		||||
    if (thost)
 | 
			
		||||
        OPENSSL_free(thost);
 | 
			
		||||
@@ -895,8 +803,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert,
 | 
			
		||||
                         const EVP_MD *cert_id_md, X509 *issuer,
 | 
			
		||||
static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert, X509 *issuer,
 | 
			
		||||
                         STACK_OF(OCSP_CERTID) *ids)
 | 
			
		||||
{
 | 
			
		||||
    OCSP_CERTID *id;
 | 
			
		||||
@@ -908,7 +815,7 @@ static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert,
 | 
			
		||||
        *req = OCSP_REQUEST_new();
 | 
			
		||||
    if (!*req)
 | 
			
		||||
        goto err;
 | 
			
		||||
    id = OCSP_cert_to_id(cert_id_md, cert, issuer);
 | 
			
		||||
    id = OCSP_cert_to_id(NULL, cert, issuer);
 | 
			
		||||
    if (!id || !sk_OCSP_CERTID_push(ids, id))
 | 
			
		||||
        goto err;
 | 
			
		||||
    if (!OCSP_request_add0_id(*req, id))
 | 
			
		||||
@@ -920,8 +827,7 @@ static int add_ocsp_cert(OCSP_REQUEST **req, X509 *cert,
 | 
			
		||||
    return 0;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int add_ocsp_serial(OCSP_REQUEST **req, char *serial,
 | 
			
		||||
                           const EVP_MD *cert_id_md, X509 *issuer,
 | 
			
		||||
static int add_ocsp_serial(OCSP_REQUEST **req, char *serial, X509 *issuer,
 | 
			
		||||
                           STACK_OF(OCSP_CERTID) *ids)
 | 
			
		||||
{
 | 
			
		||||
    OCSP_CERTID *id;
 | 
			
		||||
@@ -943,7 +849,7 @@ static int add_ocsp_serial(OCSP_REQUEST **req, char *serial,
 | 
			
		||||
        BIO_printf(bio_err, "Error converting serial number %s\n", serial);
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
    id = OCSP_cert_id_new(cert_id_md, iname, ikey, sno);
 | 
			
		||||
    id = OCSP_cert_id_new(EVP_sha1(), iname, ikey, sno);
 | 
			
		||||
    ASN1_INTEGER_free(sno);
 | 
			
		||||
    if (!id || !sk_OCSP_CERTID_push(ids, id))
 | 
			
		||||
        goto err;
 | 
			
		||||
@@ -957,9 +863,8 @@ static int add_ocsp_serial(OCSP_REQUEST **req, char *serial,
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int print_ocsp_summary(BIO *out, OCSP_BASICRESP *bs, OCSP_REQUEST *req,
 | 
			
		||||
                              STACK_OF(OPENSSL_STRING) *names,
 | 
			
		||||
                              STACK_OF(OCSP_CERTID) *ids, long nsec,
 | 
			
		||||
                              long maxage)
 | 
			
		||||
                              STACK * names, STACK_OF(OCSP_CERTID) *ids,
 | 
			
		||||
                              long nsec, long maxage)
 | 
			
		||||
{
 | 
			
		||||
    OCSP_CERTID *id;
 | 
			
		||||
    char *name;
 | 
			
		||||
@@ -969,13 +874,12 @@ static int print_ocsp_summary(BIO *out, OCSP_BASICRESP *bs, OCSP_REQUEST *req,
 | 
			
		||||
 | 
			
		||||
    ASN1_GENERALIZEDTIME *rev, *thisupd, *nextupd;
 | 
			
		||||
 | 
			
		||||
    if (!bs || !req || !sk_OPENSSL_STRING_num(names)
 | 
			
		||||
        || !sk_OCSP_CERTID_num(ids))
 | 
			
		||||
    if (!bs || !req || !sk_num(names) || !sk_OCSP_CERTID_num(ids))
 | 
			
		||||
        return 1;
 | 
			
		||||
 | 
			
		||||
    for (i = 0; i < sk_OCSP_CERTID_num(ids); i++) {
 | 
			
		||||
        id = sk_OCSP_CERTID_value(ids, i);
 | 
			
		||||
        name = sk_OPENSSL_STRING_value(names, i);
 | 
			
		||||
        name = sk_value(names, i);
 | 
			
		||||
        BIO_printf(out, "%s: ", name);
 | 
			
		||||
 | 
			
		||||
        if (!OCSP_resp_find_status(bs, id, &status, &reason,
 | 
			
		||||
@@ -1020,9 +924,8 @@ static int print_ocsp_summary(BIO *out, OCSP_BASICRESP *bs, OCSP_REQUEST *req,
 | 
			
		||||
 | 
			
		||||
static int make_ocsp_response(OCSP_RESPONSE **resp, OCSP_REQUEST *req,
 | 
			
		||||
                              CA_DB *db, X509 *ca, X509 *rcert,
 | 
			
		||||
                              EVP_PKEY *rkey, const EVP_MD *rmd,
 | 
			
		||||
                              STACK_OF(X509) *rother, unsigned long flags,
 | 
			
		||||
                              int nmin, int ndays, int badsig)
 | 
			
		||||
                              EVP_PKEY *rkey, STACK_OF(X509) *rother,
 | 
			
		||||
                              unsigned long flags, int nmin, int ndays)
 | 
			
		||||
{
 | 
			
		||||
    ASN1_TIME *thisupd = NULL, *nextupd = NULL;
 | 
			
		||||
    OCSP_CERTID *cid, *ca_id = NULL;
 | 
			
		||||
@@ -1037,6 +940,8 @@ static int make_ocsp_response(OCSP_RESPONSE **resp, OCSP_REQUEST *req,
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ca_id = OCSP_cert_to_id(EVP_sha1(), NULL, ca);
 | 
			
		||||
 | 
			
		||||
    bs = OCSP_BASICRESP_new();
 | 
			
		||||
    thisupd = X509_gmtime_adj(NULL, 0);
 | 
			
		||||
    if (ndays != -1)
 | 
			
		||||
@@ -1047,23 +952,8 @@ static int make_ocsp_response(OCSP_RESPONSE **resp, OCSP_REQUEST *req,
 | 
			
		||||
        OCSP_ONEREQ *one;
 | 
			
		||||
        ASN1_INTEGER *serial;
 | 
			
		||||
        char **inf;
 | 
			
		||||
        ASN1_OBJECT *cert_id_md_oid;
 | 
			
		||||
        const EVP_MD *cert_id_md;
 | 
			
		||||
        one = OCSP_request_onereq_get0(req, i);
 | 
			
		||||
        cid = OCSP_onereq_get0_id(one);
 | 
			
		||||
 | 
			
		||||
        OCSP_id_get0_info(NULL, &cert_id_md_oid, NULL, NULL, cid);
 | 
			
		||||
 | 
			
		||||
        cert_id_md = EVP_get_digestbyobj(cert_id_md_oid);
 | 
			
		||||
        if (!cert_id_md) {
 | 
			
		||||
            *resp = OCSP_response_create(OCSP_RESPONSE_STATUS_INTERNALERROR,
 | 
			
		||||
                                         NULL);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        if (ca_id)
 | 
			
		||||
            OCSP_CERTID_free(ca_id);
 | 
			
		||||
        ca_id = OCSP_cert_to_id(cert_id_md, NULL, ca);
 | 
			
		||||
 | 
			
		||||
        /* Is this request about our CA? */
 | 
			
		||||
        if (OCSP_id_issuer_cmp(ca_id, cid)) {
 | 
			
		||||
            OCSP_basic_add1_status(bs, cid,
 | 
			
		||||
@@ -1106,10 +996,7 @@ static int make_ocsp_response(OCSP_RESPONSE **resp, OCSP_REQUEST *req,
 | 
			
		||||
 | 
			
		||||
    OCSP_copy_nonce(bs, req);
 | 
			
		||||
 | 
			
		||||
    OCSP_basic_sign(bs, rcert, rkey, rmd, rother, flags);
 | 
			
		||||
 | 
			
		||||
    if (badsig)
 | 
			
		||||
        bs->signature->data[bs->signature->length - 1] ^= 0x1;
 | 
			
		||||
    OCSP_basic_sign(bs, rcert, rkey, EVP_sha1(), rother, flags);
 | 
			
		||||
 | 
			
		||||
    *resp = OCSP_response_create(OCSP_RESPONSE_STATUS_SUCCESSFUL, bs);
 | 
			
		||||
 | 
			
		||||
@@ -1145,7 +1032,7 @@ static char **lookup_serial(CA_DB *db, ASN1_INTEGER *ser)
 | 
			
		||||
 | 
			
		||||
/* Quick and dirty OCSP server: read in and parse input request */
 | 
			
		||||
 | 
			
		||||
static BIO *init_responder(const char *port)
 | 
			
		||||
static BIO *init_responder(char *port)
 | 
			
		||||
{
 | 
			
		||||
    BIO *acbio = NULL, *bufbio = NULL;
 | 
			
		||||
    bufbio = BIO_new(BIO_f_buffer());
 | 
			
		||||
@@ -1177,7 +1064,7 @@ static BIO *init_responder(const char *port)
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int do_responder(OCSP_REQUEST **preq, BIO **pcbio, BIO *acbio,
 | 
			
		||||
                        const char *port)
 | 
			
		||||
                        char *port)
 | 
			
		||||
{
 | 
			
		||||
    int have_post = 0, len;
 | 
			
		||||
    OCSP_REQUEST *req = NULL;
 | 
			
		||||
@@ -1238,13 +1125,11 @@ static int send_ocsp_response(BIO *cbio, OCSP_RESPONSE *resp)
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static OCSP_RESPONSE *query_responder(BIO *err, BIO *cbio, const char *path,
 | 
			
		||||
                                      const STACK_OF(CONF_VALUE) *headers,
 | 
			
		||||
static OCSP_RESPONSE *query_responder(BIO *err, BIO *cbio, char *path,
 | 
			
		||||
                                      OCSP_REQUEST *req, int req_timeout)
 | 
			
		||||
{
 | 
			
		||||
    int fd;
 | 
			
		||||
    int rv;
 | 
			
		||||
    int i;
 | 
			
		||||
    OCSP_REQ_CTX *ctx = NULL;
 | 
			
		||||
    OCSP_RESPONSE *rsp = NULL;
 | 
			
		||||
    fd_set confds;
 | 
			
		||||
@@ -1260,12 +1145,15 @@ static OCSP_RESPONSE *query_responder(BIO *err, BIO *cbio, const char *path,
 | 
			
		||||
        return NULL;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (req_timeout == -1)
 | 
			
		||||
        return OCSP_sendreq_bio(cbio, path, req);
 | 
			
		||||
 | 
			
		||||
    if (BIO_get_fd(cbio, &fd) <= 0) {
 | 
			
		||||
        BIO_puts(err, "Can't get connection fd\n");
 | 
			
		||||
        goto err;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (req_timeout != -1 && rv <= 0) {
 | 
			
		||||
    if (rv <= 0) {
 | 
			
		||||
        FD_ZERO(&confds);
 | 
			
		||||
        openssl_fdset(fd, &confds);
 | 
			
		||||
        tv.tv_usec = 0;
 | 
			
		||||
@@ -1277,25 +1165,14 @@ static OCSP_RESPONSE *query_responder(BIO *err, BIO *cbio, const char *path,
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ctx = OCSP_sendreq_new(cbio, path, NULL, -1);
 | 
			
		||||
    ctx = OCSP_sendreq_new(cbio, path, req, -1);
 | 
			
		||||
    if (!ctx)
 | 
			
		||||
        return NULL;
 | 
			
		||||
 | 
			
		||||
    for (i = 0; i < sk_CONF_VALUE_num(headers); i++) {
 | 
			
		||||
        CONF_VALUE *hdr = sk_CONF_VALUE_value(headers, i);
 | 
			
		||||
        if (!OCSP_REQ_CTX_add1_header(ctx, hdr->name, hdr->value))
 | 
			
		||||
            goto err;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!OCSP_REQ_CTX_set1_req(ctx, req))
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    for (;;) {
 | 
			
		||||
        rv = OCSP_sendreq_nbio(&rsp, ctx);
 | 
			
		||||
        if (rv != -1)
 | 
			
		||||
            break;
 | 
			
		||||
        if (req_timeout == -1)
 | 
			
		||||
            continue;
 | 
			
		||||
        FD_ZERO(&confds);
 | 
			
		||||
        openssl_fdset(fd, &confds);
 | 
			
		||||
        tv.tv_usec = 0;
 | 
			
		||||
@@ -1326,10 +1203,8 @@ static OCSP_RESPONSE *query_responder(BIO *err, BIO *cbio, const char *path,
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
OCSP_RESPONSE *process_responder(BIO *err, OCSP_REQUEST *req,
 | 
			
		||||
                                 const char *host, const char *path,
 | 
			
		||||
                                 const char *port, int use_ssl,
 | 
			
		||||
                                 const STACK_OF(CONF_VALUE) *headers,
 | 
			
		||||
                                 int req_timeout)
 | 
			
		||||
                                 char *host, char *path, char *port,
 | 
			
		||||
                                 int use_ssl, int req_timeout)
 | 
			
		||||
{
 | 
			
		||||
    BIO *cbio = NULL;
 | 
			
		||||
    SSL_CTX *ctx = NULL;
 | 
			
		||||
@@ -1343,7 +1218,16 @@ OCSP_RESPONSE *process_responder(BIO *err, OCSP_REQUEST *req,
 | 
			
		||||
        BIO_set_conn_port(cbio, port);
 | 
			
		||||
    if (use_ssl == 1) {
 | 
			
		||||
        BIO *sbio;
 | 
			
		||||
# if !defined(OPENSSL_NO_SSL2) && !defined(OPENSSL_NO_SSL3)
 | 
			
		||||
        ctx = SSL_CTX_new(SSLv23_client_method());
 | 
			
		||||
# elif !defined(OPENSSL_NO_SSL3)
 | 
			
		||||
        ctx = SSL_CTX_new(SSLv3_client_method());
 | 
			
		||||
# elif !defined(OPENSSL_NO_SSL2)
 | 
			
		||||
        ctx = SSL_CTX_new(SSLv2_client_method());
 | 
			
		||||
# else
 | 
			
		||||
        BIO_printf(err, "SSL is disabled\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
# endif
 | 
			
		||||
        if (ctx == NULL) {
 | 
			
		||||
            BIO_printf(err, "Error creating SSL context.\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
@@ -1352,14 +1236,14 @@ OCSP_RESPONSE *process_responder(BIO *err, OCSP_REQUEST *req,
 | 
			
		||||
        sbio = BIO_new_ssl(ctx, 1);
 | 
			
		||||
        cbio = BIO_push(sbio, cbio);
 | 
			
		||||
    }
 | 
			
		||||
    resp = query_responder(err, cbio, path, headers, req, req_timeout);
 | 
			
		||||
    resp = query_responder(err, cbio, path, req, req_timeout);
 | 
			
		||||
    if (!resp)
 | 
			
		||||
        BIO_printf(bio_err, "Error querying OCSP responder\n");
 | 
			
		||||
 end:
 | 
			
		||||
    if (cbio)
 | 
			
		||||
        BIO_free_all(cbio);
 | 
			
		||||
    if (ctx)
 | 
			
		||||
        SSL_CTX_free(ctx);
 | 
			
		||||
    if (cbio)
 | 
			
		||||
        BIO_free_all(cbio);
 | 
			
		||||
    return resp;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
@@ -21,17 +21,12 @@ oid_section		= new_oids
 | 
			
		||||
 | 
			
		||||
[ new_oids ]
 | 
			
		||||
 | 
			
		||||
# We can add new OIDs in here for use by 'ca', 'req' and 'ts'.
 | 
			
		||||
# We can add new OIDs in here for use by 'ca' and 'req'.
 | 
			
		||||
# Add a simple OID like this:
 | 
			
		||||
# testoid1=1.2.3.4
 | 
			
		||||
# Or use config file substitution like this:
 | 
			
		||||
# testoid2=${testoid1}.5.6
 | 
			
		||||
 | 
			
		||||
# Policies used by the TSA examples.
 | 
			
		||||
tsa_policy1 = 1.2.3.4.1
 | 
			
		||||
tsa_policy2 = 1.2.3.4.5.6
 | 
			
		||||
tsa_policy3 = 1.2.3.4.5.7
 | 
			
		||||
 | 
			
		||||
####################################################################
 | 
			
		||||
[ ca ]
 | 
			
		||||
default_ca	= CA_default		# The default ca section
 | 
			
		||||
@@ -44,7 +39,7 @@ certs		= $dir.certs]		# Where the issued certs are kept
 | 
			
		||||
crl_dir		= $dir.crl]		# Where the issued crl are kept
 | 
			
		||||
database	= $dir]index.txt	# database index file.
 | 
			
		||||
#unique_subject	= no			# Set to 'no' to allow creation of
 | 
			
		||||
					# several certs with same subject.
 | 
			
		||||
					# several ctificates with same subject.
 | 
			
		||||
new_certs_dir	= $dir.newcerts]		# default place for new certs.
 | 
			
		||||
 | 
			
		||||
certificate	= $dir]cacert.pem 	# The CA certificate
 | 
			
		||||
@@ -55,7 +50,7 @@ crl		= $dir]crl.pem 		# The current CRL
 | 
			
		||||
private_key	= $dir.private]cakey.pem# The private key
 | 
			
		||||
RANDFILE	= $dir.private].rand	# private random number file
 | 
			
		||||
 | 
			
		||||
x509_extensions	= usr_cert		# The extensions to add to the cert
 | 
			
		||||
x509_extensions	= usr_cert		# The extentions to add to the cert
 | 
			
		||||
 | 
			
		||||
# Comment out the following two lines for the "traditional"
 | 
			
		||||
# (and highly broken) format.
 | 
			
		||||
@@ -72,7 +67,7 @@ cert_opt 	= ca_default		# Certificate field options
 | 
			
		||||
 | 
			
		||||
default_days	= 365			# how long to certify for
 | 
			
		||||
default_crl_days= 30			# how long before next CRL
 | 
			
		||||
default_md	= default		# use public key default MD
 | 
			
		||||
default_md	= sha1			# which md to use.
 | 
			
		||||
preserve	= no			# keep passed DN ordering
 | 
			
		||||
 | 
			
		||||
# A few difference way of specifying how similar the request should look
 | 
			
		||||
@@ -103,11 +98,11 @@ emailAddress		= optional
 | 
			
		||||
 | 
			
		||||
####################################################################
 | 
			
		||||
[ req ]
 | 
			
		||||
default_bits		= 2048
 | 
			
		||||
default_bits		= 1024
 | 
			
		||||
default_keyfile 	= privkey.pem
 | 
			
		||||
distinguished_name	= req_distinguished_name
 | 
			
		||||
attributes		= req_attributes
 | 
			
		||||
x509_extensions	= v3_ca	# The extensions to add to the self signed cert
 | 
			
		||||
x509_extensions	= v3_ca	# The extentions to add to the self signed cert
 | 
			
		||||
 | 
			
		||||
# Passwords for private keys if not present they will be prompted for
 | 
			
		||||
# input_password = secret
 | 
			
		||||
@@ -115,12 +110,13 @@ x509_extensions	= v3_ca	# The extensions to add to the self signed cert
 | 
			
		||||
 | 
			
		||||
# This sets a mask for permitted string types. There are several options. 
 | 
			
		||||
# default: PrintableString, T61String, BMPString.
 | 
			
		||||
# pkix	 : PrintableString, BMPString (PKIX recommendation before 2004)
 | 
			
		||||
# utf8only: only UTF8Strings (PKIX recommendation after 2004).
 | 
			
		||||
# pkix	 : PrintableString, BMPString.
 | 
			
		||||
# utf8only: only UTF8Strings.
 | 
			
		||||
# nombstr : PrintableString, T61String (no BMPStrings or UTF8Strings).
 | 
			
		||||
# MASK:XXXX a literal mask value.
 | 
			
		||||
# WARNING: ancient versions of Netscape crash on BMPStrings or UTF8Strings.
 | 
			
		||||
string_mask = utf8only
 | 
			
		||||
# WARNING: current versions of Netscape crash on BMPStrings or UTF8Strings
 | 
			
		||||
# so use this option with caution!
 | 
			
		||||
string_mask = nombstr
 | 
			
		||||
 | 
			
		||||
# req_extensions = v3_req # The extensions to add to a certificate request
 | 
			
		||||
 | 
			
		||||
@@ -211,9 +207,6 @@ authorityKeyIdentifier=keyid,issuer
 | 
			
		||||
#nsCaPolicyUrl
 | 
			
		||||
#nsSslServerName
 | 
			
		||||
 | 
			
		||||
# This is required for TSA certificates.
 | 
			
		||||
# extendedKeyUsage = critical,timeStamping
 | 
			
		||||
 | 
			
		||||
[ v3_req ]
 | 
			
		||||
 | 
			
		||||
# Extensions to add to a certificate request
 | 
			
		||||
@@ -231,7 +224,7 @@ keyUsage = nonRepudiation, digitalSignature, keyEncipherment
 | 
			
		||||
 | 
			
		||||
subjectKeyIdentifier=hash
 | 
			
		||||
 | 
			
		||||
authorityKeyIdentifier=keyid:always,issuer
 | 
			
		||||
authorityKeyIdentifier=keyid:always,issuer:always
 | 
			
		||||
 | 
			
		||||
# This is what PKIX recommends but some broken software chokes on critical
 | 
			
		||||
# extensions.
 | 
			
		||||
@@ -264,7 +257,7 @@ basicConstraints = CA:true
 | 
			
		||||
# Only issuerAltName and authorityKeyIdentifier make any sense in a CRL.
 | 
			
		||||
 | 
			
		||||
# issuerAltName=issuer:copy
 | 
			
		||||
authorityKeyIdentifier=keyid:always
 | 
			
		||||
authorityKeyIdentifier=keyid:always,issuer:always
 | 
			
		||||
 | 
			
		||||
[ proxy_cert_ext ]
 | 
			
		||||
# These extensions should be added when creating a proxy certificate
 | 
			
		||||
@@ -297,7 +290,7 @@ nsComment			= "OpenSSL Generated Certificate"
 | 
			
		||||
 | 
			
		||||
# PKIX recommendations harmless if included in all certificates.
 | 
			
		||||
subjectKeyIdentifier=hash
 | 
			
		||||
authorityKeyIdentifier=keyid,issuer
 | 
			
		||||
authorityKeyIdentifier=keyid,issuer:always
 | 
			
		||||
 | 
			
		||||
# This stuff is for subjectAltName and issuerAltname.
 | 
			
		||||
# Import the email address.
 | 
			
		||||
@@ -318,33 +311,3 @@ authorityKeyIdentifier=keyid,issuer
 | 
			
		||||
 | 
			
		||||
# This really needs to be in place for it to be a proxy certificate.
 | 
			
		||||
proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:3,policy:foo
 | 
			
		||||
 | 
			
		||||
####################################################################
 | 
			
		||||
[ tsa ]
 | 
			
		||||
 | 
			
		||||
default_tsa = tsa_config1	# the default TSA section
 | 
			
		||||
 | 
			
		||||
[ tsa_config1 ]
 | 
			
		||||
 | 
			
		||||
# These are used by the TSA reply generation only.
 | 
			
		||||
dir		= sys\$disk:[.demoCA		# TSA root directory
 | 
			
		||||
serial		= $dir]tsaserial.	# The current serial number (mandatory)
 | 
			
		||||
crypto_device	= builtin		# OpenSSL engine to use for signing
 | 
			
		||||
signer_cert	= $dir/tsacert.pem 	# The TSA signing certificate
 | 
			
		||||
					# (optional)
 | 
			
		||||
certs		= $dir.cacert.pem]	# Certificate chain to include in reply
 | 
			
		||||
					# (optional)
 | 
			
		||||
signer_key	= $dir/private/tsakey.pem # The TSA private key (optional)
 | 
			
		||||
 | 
			
		||||
default_policy	= tsa_policy1		# Policy if request did not specify it
 | 
			
		||||
					# (optional)
 | 
			
		||||
other_policies	= tsa_policy2, tsa_policy3	# acceptable policies (optional)
 | 
			
		||||
digests		= md5, sha1		# Acceptable message digests (mandatory)
 | 
			
		||||
accuracy	= secs:1, millisecs:500, microsecs:100	# (optional)
 | 
			
		||||
clock_precision_digits  = 0	# number of digits after dot. (optional)
 | 
			
		||||
ordering		= yes	# Is ordering defined for timestamps?
 | 
			
		||||
				# (optional, default: no)
 | 
			
		||||
tsa_name		= yes	# Must the TSA name be included in the reply?
 | 
			
		||||
				# (optional, default: no)
 | 
			
		||||
ess_cert_id_chain	= no	# Must the ESS cert id chain be included?
 | 
			
		||||
				# (optional, default: no)
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										275
									
								
								apps/openssl.c
									
									
									
									
									
								
							
							
						
						
									
										275
									
								
								apps/openssl.c
									
									
									
									
									
								
							@@ -117,7 +117,6 @@
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/bio.h>
 | 
			
		||||
#include <openssl/crypto.h>
 | 
			
		||||
#include <openssl/rand.h>
 | 
			
		||||
#include <openssl/lhash.h>
 | 
			
		||||
#include <openssl/conf.h>
 | 
			
		||||
#include <openssl/x509.h>
 | 
			
		||||
@@ -131,9 +130,6 @@
 | 
			
		||||
#include "progs.h"
 | 
			
		||||
#include "s_apps.h"
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#ifdef OPENSSL_FIPS
 | 
			
		||||
# include <openssl/fips.h>
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * The LHASH callbacks ("hash" & "cmp") have been replaced by functions with
 | 
			
		||||
@@ -142,17 +138,19 @@
 | 
			
		||||
 * macro-generated wrapper functions.
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
static LHASH_OF(FUNCTION) *prog_init(void);
 | 
			
		||||
static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[]);
 | 
			
		||||
static void list_pkey(BIO *out);
 | 
			
		||||
static void list_cipher(BIO *out);
 | 
			
		||||
static void list_md(BIO *out);
 | 
			
		||||
/* static unsigned long MS_CALLBACK hash(FUNCTION *a); */
 | 
			
		||||
static unsigned long MS_CALLBACK hash(const void *a_void);
 | 
			
		||||
/* static int MS_CALLBACK cmp(FUNCTION *a,FUNCTION *b); */
 | 
			
		||||
static int MS_CALLBACK cmp(const void *a_void, const void *b_void);
 | 
			
		||||
static LHASH *prog_init(void);
 | 
			
		||||
static int do_cmd(LHASH *prog, int argc, char *argv[]);
 | 
			
		||||
char *default_config_file = NULL;
 | 
			
		||||
 | 
			
		||||
/* Make sure there is only one when MONOLITH is defined */
 | 
			
		||||
#ifdef MONOLITH
 | 
			
		||||
CONF *config = NULL;
 | 
			
		||||
BIO *bio_err = NULL;
 | 
			
		||||
int in_FIPS_mode = 0;
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
static void lock_dbg_cb(int mode, int type, const char *file, int line)
 | 
			
		||||
@@ -209,13 +207,7 @@ static void lock_dbg_cb(int mode, int type, const char *file, int line)
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#if defined( OPENSSL_SYS_VMS) && (__INITIAL_POINTER_SIZE == 64)
 | 
			
		||||
# define ARGV _Argv
 | 
			
		||||
#else
 | 
			
		||||
# define ARGV Argv
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
int main(int Argc, char *ARGV[])
 | 
			
		||||
int main(int Argc, char *Argv[])
 | 
			
		||||
{
 | 
			
		||||
    ARGS arg;
 | 
			
		||||
#define PROG_NAME_SIZE  39
 | 
			
		||||
@@ -227,63 +219,28 @@ int main(int Argc, char *ARGV[])
 | 
			
		||||
    int n, i, ret = 0;
 | 
			
		||||
    int argc;
 | 
			
		||||
    char **argv, *p;
 | 
			
		||||
    LHASH_OF(FUNCTION) *prog = NULL;
 | 
			
		||||
    LHASH *prog = NULL;
 | 
			
		||||
    long errline;
 | 
			
		||||
 | 
			
		||||
#if defined( OPENSSL_SYS_VMS) && (__INITIAL_POINTER_SIZE == 64)
 | 
			
		||||
    /*-
 | 
			
		||||
     * 2011-03-22 SMS.
 | 
			
		||||
     * If we have 32-bit pointers everywhere, then we're safe, and
 | 
			
		||||
     * we bypass this mess, as on non-VMS systems.  (See ARGV,
 | 
			
		||||
     * above.)
 | 
			
		||||
     * Problem 1: Compaq/HP C before V7.3 always used 32-bit
 | 
			
		||||
     * pointers for argv[].
 | 
			
		||||
     * Fix 1: For a 32-bit argv[], when we're using 64-bit pointers
 | 
			
		||||
     * everywhere else, we always allocate and use a 64-bit
 | 
			
		||||
     * duplicate of argv[].
 | 
			
		||||
     * Problem 2: Compaq/HP C V7.3 (Alpha, IA64) before ECO1 failed
 | 
			
		||||
     * to NULL-terminate a 64-bit argv[].  (As this was written, the
 | 
			
		||||
     * compiler ECO was available only on IA64.)
 | 
			
		||||
     * Fix 2: Unless advised not to (VMS_TRUST_ARGV), we test a
 | 
			
		||||
     * 64-bit argv[argc] for NULL, and, if necessary, use a
 | 
			
		||||
     * (properly) NULL-terminated (64-bit) duplicate of argv[].
 | 
			
		||||
     * The same code is used in either case to duplicate argv[].
 | 
			
		||||
     * Some of these decisions could be handled in preprocessing,
 | 
			
		||||
     * but the code tends to get even uglier, and the penalty for
 | 
			
		||||
     * deciding at compile- or run-time is tiny.
 | 
			
		||||
     */
 | 
			
		||||
    char **Argv = NULL;
 | 
			
		||||
    int free_Argv = 0;
 | 
			
		||||
 | 
			
		||||
    if ((sizeof(_Argv) < 8)     /* 32-bit argv[]. */
 | 
			
		||||
# if !defined( VMS_TRUST_ARGV)
 | 
			
		||||
        || (_Argv[Argc] != NULL) /* Untrusted argv[argc] not NULL. */
 | 
			
		||||
# endif
 | 
			
		||||
        ) {
 | 
			
		||||
        int i;
 | 
			
		||||
        Argv = OPENSSL_malloc((Argc + 1) * sizeof(char *));
 | 
			
		||||
        if (Argv == NULL) {
 | 
			
		||||
            ret = -1;
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        for (i = 0; i < Argc; i++)
 | 
			
		||||
            Argv[i] = _Argv[i];
 | 
			
		||||
        Argv[Argc] = NULL;      /* Certain NULL termination. */
 | 
			
		||||
        free_Argv = 1;
 | 
			
		||||
    } else {
 | 
			
		||||
        /*
 | 
			
		||||
         * Use the known-good 32-bit argv[] (which needs the type cast to
 | 
			
		||||
         * satisfy the compiler), or the trusted or tested-good 64-bit argv[]
 | 
			
		||||
         * as-is.
 | 
			
		||||
         */
 | 
			
		||||
        Argv = (char **)_Argv;
 | 
			
		||||
    }
 | 
			
		||||
#endif                          /* defined( OPENSSL_SYS_VMS) &&
 | 
			
		||||
                                 * (__INITIAL_POINTER_SIZE == 64) */
 | 
			
		||||
 | 
			
		||||
    arg.data = NULL;
 | 
			
		||||
    arg.count = 0;
 | 
			
		||||
 | 
			
		||||
    in_FIPS_mode = 0;
 | 
			
		||||
 | 
			
		||||
    if (getenv("OPENSSL_FIPS")) {
 | 
			
		||||
#ifdef OPENSSL_FIPS
 | 
			
		||||
        if (!FIPS_mode_set(1)) {
 | 
			
		||||
            ERR_load_crypto_strings();
 | 
			
		||||
            ERR_print_errors(BIO_new_fp(stderr, BIO_NOCLOSE));
 | 
			
		||||
            EXIT(1);
 | 
			
		||||
        }
 | 
			
		||||
        in_FIPS_mode = 1;
 | 
			
		||||
#else
 | 
			
		||||
        fprintf(stderr, "FIPS mode not supported.\n");
 | 
			
		||||
        EXIT(1);
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        if ((bio_err = BIO_new(BIO_s_file())) != NULL)
 | 
			
		||||
            BIO_set_fp(bio_err, stderr, BIO_NOCLOSE | BIO_FP_TEXT);
 | 
			
		||||
@@ -308,19 +265,6 @@ int main(int Argc, char *ARGV[])
 | 
			
		||||
        CRYPTO_set_locking_callback(lock_dbg_cb);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (getenv("OPENSSL_FIPS")) {
 | 
			
		||||
#ifdef OPENSSL_FIPS
 | 
			
		||||
        if (!FIPS_mode_set(1)) {
 | 
			
		||||
            ERR_load_crypto_strings();
 | 
			
		||||
            ERR_print_errors(BIO_new_fp(stderr, BIO_NOCLOSE));
 | 
			
		||||
            EXIT(1);
 | 
			
		||||
        }
 | 
			
		||||
#else
 | 
			
		||||
        fprintf(stderr, "FIPS mode not supported.\n");
 | 
			
		||||
        EXIT(1);
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
    /* Lets load up our environment a little */
 | 
			
		||||
@@ -335,17 +279,9 @@ int main(int Argc, char *ARGV[])
 | 
			
		||||
    config = NCONF_new(NULL);
 | 
			
		||||
    i = NCONF_load(config, p, &errline);
 | 
			
		||||
    if (i == 0) {
 | 
			
		||||
        if (ERR_GET_REASON(ERR_peek_last_error())
 | 
			
		||||
            == CONF_R_NO_SUCH_FILE) {
 | 
			
		||||
            BIO_printf(bio_err, "WARNING: can't open config file: %s\n", p);
 | 
			
		||||
            ERR_clear_error();
 | 
			
		||||
        NCONF_free(config);
 | 
			
		||||
        config = NULL;
 | 
			
		||||
        } else {
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            NCONF_free(config);
 | 
			
		||||
            exit(1);
 | 
			
		||||
        }
 | 
			
		||||
        ERR_clear_error();
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    prog = prog_init();
 | 
			
		||||
@@ -354,7 +290,7 @@ int main(int Argc, char *ARGV[])
 | 
			
		||||
    program_name(Argv[0], pname, sizeof pname);
 | 
			
		||||
 | 
			
		||||
    f.name = pname;
 | 
			
		||||
    fp = lh_FUNCTION_retrieve(prog, &f);
 | 
			
		||||
    fp = (FUNCTION *) lh_retrieve(prog, &f);
 | 
			
		||||
    if (fp != NULL) {
 | 
			
		||||
        Argv[0] = pname;
 | 
			
		||||
        ret = fp->func(Argc, Argv);
 | 
			
		||||
@@ -424,34 +360,25 @@ int main(int Argc, char *ARGV[])
 | 
			
		||||
        config = NULL;
 | 
			
		||||
    }
 | 
			
		||||
    if (prog != NULL)
 | 
			
		||||
        lh_FUNCTION_free(prog);
 | 
			
		||||
        lh_free(prog);
 | 
			
		||||
    if (arg.data != NULL)
 | 
			
		||||
        OPENSSL_free(arg.data);
 | 
			
		||||
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
 | 
			
		||||
    CRYPTO_mem_leaks(bio_err);
 | 
			
		||||
    if (bio_err != NULL) {
 | 
			
		||||
        BIO_free(bio_err);
 | 
			
		||||
        bio_err = NULL;
 | 
			
		||||
    }
 | 
			
		||||
#if defined( OPENSSL_SYS_VMS) && (__INITIAL_POINTER_SIZE == 64)
 | 
			
		||||
    /* Free any duplicate Argv[] storage. */
 | 
			
		||||
    if (free_Argv) {
 | 
			
		||||
        OPENSSL_free(Argv);
 | 
			
		||||
    }
 | 
			
		||||
#endif
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    CRYPTO_mem_leaks(bio_err);
 | 
			
		||||
 | 
			
		||||
    OPENSSL_EXIT(ret);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#define LIST_STANDARD_COMMANDS "list-standard-commands"
 | 
			
		||||
#define LIST_MESSAGE_DIGEST_COMMANDS "list-message-digest-commands"
 | 
			
		||||
#define LIST_MESSAGE_DIGEST_ALGORITHMS "list-message-digest-algorithms"
 | 
			
		||||
#define LIST_CIPHER_COMMANDS "list-cipher-commands"
 | 
			
		||||
#define LIST_CIPHER_ALGORITHMS "list-cipher-algorithms"
 | 
			
		||||
#define LIST_PUBLIC_KEY_ALGORITHMS "list-public-key-algorithms"
 | 
			
		||||
 | 
			
		||||
static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
 | 
			
		||||
static int do_cmd(LHASH *prog, int argc, char *argv[])
 | 
			
		||||
{
 | 
			
		||||
    FUNCTION f, *fp;
 | 
			
		||||
    int i, ret = 1, tp, nl;
 | 
			
		||||
@@ -461,18 +388,7 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    f.name = argv[0];
 | 
			
		||||
    fp = lh_FUNCTION_retrieve(prog, &f);
 | 
			
		||||
    if (fp == NULL) {
 | 
			
		||||
        if (EVP_get_digestbyname(argv[0])) {
 | 
			
		||||
            f.type = FUNC_TYPE_MD;
 | 
			
		||||
            f.func = dgst_main;
 | 
			
		||||
            fp = &f;
 | 
			
		||||
        } else if (EVP_get_cipherbyname(argv[0])) {
 | 
			
		||||
            f.type = FUNC_TYPE_CIPHER;
 | 
			
		||||
            f.func = enc_main;
 | 
			
		||||
            fp = &f;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    fp = (FUNCTION *) lh_retrieve(prog, &f);
 | 
			
		||||
    if (fp != NULL) {
 | 
			
		||||
        ret = fp->func(argc, argv);
 | 
			
		||||
    } else if ((strncmp(argv[0], "no-", 3)) == 0) {
 | 
			
		||||
@@ -484,7 +400,7 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
        f.name = argv[0] + 3;
 | 
			
		||||
        ret = (lh_FUNCTION_retrieve(prog, &f) != NULL);
 | 
			
		||||
        ret = (lh_retrieve(prog, &f) != NULL);
 | 
			
		||||
        if (!ret)
 | 
			
		||||
            BIO_printf(bio_stdout, "%s\n", argv[0]);
 | 
			
		||||
        else
 | 
			
		||||
@@ -499,10 +415,7 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
 | 
			
		||||
        goto end;
 | 
			
		||||
    } else if ((strcmp(argv[0], LIST_STANDARD_COMMANDS) == 0) ||
 | 
			
		||||
               (strcmp(argv[0], LIST_MESSAGE_DIGEST_COMMANDS) == 0) ||
 | 
			
		||||
               (strcmp(argv[0], LIST_MESSAGE_DIGEST_ALGORITHMS) == 0) ||
 | 
			
		||||
               (strcmp(argv[0], LIST_CIPHER_COMMANDS) == 0) ||
 | 
			
		||||
               (strcmp(argv[0], LIST_CIPHER_ALGORITHMS) == 0) ||
 | 
			
		||||
               (strcmp(argv[0], LIST_PUBLIC_KEY_ALGORITHMS) == 0)) {
 | 
			
		||||
               (strcmp(argv[0], LIST_CIPHER_COMMANDS) == 0)) {
 | 
			
		||||
        int list_type;
 | 
			
		||||
        BIO *bio_stdout;
 | 
			
		||||
 | 
			
		||||
@@ -510,12 +423,6 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
 | 
			
		||||
            list_type = FUNC_TYPE_GENERAL;
 | 
			
		||||
        else if (strcmp(argv[0], LIST_MESSAGE_DIGEST_COMMANDS) == 0)
 | 
			
		||||
            list_type = FUNC_TYPE_MD;
 | 
			
		||||
        else if (strcmp(argv[0], LIST_MESSAGE_DIGEST_ALGORITHMS) == 0)
 | 
			
		||||
            list_type = FUNC_TYPE_MD_ALG;
 | 
			
		||||
        else if (strcmp(argv[0], LIST_PUBLIC_KEY_ALGORITHMS) == 0)
 | 
			
		||||
            list_type = FUNC_TYPE_PKEY;
 | 
			
		||||
        else if (strcmp(argv[0], LIST_CIPHER_ALGORITHMS) == 0)
 | 
			
		||||
            list_type = FUNC_TYPE_CIPHER_ALG;
 | 
			
		||||
        else                    /* strcmp(argv[0],LIST_CIPHER_COMMANDS) == 0 */
 | 
			
		||||
            list_type = FUNC_TYPE_CIPHER;
 | 
			
		||||
        bio_stdout = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
@@ -526,20 +433,9 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
        if (!load_config(bio_err, NULL))
 | 
			
		||||
            goto end;
 | 
			
		||||
 | 
			
		||||
        if (list_type == FUNC_TYPE_PKEY)
 | 
			
		||||
            list_pkey(bio_stdout);
 | 
			
		||||
        if (list_type == FUNC_TYPE_MD_ALG)
 | 
			
		||||
            list_md(bio_stdout);
 | 
			
		||||
        if (list_type == FUNC_TYPE_CIPHER_ALG)
 | 
			
		||||
            list_cipher(bio_stdout);
 | 
			
		||||
        else {
 | 
			
		||||
        for (fp = functions; fp->name != NULL; fp++)
 | 
			
		||||
            if (fp->type == list_type)
 | 
			
		||||
                BIO_printf(bio_stdout, "%s\n", fp->name);
 | 
			
		||||
        }
 | 
			
		||||
        BIO_free_all(bio_stdout);
 | 
			
		||||
        ret = 0;
 | 
			
		||||
        goto end;
 | 
			
		||||
@@ -597,89 +493,9 @@ static int SortFnByName(const void *_f1, const void *_f2)
 | 
			
		||||
    return strcmp(f1->name, f2->name);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static void list_pkey(BIO *out)
 | 
			
		||||
static LHASH *prog_init(void)
 | 
			
		||||
{
 | 
			
		||||
    int i;
 | 
			
		||||
    for (i = 0; i < EVP_PKEY_asn1_get_count(); i++) {
 | 
			
		||||
        const EVP_PKEY_ASN1_METHOD *ameth;
 | 
			
		||||
        int pkey_id, pkey_base_id, pkey_flags;
 | 
			
		||||
        const char *pinfo, *pem_str;
 | 
			
		||||
        ameth = EVP_PKEY_asn1_get0(i);
 | 
			
		||||
        EVP_PKEY_asn1_get0_info(&pkey_id, &pkey_base_id, &pkey_flags,
 | 
			
		||||
                                &pinfo, &pem_str, ameth);
 | 
			
		||||
        if (pkey_flags & ASN1_PKEY_ALIAS) {
 | 
			
		||||
            BIO_printf(out, "Name: %s\n", OBJ_nid2ln(pkey_id));
 | 
			
		||||
            BIO_printf(out, "\tType: Alias to %s\n",
 | 
			
		||||
                       OBJ_nid2ln(pkey_base_id));
 | 
			
		||||
        } else {
 | 
			
		||||
            BIO_printf(out, "Name: %s\n", pinfo);
 | 
			
		||||
            BIO_printf(out, "\tType: %s Algorithm\n",
 | 
			
		||||
                       pkey_flags & ASN1_PKEY_DYNAMIC ?
 | 
			
		||||
                       "External" : "Builtin");
 | 
			
		||||
            BIO_printf(out, "\tOID: %s\n", OBJ_nid2ln(pkey_id));
 | 
			
		||||
            if (pem_str == NULL)
 | 
			
		||||
                pem_str = "(none)";
 | 
			
		||||
            BIO_printf(out, "\tPEM string: %s\n", pem_str);
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static void list_cipher_fn(const EVP_CIPHER *c,
 | 
			
		||||
                           const char *from, const char *to, void *arg)
 | 
			
		||||
{
 | 
			
		||||
    if (c)
 | 
			
		||||
        BIO_printf(arg, "%s\n", EVP_CIPHER_name(c));
 | 
			
		||||
    else {
 | 
			
		||||
        if (!from)
 | 
			
		||||
            from = "<undefined>";
 | 
			
		||||
        if (!to)
 | 
			
		||||
            to = "<undefined>";
 | 
			
		||||
        BIO_printf(arg, "%s => %s\n", from, to);
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static void list_cipher(BIO *out)
 | 
			
		||||
{
 | 
			
		||||
    EVP_CIPHER_do_all_sorted(list_cipher_fn, out);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static void list_md_fn(const EVP_MD *m,
 | 
			
		||||
                       const char *from, const char *to, void *arg)
 | 
			
		||||
{
 | 
			
		||||
    if (m)
 | 
			
		||||
        BIO_printf(arg, "%s\n", EVP_MD_name(m));
 | 
			
		||||
    else {
 | 
			
		||||
        if (!from)
 | 
			
		||||
            from = "<undefined>";
 | 
			
		||||
        if (!to)
 | 
			
		||||
            to = "<undefined>";
 | 
			
		||||
        BIO_printf(arg, "%s => %s\n", from, to);
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static void list_md(BIO *out)
 | 
			
		||||
{
 | 
			
		||||
    EVP_MD_do_all_sorted(list_md_fn, out);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int function_cmp(const FUNCTION * a, const FUNCTION * b)
 | 
			
		||||
{
 | 
			
		||||
    return strncmp(a->name, b->name, 8);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static IMPLEMENT_LHASH_COMP_FN(function, FUNCTION)
 | 
			
		||||
 | 
			
		||||
static unsigned long function_hash(const FUNCTION * a)
 | 
			
		||||
{
 | 
			
		||||
    return lh_strhash(a->name);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static IMPLEMENT_LHASH_HASH_FN(function, FUNCTION)
 | 
			
		||||
 | 
			
		||||
static LHASH_OF(FUNCTION) *prog_init(void)
 | 
			
		||||
{
 | 
			
		||||
    LHASH_OF(FUNCTION) *ret;
 | 
			
		||||
    LHASH *ret;
 | 
			
		||||
    FUNCTION *f;
 | 
			
		||||
    size_t i;
 | 
			
		||||
 | 
			
		||||
@@ -687,10 +503,23 @@ static LHASH_OF(FUNCTION) *prog_init(void)
 | 
			
		||||
    for (i = 0, f = functions; f->name != NULL; ++f, ++i) ;
 | 
			
		||||
    qsort(functions, i, sizeof *functions, SortFnByName);
 | 
			
		||||
 | 
			
		||||
    if ((ret = lh_FUNCTION_new()) == NULL)
 | 
			
		||||
    if ((ret = lh_new(hash, cmp)) == NULL)
 | 
			
		||||
        return (NULL);
 | 
			
		||||
 | 
			
		||||
    for (f = functions; f->name != NULL; f++)
 | 
			
		||||
        (void)lh_FUNCTION_insert(ret, f);
 | 
			
		||||
        lh_insert(ret, f);
 | 
			
		||||
    return (ret);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
/* static int MS_CALLBACK cmp(FUNCTION *a, FUNCTION *b) */
 | 
			
		||||
static int MS_CALLBACK cmp(const void *a_void, const void *b_void)
 | 
			
		||||
{
 | 
			
		||||
    return (strncmp(((const FUNCTION *)a_void)->name,
 | 
			
		||||
                    ((const FUNCTION *)b_void)->name, 8));
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
/* static unsigned long MS_CALLBACK hash(FUNCTION *a) */
 | 
			
		||||
static unsigned long MS_CALLBACK hash(const void *a_void)
 | 
			
		||||
{
 | 
			
		||||
    return (lh_strhash(((const FUNCTION *)a_void)->name));
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
@@ -21,17 +21,12 @@ oid_section		= new_oids
 | 
			
		||||
 | 
			
		||||
[ new_oids ]
 | 
			
		||||
 | 
			
		||||
# We can add new OIDs in here for use by 'ca', 'req' and 'ts'.
 | 
			
		||||
# We can add new OIDs in here for use by 'ca' and 'req'.
 | 
			
		||||
# Add a simple OID like this:
 | 
			
		||||
# testoid1=1.2.3.4
 | 
			
		||||
# Or use config file substitution like this:
 | 
			
		||||
# testoid2=${testoid1}.5.6
 | 
			
		||||
 | 
			
		||||
# Policies used by the TSA examples.
 | 
			
		||||
tsa_policy1 = 1.2.3.4.1
 | 
			
		||||
tsa_policy2 = 1.2.3.4.5.6
 | 
			
		||||
tsa_policy3 = 1.2.3.4.5.7
 | 
			
		||||
 | 
			
		||||
####################################################################
 | 
			
		||||
[ ca ]
 | 
			
		||||
default_ca	= CA_default		# The default ca section
 | 
			
		||||
@@ -44,7 +39,7 @@ certs		= $dir/certs		# Where the issued certs are kept
 | 
			
		||||
crl_dir		= $dir/crl		# Where the issued crl are kept
 | 
			
		||||
database	= $dir/index.txt	# database index file.
 | 
			
		||||
#unique_subject	= no			# Set to 'no' to allow creation of
 | 
			
		||||
					# several certs with same subject.
 | 
			
		||||
					# several ctificates with same subject.
 | 
			
		||||
new_certs_dir	= $dir/newcerts		# default place for new certs.
 | 
			
		||||
 | 
			
		||||
certificate	= $dir/cacert.pem 	# The CA certificate
 | 
			
		||||
@@ -55,7 +50,7 @@ crl		= $dir/crl.pem 		# The current CRL
 | 
			
		||||
private_key	= $dir/private/cakey.pem# The private key
 | 
			
		||||
RANDFILE	= $dir/private/.rand	# private random number file
 | 
			
		||||
 | 
			
		||||
x509_extensions	= usr_cert		# The extensions to add to the cert
 | 
			
		||||
x509_extensions	= usr_cert		# The extentions to add to the cert
 | 
			
		||||
 | 
			
		||||
# Comment out the following two lines for the "traditional"
 | 
			
		||||
# (and highly broken) format.
 | 
			
		||||
@@ -72,7 +67,7 @@ cert_opt 	= ca_default		# Certificate field options
 | 
			
		||||
 | 
			
		||||
default_days	= 365			# how long to certify for
 | 
			
		||||
default_crl_days= 30			# how long before next CRL
 | 
			
		||||
default_md	= default		# use public key default MD
 | 
			
		||||
default_md	= sha1			# which md to use.
 | 
			
		||||
preserve	= no			# keep passed DN ordering
 | 
			
		||||
 | 
			
		||||
# A few difference way of specifying how similar the request should look
 | 
			
		||||
@@ -103,11 +98,11 @@ emailAddress		= optional
 | 
			
		||||
 | 
			
		||||
####################################################################
 | 
			
		||||
[ req ]
 | 
			
		||||
default_bits		= 2048
 | 
			
		||||
default_bits		= 1024
 | 
			
		||||
default_keyfile 	= privkey.pem
 | 
			
		||||
distinguished_name	= req_distinguished_name
 | 
			
		||||
attributes		= req_attributes
 | 
			
		||||
x509_extensions	= v3_ca	# The extensions to add to the self signed cert
 | 
			
		||||
x509_extensions	= v3_ca	# The extentions to add to the self signed cert
 | 
			
		||||
 | 
			
		||||
# Passwords for private keys if not present they will be prompted for
 | 
			
		||||
# input_password = secret
 | 
			
		||||
@@ -115,12 +110,13 @@ x509_extensions	= v3_ca	# The extensions to add to the self signed cert
 | 
			
		||||
 | 
			
		||||
# This sets a mask for permitted string types. There are several options. 
 | 
			
		||||
# default: PrintableString, T61String, BMPString.
 | 
			
		||||
# pkix	 : PrintableString, BMPString (PKIX recommendation before 2004)
 | 
			
		||||
# utf8only: only UTF8Strings (PKIX recommendation after 2004).
 | 
			
		||||
# pkix	 : PrintableString, BMPString.
 | 
			
		||||
# utf8only: only UTF8Strings.
 | 
			
		||||
# nombstr : PrintableString, T61String (no BMPStrings or UTF8Strings).
 | 
			
		||||
# MASK:XXXX a literal mask value.
 | 
			
		||||
# WARNING: ancient versions of Netscape crash on BMPStrings or UTF8Strings.
 | 
			
		||||
string_mask = utf8only
 | 
			
		||||
# WARNING: current versions of Netscape crash on BMPStrings or UTF8Strings
 | 
			
		||||
# so use this option with caution!
 | 
			
		||||
string_mask = nombstr
 | 
			
		||||
 | 
			
		||||
# req_extensions = v3_req # The extensions to add to a certificate request
 | 
			
		||||
 | 
			
		||||
@@ -211,9 +207,6 @@ authorityKeyIdentifier=keyid,issuer
 | 
			
		||||
#nsCaPolicyUrl
 | 
			
		||||
#nsSslServerName
 | 
			
		||||
 | 
			
		||||
# This is required for TSA certificates.
 | 
			
		||||
# extendedKeyUsage = critical,timeStamping
 | 
			
		||||
 | 
			
		||||
[ v3_req ]
 | 
			
		||||
 | 
			
		||||
# Extensions to add to a certificate request
 | 
			
		||||
@@ -231,7 +224,7 @@ keyUsage = nonRepudiation, digitalSignature, keyEncipherment
 | 
			
		||||
 | 
			
		||||
subjectKeyIdentifier=hash
 | 
			
		||||
 | 
			
		||||
authorityKeyIdentifier=keyid:always,issuer
 | 
			
		||||
authorityKeyIdentifier=keyid:always,issuer:always
 | 
			
		||||
 | 
			
		||||
# This is what PKIX recommends but some broken software chokes on critical
 | 
			
		||||
# extensions.
 | 
			
		||||
@@ -264,7 +257,7 @@ basicConstraints = CA:true
 | 
			
		||||
# Only issuerAltName and authorityKeyIdentifier make any sense in a CRL.
 | 
			
		||||
 | 
			
		||||
# issuerAltName=issuer:copy
 | 
			
		||||
authorityKeyIdentifier=keyid:always
 | 
			
		||||
authorityKeyIdentifier=keyid:always,issuer:always
 | 
			
		||||
 | 
			
		||||
[ proxy_cert_ext ]
 | 
			
		||||
# These extensions should be added when creating a proxy certificate
 | 
			
		||||
@@ -297,7 +290,7 @@ nsComment			= "OpenSSL Generated Certificate"
 | 
			
		||||
 | 
			
		||||
# PKIX recommendations harmless if included in all certificates.
 | 
			
		||||
subjectKeyIdentifier=hash
 | 
			
		||||
authorityKeyIdentifier=keyid,issuer
 | 
			
		||||
authorityKeyIdentifier=keyid,issuer:always
 | 
			
		||||
 | 
			
		||||
# This stuff is for subjectAltName and issuerAltname.
 | 
			
		||||
# Import the email address.
 | 
			
		||||
@@ -318,33 +311,3 @@ authorityKeyIdentifier=keyid,issuer
 | 
			
		||||
 | 
			
		||||
# This really needs to be in place for it to be a proxy certificate.
 | 
			
		||||
proxyCertInfo=critical,language:id-ppl-anyLanguage,pathlen:3,policy:foo
 | 
			
		||||
 | 
			
		||||
####################################################################
 | 
			
		||||
[ tsa ]
 | 
			
		||||
 | 
			
		||||
default_tsa = tsa_config1	# the default TSA section
 | 
			
		||||
 | 
			
		||||
[ tsa_config1 ]
 | 
			
		||||
 | 
			
		||||
# These are used by the TSA reply generation only.
 | 
			
		||||
dir		= ./demoCA		# TSA root directory
 | 
			
		||||
serial		= $dir/tsaserial	# The current serial number (mandatory)
 | 
			
		||||
crypto_device	= builtin		# OpenSSL engine to use for signing
 | 
			
		||||
signer_cert	= $dir/tsacert.pem 	# The TSA signing certificate
 | 
			
		||||
					# (optional)
 | 
			
		||||
certs		= $dir/cacert.pem	# Certificate chain to include in reply
 | 
			
		||||
					# (optional)
 | 
			
		||||
signer_key	= $dir/private/tsakey.pem # The TSA private key (optional)
 | 
			
		||||
 | 
			
		||||
default_policy	= tsa_policy1		# Policy if request did not specify it
 | 
			
		||||
					# (optional)
 | 
			
		||||
other_policies	= tsa_policy2, tsa_policy3	# acceptable policies (optional)
 | 
			
		||||
digests		= md5, sha1		# Acceptable message digests (mandatory)
 | 
			
		||||
accuracy	= secs:1, millisecs:500, microsecs:100	# (optional)
 | 
			
		||||
clock_precision_digits  = 0	# number of digits after dot. (optional)
 | 
			
		||||
ordering		= yes	# Is ordering defined for timestamps?
 | 
			
		||||
				# (optional, default: no)
 | 
			
		||||
tsa_name		= yes	# Must the TSA name be included in the reply?
 | 
			
		||||
				# (optional, default: no)
 | 
			
		||||
ess_cert_id_chain	= no	# Must the ESS cert id chain be included?
 | 
			
		||||
				# (optional, default: no)
 | 
			
		||||
 
 | 
			
		||||
@@ -69,6 +69,12 @@
 | 
			
		||||
# include <openssl/pem.h>
 | 
			
		||||
# include <openssl/pkcs12.h>
 | 
			
		||||
 | 
			
		||||
# ifdef OPENSSL_SYS_NETWARE
 | 
			
		||||
/* Rename these functions to avoid name clashes on NetWare OS */
 | 
			
		||||
#  define uni2asc OPENSSL_uni2asc
 | 
			
		||||
#  define asc2uni OPENSSL_asc2uni
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# define PROG pkcs12_main
 | 
			
		||||
 | 
			
		||||
const EVP_CIPHER *enc;
 | 
			
		||||
@@ -92,7 +98,6 @@ int print_attribs(BIO *out, STACK_OF(X509_ATTRIBUTE) *attrlst,
 | 
			
		||||
void hex_prin(BIO *out, unsigned char *buf, int len);
 | 
			
		||||
int alg_print(BIO *x, X509_ALGOR *alg);
 | 
			
		||||
int cert_load(BIO *in, STACK_OF(X509) *sk);
 | 
			
		||||
static int set_pbe(BIO *err, int *ppbe, const char *str);
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
@@ -116,17 +121,16 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    int maciter = PKCS12_DEFAULT_ITER;
 | 
			
		||||
    int twopass = 0;
 | 
			
		||||
    int keytype = 0;
 | 
			
		||||
    int cert_pbe = NID_pbe_WithSHA1And40BitRC2_CBC;
 | 
			
		||||
    int cert_pbe;
 | 
			
		||||
    int key_pbe = NID_pbe_WithSHA1And3_Key_TripleDES_CBC;
 | 
			
		||||
    int ret = 1;
 | 
			
		||||
    int macver = 1;
 | 
			
		||||
    int noprompt = 0;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *canames = NULL;
 | 
			
		||||
    STACK *canames = NULL;
 | 
			
		||||
    char *cpass = NULL, *mpass = NULL;
 | 
			
		||||
    char *passargin = NULL, *passargout = NULL, *passarg = NULL;
 | 
			
		||||
    char *passin = NULL, *passout = NULL;
 | 
			
		||||
    char *inrand = NULL;
 | 
			
		||||
    char *macalg = NULL;
 | 
			
		||||
    char *CApath = NULL, *CAfile = NULL;
 | 
			
		||||
# ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
@@ -134,6 +138,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
# ifdef OPENSSL_FIPS
 | 
			
		||||
    if (FIPS_mode())
 | 
			
		||||
        cert_pbe = NID_pbe_WithSHA1And3_Key_TripleDES_CBC;
 | 
			
		||||
    else
 | 
			
		||||
# endif
 | 
			
		||||
        cert_pbe = NID_pbe_WithSHA1And40BitRC2_CBC;
 | 
			
		||||
 | 
			
		||||
    enc = EVP_des_ede3_cbc();
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        bio_err = BIO_new_fp(stderr, BIO_NOCLOSE);
 | 
			
		||||
@@ -207,19 +218,35 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                maciter = 1;
 | 
			
		||||
            else if (!strcmp(*args, "-nomac"))
 | 
			
		||||
                maciter = -1;
 | 
			
		||||
            else if (!strcmp(*args, "-macalg"))
 | 
			
		||||
                if (args[1]) {
 | 
			
		||||
                    args++;
 | 
			
		||||
                    macalg = *args;
 | 
			
		||||
                } else
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
            else if (!strcmp(*args, "-nodes"))
 | 
			
		||||
                enc = NULL;
 | 
			
		||||
            else if (!strcmp(*args, "-certpbe")) {
 | 
			
		||||
                if (!set_pbe(bio_err, &cert_pbe, *++args))
 | 
			
		||||
                if (args[1]) {
 | 
			
		||||
                    args++;
 | 
			
		||||
                    if (!strcmp(*args, "NONE"))
 | 
			
		||||
                        cert_pbe = -1;
 | 
			
		||||
                    else
 | 
			
		||||
                        cert_pbe = OBJ_txt2nid(*args);
 | 
			
		||||
                    if (cert_pbe == NID_undef) {
 | 
			
		||||
                        BIO_printf(bio_err,
 | 
			
		||||
                                   "Unknown PBE algorithm %s\n", *args);
 | 
			
		||||
                        badarg = 1;
 | 
			
		||||
                    }
 | 
			
		||||
                } else
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
            } else if (!strcmp(*args, "-keypbe")) {
 | 
			
		||||
                if (!set_pbe(bio_err, &key_pbe, *++args))
 | 
			
		||||
                if (args[1]) {
 | 
			
		||||
                    args++;
 | 
			
		||||
                    if (!strcmp(*args, "NONE"))
 | 
			
		||||
                        key_pbe = -1;
 | 
			
		||||
                    else
 | 
			
		||||
                        key_pbe = OBJ_txt2nid(*args);
 | 
			
		||||
                    if (key_pbe == NID_undef) {
 | 
			
		||||
                        BIO_printf(bio_err,
 | 
			
		||||
                                   "Unknown PBE algorithm %s\n", *args);
 | 
			
		||||
                        badarg = 1;
 | 
			
		||||
                    }
 | 
			
		||||
                } else
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
            } else if (!strcmp(*args, "-rand")) {
 | 
			
		||||
                if (args[1]) {
 | 
			
		||||
@@ -257,8 +284,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                if (args[1]) {
 | 
			
		||||
                    args++;
 | 
			
		||||
                    if (!canames)
 | 
			
		||||
                        canames = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
                    sk_OPENSSL_STRING_push(canames, *args);
 | 
			
		||||
                        canames = sk_new_null();
 | 
			
		||||
                    sk_push(canames, *args);
 | 
			
		||||
                } else
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
            } else if (!strcmp(*args, "-in")) {
 | 
			
		||||
@@ -365,9 +392,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
# endif
 | 
			
		||||
        BIO_printf(bio_err, "-nodes        don't encrypt private keys\n");
 | 
			
		||||
        BIO_printf(bio_err, "-noiter       don't use encryption iteration\n");
 | 
			
		||||
        BIO_printf(bio_err, "-nomaciter    don't use MAC iteration\n");
 | 
			
		||||
        BIO_printf(bio_err, "-maciter      use MAC iteration\n");
 | 
			
		||||
        BIO_printf(bio_err, "-nomac        don't generate MAC\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-twopass      separate MAC, encryption passwords\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
@@ -376,8 +401,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-certpbe alg  specify certificate PBE algorithm (default RC2-40)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-keypbe alg   specify private key PBE algorithm (default 3DES)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-macalg alg   digest algorithm used in MAC (default SHA1)\n");
 | 
			
		||||
        BIO_printf(bio_err, "-keyex        set MS key exchange type\n");
 | 
			
		||||
        BIO_printf(bio_err, "-keysig       set MS key signature type\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
@@ -490,7 +513,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        EVP_PKEY *key = NULL;
 | 
			
		||||
        X509 *ucert = NULL, *x = NULL;
 | 
			
		||||
        STACK_OF(X509) *certs = NULL;
 | 
			
		||||
        const EVP_MD *macmd = NULL;
 | 
			
		||||
        unsigned char *catmp = NULL;
 | 
			
		||||
        int i;
 | 
			
		||||
 | 
			
		||||
@@ -606,8 +628,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
        /* Add any CA names */
 | 
			
		||||
 | 
			
		||||
        for (i = 0; i < sk_OPENSSL_STRING_num(canames); i++) {
 | 
			
		||||
            catmp = (unsigned char *)sk_OPENSSL_STRING_value(canames, i);
 | 
			
		||||
        for (i = 0; i < sk_num(canames); i++) {
 | 
			
		||||
            catmp = (unsigned char *)sk_value(canames, i);
 | 
			
		||||
            X509_alias_set1(sk_X509_value(certs, i), catmp, -1);
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
@@ -646,15 +668,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            goto export_end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (macalg) {
 | 
			
		||||
            macmd = EVP_get_digestbyname(macalg);
 | 
			
		||||
            if (!macmd) {
 | 
			
		||||
                BIO_printf(bio_err, "Unknown digest algorithm %s\n", macalg);
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (maciter != -1)
 | 
			
		||||
            PKCS12_set_mac(p12, mpass, -1, NULL, 0, maciter, macmd);
 | 
			
		||||
            PKCS12_set_mac(p12, mpass, -1, NULL, 0, maciter, NULL);
 | 
			
		||||
 | 
			
		||||
# ifdef CRYPTO_MDEBUG
 | 
			
		||||
        CRYPTO_pop_info();
 | 
			
		||||
@@ -751,7 +766,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    if (canames)
 | 
			
		||||
        sk_OPENSSL_STRING_free(canames);
 | 
			
		||||
        sk_free(canames);
 | 
			
		||||
    if (passin)
 | 
			
		||||
        OPENSSL_free(passin);
 | 
			
		||||
    if (passout)
 | 
			
		||||
@@ -1007,7 +1022,7 @@ int print_attribs(BIO *out, STACK_OF(X509_ATTRIBUTE) *attrlst,
 | 
			
		||||
            av = sk_ASN1_TYPE_value(attr->value.set, 0);
 | 
			
		||||
            switch (av->type) {
 | 
			
		||||
            case V_ASN1_BMPSTRING:
 | 
			
		||||
                value = OPENSSL_uni2asc(av->value.bmpstring->data,
 | 
			
		||||
                value = uni2asc(av->value.bmpstring->data,
 | 
			
		||||
                                av->value.bmpstring->length);
 | 
			
		||||
                BIO_printf(out, "%s\n", value);
 | 
			
		||||
                OPENSSL_free(value);
 | 
			
		||||
@@ -1042,20 +1057,4 @@ void hex_prin(BIO *out, unsigned char *buf, int len)
 | 
			
		||||
        BIO_printf(out, "%02X ", buf[i]);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int set_pbe(BIO *err, int *ppbe, const char *str)
 | 
			
		||||
{
 | 
			
		||||
    if (!str)
 | 
			
		||||
        return 0;
 | 
			
		||||
    if (!strcmp(str, "NONE")) {
 | 
			
		||||
        *ppbe = -1;
 | 
			
		||||
        return 1;
 | 
			
		||||
    }
 | 
			
		||||
    *ppbe = OBJ_txt2nid(str);
 | 
			
		||||
    if (*ppbe == NID_undef) {
 | 
			
		||||
        BIO_printf(bio_err, "Unknown PBE algorithm %s\n", str);
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
@@ -88,7 +88,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    BIO *in = NULL, *out = NULL;
 | 
			
		||||
    int informat, outformat;
 | 
			
		||||
    char *infile, *outfile, *prog;
 | 
			
		||||
    int print_certs = 0, text = 0, noout = 0, p7_print = 0;
 | 
			
		||||
    int print_certs = 0, text = 0, noout = 0;
 | 
			
		||||
    int ret = 1;
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
@@ -132,8 +132,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            noout = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-text") == 0)
 | 
			
		||||
            text = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-print") == 0)
 | 
			
		||||
            p7_print = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-print_certs") == 0)
 | 
			
		||||
            print_certs = 1;
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
@@ -225,9 +223,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (p7_print)
 | 
			
		||||
        PKCS7_print_ctx(out, p7, 0, NULL);
 | 
			
		||||
 | 
			
		||||
    if (print_certs) {
 | 
			
		||||
        STACK_OF(X509) *certs = NULL;
 | 
			
		||||
        STACK_OF(X509_CRL) *crls = NULL;
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										118
									
								
								apps/pkcs8.c
									
									
									
									
									
								
							
							
						
						
									
										118
									
								
								apps/pkcs8.c
									
									
									
									
									
								
							@@ -57,7 +57,6 @@
 | 
			
		||||
 *
 | 
			
		||||
 */
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <stdlib.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/pem.h>
 | 
			
		||||
@@ -82,12 +81,11 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    int informat, outformat;
 | 
			
		||||
    int p8_broken = PKCS8_OK;
 | 
			
		||||
    int nocrypt = 0;
 | 
			
		||||
    X509_SIG *p8 = NULL;
 | 
			
		||||
    PKCS8_PRIV_KEY_INFO *p8inf = NULL;
 | 
			
		||||
    X509_SIG *p8;
 | 
			
		||||
    PKCS8_PRIV_KEY_INFO *p8inf;
 | 
			
		||||
    EVP_PKEY *pkey = NULL;
 | 
			
		||||
    char pass[50], *passin = NULL, *passout = NULL, *p8pass = NULL;
 | 
			
		||||
    int badarg = 0;
 | 
			
		||||
    int ret = 1;
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
#endif
 | 
			
		||||
@@ -125,16 +123,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                }
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-v2prf")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                pbe_nid = OBJ_txt2nid(*args);
 | 
			
		||||
                if (!EVP_PBE_find(EVP_PBE_TYPE_PRF, pbe_nid, NULL, NULL, 0)) {
 | 
			
		||||
                    BIO_printf(bio_err, "Unknown PRF algorithm %s\n", *args);
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
                }
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-inform")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
@@ -151,14 +139,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            topk8 = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-noiter"))
 | 
			
		||||
            iter = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-iter")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                iter = atoi(*(++args));
 | 
			
		||||
                if (iter <= 0)
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-nocrypt"))
 | 
			
		||||
        else if (!strcmp(*args, "-nocrypt"))
 | 
			
		||||
            nocrypt = 1;
 | 
			
		||||
        else if (!strcmp(*args, "-nooct"))
 | 
			
		||||
            p8_broken = PKCS8_NO_OCTET;
 | 
			
		||||
@@ -167,22 +148,19 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        else if (!strcmp(*args, "-embed"))
 | 
			
		||||
            p8_broken = PKCS8_EMBEDDED_PARAM;
 | 
			
		||||
        else if (!strcmp(*args, "-passin")) {
 | 
			
		||||
            if (args[1])
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            passargin = *(++args);
 | 
			
		||||
            else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-passout")) {
 | 
			
		||||
            if (args[1])
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            passargout = *(++args);
 | 
			
		||||
            else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        else if (strcmp(*args, "-engine") == 0) {
 | 
			
		||||
            if (args[1])
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            engine = *(++args);
 | 
			
		||||
            else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
        else if (!strcmp(*args, "-in")) {
 | 
			
		||||
@@ -203,6 +181,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (badarg) {
 | 
			
		||||
 bad:
 | 
			
		||||
        BIO_printf(bio_err, "Usage pkcs8 [options]\n");
 | 
			
		||||
        BIO_printf(bio_err, "where options are\n");
 | 
			
		||||
        BIO_printf(bio_err, "-in file        input file\n");
 | 
			
		||||
@@ -220,7 +199,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                   "-embed          use (nonstandard) embedded DSA parameters format\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-nsdb           use (nonstandard) DSA Netscape DB format\n");
 | 
			
		||||
        BIO_printf(bio_err, "-iter count     use count as iteration count\n");
 | 
			
		||||
        BIO_printf(bio_err, "-noiter         use 1 as iteration count\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-nocrypt        use or expect unencrypted private key\n");
 | 
			
		||||
@@ -232,7 +210,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   " -engine e       use engine e, possibly a hardware device.\n");
 | 
			
		||||
#endif
 | 
			
		||||
        goto end;
 | 
			
		||||
        return 1;
 | 
			
		||||
    }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    e = setup_engine(bio_err, engine, 0);
 | 
			
		||||
@@ -240,7 +218,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
 | 
			
		||||
    if (!app_passwd(bio_err, passargin, passargout, &passin, &passout)) {
 | 
			
		||||
        BIO_printf(bio_err, "Error getting passwords\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
        return 1;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if ((pbe_nid == -1) && !cipher)
 | 
			
		||||
@@ -249,7 +227,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (infile) {
 | 
			
		||||
        if (!(in = BIO_new_file(infile, "rb"))) {
 | 
			
		||||
            BIO_printf(bio_err, "Can't open input file %s\n", infile);
 | 
			
		||||
            goto end;
 | 
			
		||||
            return (1);
 | 
			
		||||
        }
 | 
			
		||||
    } else
 | 
			
		||||
        in = BIO_new_fp(stdin, BIO_NOCLOSE);
 | 
			
		||||
@@ -257,7 +235,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (outfile) {
 | 
			
		||||
        if (!(out = BIO_new_file(outfile, "wb"))) {
 | 
			
		||||
            BIO_printf(bio_err, "Can't open output file %s\n", outfile);
 | 
			
		||||
            goto end;
 | 
			
		||||
            return (1);
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        out = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
@@ -269,13 +247,18 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
    if (topk8) {
 | 
			
		||||
        BIO_free(in);           /* Not needed in this section */
 | 
			
		||||
        pkey = load_key(bio_err, infile, informat, 1, passin, e, "key");
 | 
			
		||||
        if (!pkey)
 | 
			
		||||
            goto end;
 | 
			
		||||
        if (!pkey) {
 | 
			
		||||
            BIO_free_all(out);
 | 
			
		||||
            return 1;
 | 
			
		||||
        }
 | 
			
		||||
        if (!(p8inf = EVP_PKEY2PKCS8_broken(pkey, p8_broken))) {
 | 
			
		||||
            BIO_printf(bio_err, "Error converting key\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
            EVP_PKEY_free(pkey);
 | 
			
		||||
            BIO_free_all(out);
 | 
			
		||||
            return 1;
 | 
			
		||||
        }
 | 
			
		||||
        if (nocrypt) {
 | 
			
		||||
            if (outformat == FORMAT_PEM)
 | 
			
		||||
@@ -284,7 +267,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                i2d_PKCS8_PRIV_KEY_INFO_bio(out, p8inf);
 | 
			
		||||
            else {
 | 
			
		||||
                BIO_printf(bio_err, "Bad format specified for key\n");
 | 
			
		||||
                goto end;
 | 
			
		||||
                PKCS8_PRIV_KEY_INFO_free(p8inf);
 | 
			
		||||
                EVP_PKEY_free(pkey);
 | 
			
		||||
                BIO_free_all(out);
 | 
			
		||||
                return (1);
 | 
			
		||||
            }
 | 
			
		||||
        } else {
 | 
			
		||||
            if (passout)
 | 
			
		||||
@@ -292,8 +278,12 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            else {
 | 
			
		||||
                p8pass = pass;
 | 
			
		||||
                if (EVP_read_pw_string
 | 
			
		||||
                    (pass, sizeof pass, "Enter Encryption Password:", 1))
 | 
			
		||||
                    goto end;
 | 
			
		||||
                    (pass, sizeof pass, "Enter Encryption Password:", 1)) {
 | 
			
		||||
                    PKCS8_PRIV_KEY_INFO_free(p8inf);
 | 
			
		||||
                    EVP_PKEY_free(pkey);
 | 
			
		||||
                    BIO_free_all(out);
 | 
			
		||||
                    return (1);
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
            app_RAND_load_file(NULL, bio_err, 0);
 | 
			
		||||
            if (!(p8 = PKCS8_encrypt(pbe_nid, cipher,
 | 
			
		||||
@@ -301,7 +291,10 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                                     NULL, 0, iter, p8inf))) {
 | 
			
		||||
                BIO_printf(bio_err, "Error encrypting key\n");
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
                goto end;
 | 
			
		||||
                PKCS8_PRIV_KEY_INFO_free(p8inf);
 | 
			
		||||
                EVP_PKEY_free(pkey);
 | 
			
		||||
                BIO_free_all(out);
 | 
			
		||||
                return (1);
 | 
			
		||||
            }
 | 
			
		||||
            app_RAND_write_file(NULL, bio_err);
 | 
			
		||||
            if (outformat == FORMAT_PEM)
 | 
			
		||||
@@ -310,12 +303,22 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                i2d_PKCS8_bio(out, p8);
 | 
			
		||||
            else {
 | 
			
		||||
                BIO_printf(bio_err, "Bad format specified for key\n");
 | 
			
		||||
                goto end;
 | 
			
		||||
                PKCS8_PRIV_KEY_INFO_free(p8inf);
 | 
			
		||||
                EVP_PKEY_free(pkey);
 | 
			
		||||
                BIO_free_all(out);
 | 
			
		||||
                return (1);
 | 
			
		||||
            }
 | 
			
		||||
            X509_SIG_free(p8);
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        ret = 0;
 | 
			
		||||
        goto end;
 | 
			
		||||
        PKCS8_PRIV_KEY_INFO_free(p8inf);
 | 
			
		||||
        EVP_PKEY_free(pkey);
 | 
			
		||||
        BIO_free_all(out);
 | 
			
		||||
        if (passin)
 | 
			
		||||
            OPENSSL_free(passin);
 | 
			
		||||
        if (passout)
 | 
			
		||||
            OPENSSL_free(passout);
 | 
			
		||||
        return (0);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (nocrypt) {
 | 
			
		||||
@@ -325,7 +328,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            p8inf = d2i_PKCS8_PRIV_KEY_INFO_bio(in, NULL);
 | 
			
		||||
        else {
 | 
			
		||||
            BIO_printf(bio_err, "Bad format specified for key\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
            return (1);
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        if (informat == FORMAT_PEM)
 | 
			
		||||
@@ -334,13 +337,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            p8 = d2i_PKCS8_bio(in, NULL);
 | 
			
		||||
        else {
 | 
			
		||||
            BIO_printf(bio_err, "Bad format specified for key\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
            return (1);
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (!p8) {
 | 
			
		||||
            BIO_printf(bio_err, "Error reading key\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
            return (1);
 | 
			
		||||
        }
 | 
			
		||||
        if (passin)
 | 
			
		||||
            p8pass = passin;
 | 
			
		||||
@@ -349,18 +352,19 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            EVP_read_pw_string(pass, sizeof pass, "Enter Password:", 0);
 | 
			
		||||
        }
 | 
			
		||||
        p8inf = PKCS8_decrypt(p8, p8pass, strlen(p8pass));
 | 
			
		||||
        X509_SIG_free(p8);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!p8inf) {
 | 
			
		||||
        BIO_printf(bio_err, "Error decrypting key\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
        return (1);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!(pkey = EVP_PKCS82PKEY(p8inf))) {
 | 
			
		||||
        BIO_printf(bio_err, "Error converting key\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
        return (1);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (p8inf->broken) {
 | 
			
		||||
@@ -378,29 +382,23 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            BIO_printf(bio_err, "DSA public key include in PrivateKey\n");
 | 
			
		||||
            break;
 | 
			
		||||
 | 
			
		||||
        case PKCS8_NEG_PRIVKEY:
 | 
			
		||||
            BIO_printf(bio_err, "DSA private key value is negative\n");
 | 
			
		||||
            break;
 | 
			
		||||
 | 
			
		||||
        default:
 | 
			
		||||
            BIO_printf(bio_err, "Unknown broken type\n");
 | 
			
		||||
            break;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    PKCS8_PRIV_KEY_INFO_free(p8inf);
 | 
			
		||||
    if (outformat == FORMAT_PEM)
 | 
			
		||||
        PEM_write_bio_PrivateKey(out, pkey, NULL, NULL, 0, NULL, passout);
 | 
			
		||||
    else if (outformat == FORMAT_ASN1)
 | 
			
		||||
        i2d_PrivateKey_bio(out, pkey);
 | 
			
		||||
    else {
 | 
			
		||||
        BIO_printf(bio_err, "Bad format specified for key\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
        return (1);
 | 
			
		||||
    }
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
    X509_SIG_free(p8);
 | 
			
		||||
    PKCS8_PRIV_KEY_INFO_free(p8inf);
 | 
			
		||||
    EVP_PKEY_free(pkey);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
@@ -409,5 +407,5 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (passout)
 | 
			
		||||
        OPENSSL_free(passout);
 | 
			
		||||
 | 
			
		||||
    return ret;
 | 
			
		||||
    return (0);
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										251
									
								
								apps/pkey.c
									
									
									
									
									
								
							
							
						
						
									
										251
									
								
								apps/pkey.c
									
									
									
									
									
								
							@@ -1,251 +0,0 @@
 | 
			
		||||
/* apps/pkey.c */
 | 
			
		||||
/*
 | 
			
		||||
 * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL project
 | 
			
		||||
 * 2006
 | 
			
		||||
 */
 | 
			
		||||
/* ====================================================================
 | 
			
		||||
 * Copyright (c) 2006 The OpenSSL Project.  All rights reserved.
 | 
			
		||||
 *
 | 
			
		||||
 * Redistribution and use in source and binary forms, with or without
 | 
			
		||||
 * modification, are permitted provided that the following conditions
 | 
			
		||||
 * are met:
 | 
			
		||||
 *
 | 
			
		||||
 * 1. Redistributions of source code must retain the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer.
 | 
			
		||||
 *
 | 
			
		||||
 * 2. Redistributions in binary form must reproduce the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer in
 | 
			
		||||
 *    the documentation and/or other materials provided with the
 | 
			
		||||
 *    distribution.
 | 
			
		||||
 *
 | 
			
		||||
 * 3. All advertising materials mentioning features or use of this
 | 
			
		||||
 *    software must display the following acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
 | 
			
		||||
 *    endorse or promote products derived from this software without
 | 
			
		||||
 *    prior written permission. For written permission, please contact
 | 
			
		||||
 *    licensing@OpenSSL.org.
 | 
			
		||||
 *
 | 
			
		||||
 * 5. Products derived from this software may not be called "OpenSSL"
 | 
			
		||||
 *    nor may "OpenSSL" appear in their names without prior written
 | 
			
		||||
 *    permission of the OpenSSL Project.
 | 
			
		||||
 *
 | 
			
		||||
 * 6. Redistributions of any form whatsoever must retain the following
 | 
			
		||||
 *    acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
 | 
			
		||||
 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 | 
			
		||||
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
 | 
			
		||||
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
 | 
			
		||||
 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
 | 
			
		||||
 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
 | 
			
		||||
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
 | 
			
		||||
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 | 
			
		||||
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
 | 
			
		||||
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
 | 
			
		||||
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
 | 
			
		||||
 * OF THE POSSIBILITY OF SUCH DAMAGE.
 | 
			
		||||
 * ====================================================================
 | 
			
		||||
 *
 | 
			
		||||
 * This product includes cryptographic software written by Eric Young
 | 
			
		||||
 * (eay@cryptsoft.com).  This product includes software written by Tim
 | 
			
		||||
 * Hudson (tjh@cryptsoft.com).
 | 
			
		||||
 *
 | 
			
		||||
 */
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/pem.h>
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#include <openssl/evp.h>
 | 
			
		||||
 | 
			
		||||
#define PROG pkey_main
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    ENGINE *e = NULL;
 | 
			
		||||
    char **args, *infile = NULL, *outfile = NULL;
 | 
			
		||||
    char *passargin = NULL, *passargout = NULL;
 | 
			
		||||
    BIO *in = NULL, *out = NULL;
 | 
			
		||||
    const EVP_CIPHER *cipher = NULL;
 | 
			
		||||
    int informat, outformat;
 | 
			
		||||
    int pubin = 0, pubout = 0, pubtext = 0, text = 0, noout = 0;
 | 
			
		||||
    EVP_PKEY *pkey = NULL;
 | 
			
		||||
    char *passin = NULL, *passout = NULL;
 | 
			
		||||
    int badarg = 0;
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
#endif
 | 
			
		||||
    int ret = 1;
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        bio_err = BIO_new_fp(stderr, BIO_NOCLOSE);
 | 
			
		||||
 | 
			
		||||
    if (!load_config(bio_err, NULL))
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    informat = FORMAT_PEM;
 | 
			
		||||
    outformat = FORMAT_PEM;
 | 
			
		||||
 | 
			
		||||
    ERR_load_crypto_strings();
 | 
			
		||||
    OpenSSL_add_all_algorithms();
 | 
			
		||||
    args = argv + 1;
 | 
			
		||||
    while (!badarg && *args && *args[0] == '-') {
 | 
			
		||||
        if (!strcmp(*args, "-inform")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                informat = str2fmt(*args);
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-outform")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                outformat = str2fmt(*args);
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-passin")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            passargin = *(++args);
 | 
			
		||||
        } else if (!strcmp(*args, "-passout")) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            passargout = *(++args);
 | 
			
		||||
        }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        else if (strcmp(*args, "-engine") == 0) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            engine = *(++args);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
        else if (!strcmp(*args, "-in")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                infile = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-out")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                outfile = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (strcmp(*args, "-pubin") == 0) {
 | 
			
		||||
            pubin = 1;
 | 
			
		||||
            pubout = 1;
 | 
			
		||||
            pubtext = 1;
 | 
			
		||||
        } else if (strcmp(*args, "-pubout") == 0)
 | 
			
		||||
            pubout = 1;
 | 
			
		||||
        else if (strcmp(*args, "-text_pub") == 0) {
 | 
			
		||||
            pubtext = 1;
 | 
			
		||||
            text = 1;
 | 
			
		||||
        } else if (strcmp(*args, "-text") == 0)
 | 
			
		||||
            text = 1;
 | 
			
		||||
        else if (strcmp(*args, "-noout") == 0)
 | 
			
		||||
            noout = 1;
 | 
			
		||||
        else {
 | 
			
		||||
            cipher = EVP_get_cipherbyname(*args + 1);
 | 
			
		||||
            if (!cipher) {
 | 
			
		||||
                BIO_printf(bio_err, "Unknown cipher %s\n", *args + 1);
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
        args++;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (badarg) {
 | 
			
		||||
 bad:
 | 
			
		||||
        BIO_printf(bio_err, "Usage pkey [options]\n");
 | 
			
		||||
        BIO_printf(bio_err, "where options are\n");
 | 
			
		||||
        BIO_printf(bio_err, "-in file        input file\n");
 | 
			
		||||
        BIO_printf(bio_err, "-inform X       input format (DER or PEM)\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-passin arg     input file pass phrase source\n");
 | 
			
		||||
        BIO_printf(bio_err, "-outform X      output format (DER or PEM)\n");
 | 
			
		||||
        BIO_printf(bio_err, "-out file       output file\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-passout arg    output file pass phrase source\n");
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-engine e       use engine e, possibly a hardware device.\n");
 | 
			
		||||
#endif
 | 
			
		||||
        return 1;
 | 
			
		||||
    }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    e = setup_engine(bio_err, engine, 0);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    if (!app_passwd(bio_err, passargin, passargout, &passin, &passout)) {
 | 
			
		||||
        BIO_printf(bio_err, "Error getting passwords\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (outfile) {
 | 
			
		||||
        if (!(out = BIO_new_file(outfile, "wb"))) {
 | 
			
		||||
            BIO_printf(bio_err, "Can't open output file %s\n", outfile);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        out = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
#ifdef OPENSSL_SYS_VMS
 | 
			
		||||
        {
 | 
			
		||||
            BIO *tmpbio = BIO_new(BIO_f_linebuffer());
 | 
			
		||||
            out = BIO_push(tmpbio, out);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (pubin)
 | 
			
		||||
        pkey = load_pubkey(bio_err, infile, informat, 1,
 | 
			
		||||
                           passin, e, "Public Key");
 | 
			
		||||
    else
 | 
			
		||||
        pkey = load_key(bio_err, infile, informat, 1, passin, e, "key");
 | 
			
		||||
    if (!pkey)
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    if (!noout) {
 | 
			
		||||
        if (outformat == FORMAT_PEM) {
 | 
			
		||||
            if (pubout)
 | 
			
		||||
                PEM_write_bio_PUBKEY(out, pkey);
 | 
			
		||||
            else
 | 
			
		||||
                PEM_write_bio_PrivateKey(out, pkey, cipher,
 | 
			
		||||
                                         NULL, 0, NULL, passout);
 | 
			
		||||
        } else if (outformat == FORMAT_ASN1) {
 | 
			
		||||
            if (pubout)
 | 
			
		||||
                i2d_PUBKEY_bio(out, pkey);
 | 
			
		||||
            else
 | 
			
		||||
                i2d_PrivateKey_bio(out, pkey);
 | 
			
		||||
        } else {
 | 
			
		||||
            BIO_printf(bio_err, "Bad format specified for key\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (text) {
 | 
			
		||||
        if (pubtext)
 | 
			
		||||
            EVP_PKEY_print_public(out, pkey, 0, NULL);
 | 
			
		||||
        else
 | 
			
		||||
            EVP_PKEY_print_private(out, pkey, 0, NULL);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
    EVP_PKEY_free(pkey);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
    if (passin)
 | 
			
		||||
        OPENSSL_free(passin);
 | 
			
		||||
    if (passout)
 | 
			
		||||
        OPENSSL_free(passout);
 | 
			
		||||
 | 
			
		||||
    return ret;
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										185
									
								
								apps/pkeyparam.c
									
									
									
									
									
								
							
							
						
						
									
										185
									
								
								apps/pkeyparam.c
									
									
									
									
									
								
							@@ -1,185 +0,0 @@
 | 
			
		||||
/* apps/pkeyparam.c */
 | 
			
		||||
/*
 | 
			
		||||
 * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL project
 | 
			
		||||
 * 2006
 | 
			
		||||
 */
 | 
			
		||||
/* ====================================================================
 | 
			
		||||
 * Copyright (c) 2006 The OpenSSL Project.  All rights reserved.
 | 
			
		||||
 *
 | 
			
		||||
 * Redistribution and use in source and binary forms, with or without
 | 
			
		||||
 * modification, are permitted provided that the following conditions
 | 
			
		||||
 * are met:
 | 
			
		||||
 *
 | 
			
		||||
 * 1. Redistributions of source code must retain the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer.
 | 
			
		||||
 *
 | 
			
		||||
 * 2. Redistributions in binary form must reproduce the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer in
 | 
			
		||||
 *    the documentation and/or other materials provided with the
 | 
			
		||||
 *    distribution.
 | 
			
		||||
 *
 | 
			
		||||
 * 3. All advertising materials mentioning features or use of this
 | 
			
		||||
 *    software must display the following acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
 | 
			
		||||
 *    endorse or promote products derived from this software without
 | 
			
		||||
 *    prior written permission. For written permission, please contact
 | 
			
		||||
 *    licensing@OpenSSL.org.
 | 
			
		||||
 *
 | 
			
		||||
 * 5. Products derived from this software may not be called "OpenSSL"
 | 
			
		||||
 *    nor may "OpenSSL" appear in their names without prior written
 | 
			
		||||
 *    permission of the OpenSSL Project.
 | 
			
		||||
 *
 | 
			
		||||
 * 6. Redistributions of any form whatsoever must retain the following
 | 
			
		||||
 *    acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
 | 
			
		||||
 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 | 
			
		||||
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
 | 
			
		||||
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
 | 
			
		||||
 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
 | 
			
		||||
 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
 | 
			
		||||
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
 | 
			
		||||
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 | 
			
		||||
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
 | 
			
		||||
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
 | 
			
		||||
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
 | 
			
		||||
 * OF THE POSSIBILITY OF SUCH DAMAGE.
 | 
			
		||||
 * ====================================================================
 | 
			
		||||
 *
 | 
			
		||||
 * This product includes cryptographic software written by Eric Young
 | 
			
		||||
 * (eay@cryptsoft.com).  This product includes software written by Tim
 | 
			
		||||
 * Hudson (tjh@cryptsoft.com).
 | 
			
		||||
 *
 | 
			
		||||
 */
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/pem.h>
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#include <openssl/evp.h>
 | 
			
		||||
 | 
			
		||||
#define PROG pkeyparam_main
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    char **args, *infile = NULL, *outfile = NULL;
 | 
			
		||||
    BIO *in = NULL, *out = NULL;
 | 
			
		||||
    int text = 0, noout = 0;
 | 
			
		||||
    EVP_PKEY *pkey = NULL;
 | 
			
		||||
    int badarg = 0;
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    char *engine = NULL;
 | 
			
		||||
#endif
 | 
			
		||||
    int ret = 1;
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
        bio_err = BIO_new_fp(stderr, BIO_NOCLOSE);
 | 
			
		||||
 | 
			
		||||
    if (!load_config(bio_err, NULL))
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    ERR_load_crypto_strings();
 | 
			
		||||
    OpenSSL_add_all_algorithms();
 | 
			
		||||
    args = argv + 1;
 | 
			
		||||
    while (!badarg && *args && *args[0] == '-') {
 | 
			
		||||
        if (!strcmp(*args, "-in")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                infile = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*args, "-out")) {
 | 
			
		||||
            if (args[1]) {
 | 
			
		||||
                args++;
 | 
			
		||||
                outfile = *args;
 | 
			
		||||
            } else
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        else if (strcmp(*args, "-engine") == 0) {
 | 
			
		||||
            if (!args[1])
 | 
			
		||||
                goto bad;
 | 
			
		||||
            engine = *(++args);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
        else if (strcmp(*args, "-text") == 0)
 | 
			
		||||
            text = 1;
 | 
			
		||||
        else if (strcmp(*args, "-noout") == 0)
 | 
			
		||||
            noout = 1;
 | 
			
		||||
        args++;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (badarg) {
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
 bad:
 | 
			
		||||
#endif
 | 
			
		||||
        BIO_printf(bio_err, "Usage pkeyparam [options]\n");
 | 
			
		||||
        BIO_printf(bio_err, "where options are\n");
 | 
			
		||||
        BIO_printf(bio_err, "-in file        input file\n");
 | 
			
		||||
        BIO_printf(bio_err, "-out file       output file\n");
 | 
			
		||||
        BIO_printf(bio_err, "-text           print parameters as text\n");
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-noout          don't output encoded parameters\n");
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        BIO_printf(bio_err,
 | 
			
		||||
                   "-engine e       use engine e, possibly a hardware device.\n");
 | 
			
		||||
#endif
 | 
			
		||||
        return 1;
 | 
			
		||||
    }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    setup_engine(bio_err, engine, 0);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    if (infile) {
 | 
			
		||||
        if (!(in = BIO_new_file(infile, "r"))) {
 | 
			
		||||
            BIO_printf(bio_err, "Can't open input file %s\n", infile);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else
 | 
			
		||||
        in = BIO_new_fp(stdin, BIO_NOCLOSE);
 | 
			
		||||
 | 
			
		||||
    if (outfile) {
 | 
			
		||||
        if (!(out = BIO_new_file(outfile, "w"))) {
 | 
			
		||||
            BIO_printf(bio_err, "Can't open output file %s\n", outfile);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        out = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
#ifdef OPENSSL_SYS_VMS
 | 
			
		||||
        {
 | 
			
		||||
            BIO *tmpbio = BIO_new(BIO_f_linebuffer());
 | 
			
		||||
            out = BIO_push(tmpbio, out);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    pkey = PEM_read_bio_Parameters(in, NULL);
 | 
			
		||||
    if (!pkey) {
 | 
			
		||||
        BIO_printf(bio_err, "Error reading parameters\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!noout)
 | 
			
		||||
        PEM_write_bio_Parameters(out, pkey);
 | 
			
		||||
 | 
			
		||||
    if (text)
 | 
			
		||||
        EVP_PKEY_print_params(out, pkey, 0, NULL);
 | 
			
		||||
 | 
			
		||||
    ret = 0;
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
    EVP_PKEY_free(pkey);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
 | 
			
		||||
    return ret;
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										523
									
								
								apps/pkeyutl.c
									
									
									
									
									
								
							
							
						
						
									
										523
									
								
								apps/pkeyutl.c
									
									
									
									
									
								
							@@ -1,523 +0,0 @@
 | 
			
		||||
/*
 | 
			
		||||
 * Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL project
 | 
			
		||||
 * 2006.
 | 
			
		||||
 */
 | 
			
		||||
/* ====================================================================
 | 
			
		||||
 * Copyright (c) 2006 The OpenSSL Project.  All rights reserved.
 | 
			
		||||
 *
 | 
			
		||||
 * Redistribution and use in source and binary forms, with or without
 | 
			
		||||
 * modification, are permitted provided that the following conditions
 | 
			
		||||
 * are met:
 | 
			
		||||
 *
 | 
			
		||||
 * 1. Redistributions of source code must retain the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer.
 | 
			
		||||
 *
 | 
			
		||||
 * 2. Redistributions in binary form must reproduce the above copyright
 | 
			
		||||
 *    notice, this list of conditions and the following disclaimer in
 | 
			
		||||
 *    the documentation and/or other materials provided with the
 | 
			
		||||
 *    distribution.
 | 
			
		||||
 *
 | 
			
		||||
 * 3. All advertising materials mentioning features or use of this
 | 
			
		||||
 *    software must display the following acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
 | 
			
		||||
 *    endorse or promote products derived from this software without
 | 
			
		||||
 *    prior written permission. For written permission, please contact
 | 
			
		||||
 *    licensing@OpenSSL.org.
 | 
			
		||||
 *
 | 
			
		||||
 * 5. Products derived from this software may not be called "OpenSSL"
 | 
			
		||||
 *    nor may "OpenSSL" appear in their names without prior written
 | 
			
		||||
 *    permission of the OpenSSL Project.
 | 
			
		||||
 *
 | 
			
		||||
 * 6. Redistributions of any form whatsoever must retain the following
 | 
			
		||||
 *    acknowledgment:
 | 
			
		||||
 *    "This product includes software developed by the OpenSSL Project
 | 
			
		||||
 *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
 | 
			
		||||
 *
 | 
			
		||||
 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
 | 
			
		||||
 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 | 
			
		||||
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
 | 
			
		||||
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
 | 
			
		||||
 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
 | 
			
		||||
 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
 | 
			
		||||
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
 | 
			
		||||
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 | 
			
		||||
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
 | 
			
		||||
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
 | 
			
		||||
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
 | 
			
		||||
 * OF THE POSSIBILITY OF SUCH DAMAGE.
 | 
			
		||||
 * ====================================================================
 | 
			
		||||
 *
 | 
			
		||||
 * This product includes cryptographic software written by Eric Young
 | 
			
		||||
 * (eay@cryptsoft.com).  This product includes software written by Tim
 | 
			
		||||
 * Hudson (tjh@cryptsoft.com).
 | 
			
		||||
 *
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#include <openssl/err.h>
 | 
			
		||||
#include <openssl/pem.h>
 | 
			
		||||
#include <openssl/evp.h>
 | 
			
		||||
 | 
			
		||||
#define KEY_PRIVKEY     1
 | 
			
		||||
#define KEY_PUBKEY      2
 | 
			
		||||
#define KEY_CERT        3
 | 
			
		||||
 | 
			
		||||
static void usage(void);
 | 
			
		||||
 | 
			
		||||
#undef PROG
 | 
			
		||||
 | 
			
		||||
#define PROG pkeyutl_main
 | 
			
		||||
 | 
			
		||||
static EVP_PKEY_CTX *init_ctx(int *pkeysize,
 | 
			
		||||
                              char *keyfile, int keyform, int key_type,
 | 
			
		||||
                              char *passargin, int pkey_op, ENGINE *e);
 | 
			
		||||
 | 
			
		||||
static int setup_peer(BIO *err, EVP_PKEY_CTX *ctx, int peerform,
 | 
			
		||||
                      const char *file);
 | 
			
		||||
 | 
			
		||||
static int do_keyop(EVP_PKEY_CTX *ctx, int pkey_op,
 | 
			
		||||
                    unsigned char *out, size_t *poutlen,
 | 
			
		||||
                    unsigned char *in, size_t inlen);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    BIO *in = NULL, *out = NULL;
 | 
			
		||||
    char *infile = NULL, *outfile = NULL, *sigfile = NULL;
 | 
			
		||||
    ENGINE *e = NULL;
 | 
			
		||||
    int pkey_op = EVP_PKEY_OP_SIGN, key_type = KEY_PRIVKEY;
 | 
			
		||||
    int keyform = FORMAT_PEM, peerform = FORMAT_PEM;
 | 
			
		||||
    char badarg = 0, rev = 0;
 | 
			
		||||
    char hexdump = 0, asn1parse = 0;
 | 
			
		||||
    EVP_PKEY_CTX *ctx = NULL;
 | 
			
		||||
    char *passargin = NULL;
 | 
			
		||||
    int keysize = -1;
 | 
			
		||||
 | 
			
		||||
    unsigned char *buf_in = NULL, *buf_out = NULL, *sig = NULL;
 | 
			
		||||
    size_t buf_outlen;
 | 
			
		||||
    int buf_inlen = 0, siglen = -1;
 | 
			
		||||
 | 
			
		||||
    int ret = 1, rv = -1;
 | 
			
		||||
 | 
			
		||||
    argc--;
 | 
			
		||||
    argv++;
 | 
			
		||||
 | 
			
		||||
    if (!bio_err)
 | 
			
		||||
        bio_err = BIO_new_fp(stderr, BIO_NOCLOSE);
 | 
			
		||||
 | 
			
		||||
    if (!load_config(bio_err, NULL))
 | 
			
		||||
        goto end;
 | 
			
		||||
    ERR_load_crypto_strings();
 | 
			
		||||
    OpenSSL_add_all_algorithms();
 | 
			
		||||
 | 
			
		||||
    while (argc >= 1) {
 | 
			
		||||
        if (!strcmp(*argv, "-in")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else
 | 
			
		||||
                infile = *(++argv);
 | 
			
		||||
        } else if (!strcmp(*argv, "-out")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else
 | 
			
		||||
                outfile = *(++argv);
 | 
			
		||||
        } else if (!strcmp(*argv, "-sigfile")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else
 | 
			
		||||
                sigfile = *(++argv);
 | 
			
		||||
        } else if (!strcmp(*argv, "-inkey")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else {
 | 
			
		||||
                ctx = init_ctx(&keysize,
 | 
			
		||||
                               *(++argv), keyform, key_type,
 | 
			
		||||
                               passargin, pkey_op, e);
 | 
			
		||||
                if (!ctx) {
 | 
			
		||||
                    BIO_puts(bio_err, "Error initializing context\n");
 | 
			
		||||
                    ERR_print_errors(bio_err);
 | 
			
		||||
                    badarg = 1;
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
        } else if (!strcmp(*argv, "-peerkey")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else if (!setup_peer(bio_err, ctx, peerform, *(++argv)))
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
        } else if (!strcmp(*argv, "-passin")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else
 | 
			
		||||
                passargin = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-peerform") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else
 | 
			
		||||
                peerform = str2fmt(*(++argv));
 | 
			
		||||
        } else if (strcmp(*argv, "-keyform") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else
 | 
			
		||||
                keyform = str2fmt(*(++argv));
 | 
			
		||||
        }
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        else if (!strcmp(*argv, "-engine")) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else
 | 
			
		||||
                e = setup_engine(bio_err, *(++argv), 0);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
        else if (!strcmp(*argv, "-pubin"))
 | 
			
		||||
            key_type = KEY_PUBKEY;
 | 
			
		||||
        else if (!strcmp(*argv, "-certin"))
 | 
			
		||||
            key_type = KEY_CERT;
 | 
			
		||||
        else if (!strcmp(*argv, "-asn1parse"))
 | 
			
		||||
            asn1parse = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-hexdump"))
 | 
			
		||||
            hexdump = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-sign"))
 | 
			
		||||
            pkey_op = EVP_PKEY_OP_SIGN;
 | 
			
		||||
        else if (!strcmp(*argv, "-verify"))
 | 
			
		||||
            pkey_op = EVP_PKEY_OP_VERIFY;
 | 
			
		||||
        else if (!strcmp(*argv, "-verifyrecover"))
 | 
			
		||||
            pkey_op = EVP_PKEY_OP_VERIFYRECOVER;
 | 
			
		||||
        else if (!strcmp(*argv, "-rev"))
 | 
			
		||||
            rev = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-encrypt"))
 | 
			
		||||
            pkey_op = EVP_PKEY_OP_ENCRYPT;
 | 
			
		||||
        else if (!strcmp(*argv, "-decrypt"))
 | 
			
		||||
            pkey_op = EVP_PKEY_OP_DECRYPT;
 | 
			
		||||
        else if (!strcmp(*argv, "-derive"))
 | 
			
		||||
            pkey_op = EVP_PKEY_OP_DERIVE;
 | 
			
		||||
        else if (strcmp(*argv, "-pkeyopt") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            else if (!ctx) {
 | 
			
		||||
                BIO_puts(bio_err, "-pkeyopt command before -inkey\n");
 | 
			
		||||
                badarg = 1;
 | 
			
		||||
            } else if (pkey_ctrl_string(ctx, *(++argv)) <= 0) {
 | 
			
		||||
                BIO_puts(bio_err, "parameter setting error\n");
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        } else
 | 
			
		||||
            badarg = 1;
 | 
			
		||||
        if (badarg) {
 | 
			
		||||
            usage();
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        argc--;
 | 
			
		||||
        argv++;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!ctx) {
 | 
			
		||||
        usage();
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (sigfile && (pkey_op != EVP_PKEY_OP_VERIFY)) {
 | 
			
		||||
        BIO_puts(bio_err, "Signature file specified for non verify\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (!sigfile && (pkey_op == EVP_PKEY_OP_VERIFY)) {
 | 
			
		||||
        BIO_puts(bio_err, "No signature file specified for verify\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
/* FIXME: seed PRNG only if needed */
 | 
			
		||||
    app_RAND_load_file(NULL, bio_err, 0);
 | 
			
		||||
 | 
			
		||||
    if (pkey_op != EVP_PKEY_OP_DERIVE) {
 | 
			
		||||
        if (infile) {
 | 
			
		||||
            if (!(in = BIO_new_file(infile, "rb"))) {
 | 
			
		||||
                BIO_puts(bio_err, "Error Opening Input File\n");
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        } else
 | 
			
		||||
            in = BIO_new_fp(stdin, BIO_NOCLOSE);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (outfile) {
 | 
			
		||||
        if (!(out = BIO_new_file(outfile, "wb"))) {
 | 
			
		||||
            BIO_printf(bio_err, "Error Creating Output File\n");
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    } else {
 | 
			
		||||
        out = BIO_new_fp(stdout, BIO_NOCLOSE);
 | 
			
		||||
#ifdef OPENSSL_SYS_VMS
 | 
			
		||||
        {
 | 
			
		||||
            BIO *tmpbio = BIO_new(BIO_f_linebuffer());
 | 
			
		||||
            out = BIO_push(tmpbio, out);
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (sigfile) {
 | 
			
		||||
        BIO *sigbio = BIO_new_file(sigfile, "rb");
 | 
			
		||||
        if (!sigbio) {
 | 
			
		||||
            BIO_printf(bio_err, "Can't open signature file %s\n", sigfile);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
        siglen = bio_to_mem(&sig, keysize * 10, sigbio);
 | 
			
		||||
        BIO_free(sigbio);
 | 
			
		||||
        if (siglen <= 0) {
 | 
			
		||||
            BIO_printf(bio_err, "Error reading signature data\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (in) {
 | 
			
		||||
        /* Read the input data */
 | 
			
		||||
        buf_inlen = bio_to_mem(&buf_in, keysize * 10, in);
 | 
			
		||||
        if (buf_inlen <= 0) {
 | 
			
		||||
            BIO_printf(bio_err, "Error reading input Data\n");
 | 
			
		||||
            exit(1);
 | 
			
		||||
        }
 | 
			
		||||
        if (rev) {
 | 
			
		||||
            size_t i;
 | 
			
		||||
            unsigned char ctmp;
 | 
			
		||||
            size_t l = (size_t)buf_inlen;
 | 
			
		||||
            for (i = 0; i < l / 2; i++) {
 | 
			
		||||
                ctmp = buf_in[i];
 | 
			
		||||
                buf_in[i] = buf_in[l - 1 - i];
 | 
			
		||||
                buf_in[l - 1 - i] = ctmp;
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (pkey_op == EVP_PKEY_OP_VERIFY) {
 | 
			
		||||
        rv = EVP_PKEY_verify(ctx, sig, (size_t)siglen,
 | 
			
		||||
                             buf_in, (size_t)buf_inlen);
 | 
			
		||||
        if (rv == 0)
 | 
			
		||||
            BIO_puts(out, "Signature Verification Failure\n");
 | 
			
		||||
        else if (rv == 1)
 | 
			
		||||
            BIO_puts(out, "Signature Verified Successfully\n");
 | 
			
		||||
        if (rv >= 0)
 | 
			
		||||
            goto end;
 | 
			
		||||
    } else {
 | 
			
		||||
        rv = do_keyop(ctx, pkey_op, NULL, (size_t *)&buf_outlen,
 | 
			
		||||
                      buf_in, (size_t)buf_inlen);
 | 
			
		||||
        if (rv > 0) {
 | 
			
		||||
            buf_out = OPENSSL_malloc(buf_outlen);
 | 
			
		||||
            if (!buf_out)
 | 
			
		||||
                rv = -1;
 | 
			
		||||
            else
 | 
			
		||||
                rv = do_keyop(ctx, pkey_op,
 | 
			
		||||
                              buf_out, (size_t *)&buf_outlen,
 | 
			
		||||
                              buf_in, (size_t)buf_inlen);
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (rv <= 0) {
 | 
			
		||||
        BIO_printf(bio_err, "Public Key operation error\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    ret = 0;
 | 
			
		||||
    if (asn1parse) {
 | 
			
		||||
        if (!ASN1_parse_dump(out, buf_out, buf_outlen, 1, -1))
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
    } else if (hexdump)
 | 
			
		||||
        BIO_dump(out, (char *)buf_out, buf_outlen);
 | 
			
		||||
    else
 | 
			
		||||
        BIO_write(out, buf_out, buf_outlen);
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
    if (ctx)
 | 
			
		||||
        EVP_PKEY_CTX_free(ctx);
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    if (buf_in)
 | 
			
		||||
        OPENSSL_free(buf_in);
 | 
			
		||||
    if (buf_out)
 | 
			
		||||
        OPENSSL_free(buf_out);
 | 
			
		||||
    if (sig)
 | 
			
		||||
        OPENSSL_free(sig);
 | 
			
		||||
    return ret;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static void usage()
 | 
			
		||||
{
 | 
			
		||||
    BIO_printf(bio_err, "Usage: pkeyutl [options]\n");
 | 
			
		||||
    BIO_printf(bio_err, "-in file        input file\n");
 | 
			
		||||
    BIO_printf(bio_err, "-out file       output file\n");
 | 
			
		||||
    BIO_printf(bio_err,
 | 
			
		||||
               "-sigfile file signature file (verify operation only)\n");
 | 
			
		||||
    BIO_printf(bio_err, "-inkey file     input key\n");
 | 
			
		||||
    BIO_printf(bio_err, "-keyform arg    private key format - default PEM\n");
 | 
			
		||||
    BIO_printf(bio_err, "-pubin          input is a public key\n");
 | 
			
		||||
    BIO_printf(bio_err,
 | 
			
		||||
               "-certin         input is a certificate carrying a public key\n");
 | 
			
		||||
    BIO_printf(bio_err, "-pkeyopt X:Y    public key options\n");
 | 
			
		||||
    BIO_printf(bio_err, "-sign           sign with private key\n");
 | 
			
		||||
    BIO_printf(bio_err, "-verify         verify with public key\n");
 | 
			
		||||
    BIO_printf(bio_err,
 | 
			
		||||
               "-verifyrecover  verify with public key, recover original data\n");
 | 
			
		||||
    BIO_printf(bio_err, "-encrypt        encrypt with public key\n");
 | 
			
		||||
    BIO_printf(bio_err, "-decrypt        decrypt with private key\n");
 | 
			
		||||
    BIO_printf(bio_err, "-derive         derive shared secret\n");
 | 
			
		||||
    BIO_printf(bio_err, "-hexdump        hex dump output\n");
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    BIO_printf(bio_err,
 | 
			
		||||
               "-engine e       use engine e, possibly a hardware device.\n");
 | 
			
		||||
#endif
 | 
			
		||||
    BIO_printf(bio_err, "-passin arg     pass phrase source\n");
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static EVP_PKEY_CTX *init_ctx(int *pkeysize,
 | 
			
		||||
                              char *keyfile, int keyform, int key_type,
 | 
			
		||||
                              char *passargin, int pkey_op, ENGINE *e)
 | 
			
		||||
{
 | 
			
		||||
    EVP_PKEY *pkey = NULL;
 | 
			
		||||
    EVP_PKEY_CTX *ctx = NULL;
 | 
			
		||||
    char *passin = NULL;
 | 
			
		||||
    int rv = -1;
 | 
			
		||||
    X509 *x;
 | 
			
		||||
    if (((pkey_op == EVP_PKEY_OP_SIGN) || (pkey_op == EVP_PKEY_OP_DECRYPT)
 | 
			
		||||
         || (pkey_op == EVP_PKEY_OP_DERIVE))
 | 
			
		||||
        && (key_type != KEY_PRIVKEY)) {
 | 
			
		||||
        BIO_printf(bio_err, "A private key is needed for this operation\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    if (!app_passwd(bio_err, passargin, NULL, &passin, NULL)) {
 | 
			
		||||
        BIO_printf(bio_err, "Error getting password\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    switch (key_type) {
 | 
			
		||||
    case KEY_PRIVKEY:
 | 
			
		||||
        pkey = load_key(bio_err, keyfile, keyform, 0,
 | 
			
		||||
                        passin, e, "Private Key");
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case KEY_PUBKEY:
 | 
			
		||||
        pkey = load_pubkey(bio_err, keyfile, keyform, 0,
 | 
			
		||||
                           NULL, e, "Public Key");
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case KEY_CERT:
 | 
			
		||||
        x = load_cert(bio_err, keyfile, keyform, NULL, e, "Certificate");
 | 
			
		||||
        if (x) {
 | 
			
		||||
            pkey = X509_get_pubkey(x);
 | 
			
		||||
            X509_free(x);
 | 
			
		||||
        }
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    *pkeysize = EVP_PKEY_size(pkey);
 | 
			
		||||
 | 
			
		||||
    if (!pkey)
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    ctx = EVP_PKEY_CTX_new(pkey, e);
 | 
			
		||||
 | 
			
		||||
    EVP_PKEY_free(pkey);
 | 
			
		||||
 | 
			
		||||
    if (!ctx)
 | 
			
		||||
        goto end;
 | 
			
		||||
 | 
			
		||||
    switch (pkey_op) {
 | 
			
		||||
    case EVP_PKEY_OP_SIGN:
 | 
			
		||||
        rv = EVP_PKEY_sign_init(ctx);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_VERIFY:
 | 
			
		||||
        rv = EVP_PKEY_verify_init(ctx);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_VERIFYRECOVER:
 | 
			
		||||
        rv = EVP_PKEY_verify_recover_init(ctx);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_ENCRYPT:
 | 
			
		||||
        rv = EVP_PKEY_encrypt_init(ctx);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_DECRYPT:
 | 
			
		||||
        rv = EVP_PKEY_decrypt_init(ctx);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_DERIVE:
 | 
			
		||||
        rv = EVP_PKEY_derive_init(ctx);
 | 
			
		||||
        break;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (rv <= 0) {
 | 
			
		||||
        EVP_PKEY_CTX_free(ctx);
 | 
			
		||||
        ctx = NULL;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
 end:
 | 
			
		||||
 | 
			
		||||
    if (passin)
 | 
			
		||||
        OPENSSL_free(passin);
 | 
			
		||||
 | 
			
		||||
    return ctx;
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int setup_peer(BIO *err, EVP_PKEY_CTX *ctx, int peerform,
 | 
			
		||||
                      const char *file)
 | 
			
		||||
{
 | 
			
		||||
    EVP_PKEY *peer = NULL;
 | 
			
		||||
    int ret;
 | 
			
		||||
    if (!ctx) {
 | 
			
		||||
        BIO_puts(err, "-peerkey command before -inkey\n");
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    peer = load_pubkey(bio_err, file, peerform, 0, NULL, NULL, "Peer Key");
 | 
			
		||||
 | 
			
		||||
    if (!peer) {
 | 
			
		||||
        BIO_printf(bio_err, "Error reading peer key %s\n", file);
 | 
			
		||||
        ERR_print_errors(err);
 | 
			
		||||
        return 0;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    ret = EVP_PKEY_derive_set_peer(ctx, peer);
 | 
			
		||||
 | 
			
		||||
    EVP_PKEY_free(peer);
 | 
			
		||||
    if (ret <= 0)
 | 
			
		||||
        ERR_print_errors(err);
 | 
			
		||||
    return ret;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int do_keyop(EVP_PKEY_CTX *ctx, int pkey_op,
 | 
			
		||||
                    unsigned char *out, size_t *poutlen,
 | 
			
		||||
                    unsigned char *in, size_t inlen)
 | 
			
		||||
{
 | 
			
		||||
    int rv = 0;
 | 
			
		||||
    switch (pkey_op) {
 | 
			
		||||
    case EVP_PKEY_OP_VERIFYRECOVER:
 | 
			
		||||
        rv = EVP_PKEY_verify_recover(ctx, out, poutlen, in, inlen);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_SIGN:
 | 
			
		||||
        rv = EVP_PKEY_sign(ctx, out, poutlen, in, inlen);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_ENCRYPT:
 | 
			
		||||
        rv = EVP_PKEY_encrypt(ctx, out, poutlen, in, inlen);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_DECRYPT:
 | 
			
		||||
        rv = EVP_PKEY_decrypt(ctx, out, poutlen, in, inlen);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    case EVP_PKEY_OP_DERIVE:
 | 
			
		||||
        rv = EVP_PKEY_derive(ctx, out, poutlen);
 | 
			
		||||
        break;
 | 
			
		||||
 | 
			
		||||
    }
 | 
			
		||||
    return rv;
 | 
			
		||||
}
 | 
			
		||||
							
								
								
									
										28
									
								
								apps/prime.c
									
									
									
									
									
								
							
							
						
						
									
										28
									
								
								apps/prime.c
									
									
									
									
									
								
							@@ -61,9 +61,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    int hex = 0;
 | 
			
		||||
    int checks = 20;
 | 
			
		||||
    int generate = 0;
 | 
			
		||||
    int bits = 0;
 | 
			
		||||
    int safe = 0;
 | 
			
		||||
    BIGNUM *bn = NULL;
 | 
			
		||||
    BIO *bio_out;
 | 
			
		||||
 | 
			
		||||
@@ -78,15 +75,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    while (argc >= 1 && **argv == '-') {
 | 
			
		||||
        if (!strcmp(*argv, "-hex"))
 | 
			
		||||
            hex = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-generate"))
 | 
			
		||||
            generate = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-bits"))
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            else
 | 
			
		||||
                bits = atoi(*++argv);
 | 
			
		||||
        else if (!strcmp(*argv, "-safe"))
 | 
			
		||||
            safe = 1;
 | 
			
		||||
        else if (!strcmp(*argv, "-checks"))
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
@@ -100,7 +88,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        ++argv;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (argv[0] == NULL && !generate) {
 | 
			
		||||
    if (argv[0] == NULL) {
 | 
			
		||||
        BIO_printf(bio_err, "No prime specified\n");
 | 
			
		||||
        goto bad;
 | 
			
		||||
    }
 | 
			
		||||
@@ -115,19 +103,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (generate) {
 | 
			
		||||
        char *s;
 | 
			
		||||
 | 
			
		||||
        if (!bits) {
 | 
			
		||||
            BIO_printf(bio_err, "Specifiy the number of bits.\n");
 | 
			
		||||
            return 1;
 | 
			
		||||
        }
 | 
			
		||||
        bn = BN_new();
 | 
			
		||||
        BN_generate_prime_ex(bn, bits, safe, NULL, NULL, NULL);
 | 
			
		||||
        s = hex ? BN_bn2hex(bn) : BN_bn2dec(bn);
 | 
			
		||||
        BIO_printf(bio_out, "%s\n", s);
 | 
			
		||||
        OPENSSL_free(s);
 | 
			
		||||
    } else {
 | 
			
		||||
    if (hex)
 | 
			
		||||
        BN_hex2bn(&bn, argv[0]);
 | 
			
		||||
    else
 | 
			
		||||
@@ -136,7 +111,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    BN_print(bio_out, bn);
 | 
			
		||||
    BIO_printf(bio_out, " is %sprime\n",
 | 
			
		||||
               BN_is_prime_ex(bn, checks, NULL, NULL) ? "" : "not ");
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    BN_free(bn);
 | 
			
		||||
    BIO_free_all(bio_out);
 | 
			
		||||
 
 | 
			
		||||
@@ -1,16 +1,18 @@
 | 
			
		||||
-----BEGIN PRIVATE KEY-----
 | 
			
		||||
MIICdgIBADANBgkqhkiG9w0BAQEFAASCAmAwggJcAgEAAoGBAMo7DFNMqywUA1O/
 | 
			
		||||
qvWqCOm6rGrUAcR+dKsSXw6y2qiKO7APDDyotc0b4Mxwqjga98npex2RBIwUoCGJ
 | 
			
		||||
iEmMXo/a8RbXVUZ+ZwcAX7PC+XeXVC5qoajaBBkd2MvYmib/2PqnNrgvhHsUL5dO
 | 
			
		||||
xhC7cRqxLM/g45k3Yyw+nGa+WkTdAgMBAAECgYBMBT5w4dVG0I8foGFnz+9hzWab
 | 
			
		||||
Ee9IKjE5TcKmB93ilXQyjrWO5+zPmbc7ou6aAKk9IaPCTY1kCyzW7pho7Xdt+RFq
 | 
			
		||||
TgVXGZZfqtixO7f2/5oqZAkd00eOn9ZrhBpVMu4yXbbDvhDyFe4/oy0HGDjRUhxa
 | 
			
		||||
Lf6ZlBuTherxm4eFkQJBAPBQwRs9UtqaMAQlagA9pV5UsQjV1WT4IxDURMPfXgCd
 | 
			
		||||
ETNkB6pP0SmxQm5xhv9N2HY1UtoWpug9s0OU5IJB15sCQQDXbfbjiujNbuOxCFNw
 | 
			
		||||
68JZaCFVdNovyOWORkpenQLNEjVkmTCS9OayK09ADEYtsdpUGKeF+2EYBNkFr5px
 | 
			
		||||
CajnAkBMYI4PNz1HBuwt1SpMa0tMoMQnV7bbwVV7usskKbC5pzHZUHhzM6z5gEHp
 | 
			
		||||
0iEisT4Ty7zKXZqsgzefSgoaMAzzAkEAoCIaUhtwXzwdPfvNYnOs3J6doJMimECB
 | 
			
		||||
+lbfcyLM8TimvadtRt+KGEg/OYGmLNM2UiqdY+duzdbUpvhYGcwvYwJAQvaoi9z2
 | 
			
		||||
CkiwSs/PFrLaNlfLJmXRsUBzmiWYoh6+IQJJorEXz7ewI72ee9RBO4s746cgUFwH
 | 
			
		||||
Ri+qO+HhZFUBqQ==
 | 
			
		||||
-----END PRIVATE KEY-----
 | 
			
		||||
-----BEGIN RSA PRIVATE KEY-----
 | 
			
		||||
Proc-Type: 4,ENCRYPTED
 | 
			
		||||
DEK-Info: DES-EDE3-CBC,BA26229A1653B7FF
 | 
			
		||||
 | 
			
		||||
6nhWG8PKhTPO/s3ZvjUa6226NlKdvPDZFsNXOOoSUs9ejxpb/aj5huhs6qRYzsz9
 | 
			
		||||
Year47uaAZYhGD0vAagnNiBnYmjWEpN9G/wQxG7pgZThK1ZxDi63qn8aQ8UjuGHo
 | 
			
		||||
F6RpnnBQIAnWTWqr/Qsybtc5EoNkrj/Cpx0OfbSr6gZsFBCxwX1R1hT3/mhJ45f3
 | 
			
		||||
XMofY32Vdfx9/vtw1O7HmlHXQnXaqnbd9/nn1EpvFJG9+UjPoW7gV4jCOLuR4deE
 | 
			
		||||
jS8hm+cpkwXmFtk3VGjT9tQXPpMv3JpYfBqgGQoMAJ5Toq0DWcHi6Wg08PsD8lgy
 | 
			
		||||
vmTioPsRg+JGkJkJ8GnusgLpQdlQJbjzd7wGE6ElUFLfOxLo8bLlRHoriHNdWYhh
 | 
			
		||||
JjY0LyeTkovcmWxVjImc6ZyBz5Ly4t0BYf1gq3OkjsV91Q1taBxnhiavfizqMCAf
 | 
			
		||||
PPB3sLQnlXG77TOXkNxpqbZfEYrVZW2Nsqqdn8s07Uj4IMONZyq2odYKWFPMJBiM
 | 
			
		||||
POYwXjMAOcmFMTHYsVlhcUJuV6LOuipw/FEbTtPH/MYMxLe4zx65dYo1rb4iLKLS
 | 
			
		||||
gMtB0o/Wl4Xno3ZXh1ucicYnV2J7NpVcjVq+3SFiCRu2SrSkZHZ23EPS13Ec6fcz
 | 
			
		||||
8X/YGA2vTJ8MAOozAzQUwHQYvLk7bIoQVekqDq4p0AZQbhdspHpArCk0Ifqqzg/v
 | 
			
		||||
Uyky/zZiQYanzDenTSRVI/8wac3olxpU8QvbySxYqmbkgq6bTpXJfYFQfnAttEsC
 | 
			
		||||
dA4S5UFgyOPZluxCAM4yaJF3Ft6neutNwftuJQMbgCUi9vYg2tGdSw==
 | 
			
		||||
-----END RSA PRIVATE KEY-----
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										43
									
								
								apps/progs.h
									
									
									
									
									
								
							
							
						
						
									
										43
									
								
								apps/progs.h
									
									
									
									
									
								
							@@ -22,7 +22,6 @@ extern int ecparam_main(int argc, char *argv[]);
 | 
			
		||||
extern int x509_main(int argc, char *argv[]);
 | 
			
		||||
extern int genrsa_main(int argc, char *argv[]);
 | 
			
		||||
extern int gendsa_main(int argc, char *argv[]);
 | 
			
		||||
extern int genpkey_main(int argc, char *argv[]);
 | 
			
		||||
extern int s_server_main(int argc, char *argv[]);
 | 
			
		||||
extern int s_client_main(int argc, char *argv[]);
 | 
			
		||||
extern int speed_main(int argc, char *argv[]);
 | 
			
		||||
@@ -36,31 +35,22 @@ extern int ciphers_main(int argc, char *argv[]);
 | 
			
		||||
extern int nseq_main(int argc, char *argv[]);
 | 
			
		||||
extern int pkcs12_main(int argc, char *argv[]);
 | 
			
		||||
extern int pkcs8_main(int argc, char *argv[]);
 | 
			
		||||
extern int pkey_main(int argc, char *argv[]);
 | 
			
		||||
extern int pkeyparam_main(int argc, char *argv[]);
 | 
			
		||||
extern int pkeyutl_main(int argc, char *argv[]);
 | 
			
		||||
extern int spkac_main(int argc, char *argv[]);
 | 
			
		||||
extern int smime_main(int argc, char *argv[]);
 | 
			
		||||
extern int rand_main(int argc, char *argv[]);
 | 
			
		||||
extern int engine_main(int argc, char *argv[]);
 | 
			
		||||
extern int ocsp_main(int argc, char *argv[]);
 | 
			
		||||
extern int prime_main(int argc, char *argv[]);
 | 
			
		||||
extern int ts_main(int argc, char *argv[]);
 | 
			
		||||
extern int srp_main(int argc, char *argv[]);
 | 
			
		||||
 | 
			
		||||
#define FUNC_TYPE_GENERAL       1
 | 
			
		||||
#define FUNC_TYPE_MD            2
 | 
			
		||||
#define FUNC_TYPE_CIPHER        3
 | 
			
		||||
#define FUNC_TYPE_PKEY          4
 | 
			
		||||
#define FUNC_TYPE_MD_ALG        5
 | 
			
		||||
#define FUNC_TYPE_CIPHER_ALG    6
 | 
			
		||||
 | 
			
		||||
typedef struct {
 | 
			
		||||
    int type;
 | 
			
		||||
    const char *name;
 | 
			
		||||
    int (*func) (int argc, char *argv[]);
 | 
			
		||||
} FUNCTION;
 | 
			
		||||
DECLARE_LHASH_OF(FUNCTION);
 | 
			
		||||
 | 
			
		||||
FUNCTION functions[] = {
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "verify", verify_main},
 | 
			
		||||
@@ -106,17 +96,16 @@ FUNCTION functions[] = {
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "gendsa", gendsa_main},
 | 
			
		||||
#endif
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "genpkey", genpkey_main},
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK)
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK) && !(defined(OPENSSL_NO_SSL2) && defined(OPENSSL_NO_SSL3))
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "s_server", s_server_main},
 | 
			
		||||
#endif
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK)
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK) && !(defined(OPENSSL_NO_SSL2) && defined(OPENSSL_NO_SSL3))
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "s_client", s_client_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_SPEED
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "speed", speed_main},
 | 
			
		||||
#endif
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK)
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK) && !(defined(OPENSSL_NO_SSL2) && defined(OPENSSL_NO_SSL3))
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "s_time", s_time_main},
 | 
			
		||||
#endif
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "version", version_main},
 | 
			
		||||
@@ -126,7 +115,7 @@ FUNCTION functions[] = {
 | 
			
		||||
#endif
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "crl2pkcs7", crl2pkcs7_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "sess_id", sess_id_main},
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK)
 | 
			
		||||
#if !defined(OPENSSL_NO_SOCK) && !(defined(OPENSSL_NO_SSL2) && defined(OPENSSL_NO_SSL3))
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "ciphers", ciphers_main},
 | 
			
		||||
#endif
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "nseq", nseq_main},
 | 
			
		||||
@@ -134,23 +123,14 @@ FUNCTION functions[] = {
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "pkcs12", pkcs12_main},
 | 
			
		||||
#endif
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "pkcs8", pkcs8_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "pkey", pkey_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "pkeyparam", pkeyparam_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "pkeyutl", pkeyutl_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "spkac", spkac_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "smime", smime_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "rand", rand_main},
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "engine", engine_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_OCSP
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "ocsp", ocsp_main},
 | 
			
		||||
#endif
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "prime", prime_main},
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "ts", ts_main},
 | 
			
		||||
#ifndef OPENSSL_NO_SRP
 | 
			
		||||
    {FUNC_TYPE_GENERAL, "srp", srp_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_MD2
 | 
			
		||||
    {FUNC_TYPE_MD, "md2", dgst_main},
 | 
			
		||||
#endif
 | 
			
		||||
@@ -172,18 +152,6 @@ FUNCTION functions[] = {
 | 
			
		||||
#ifndef OPENSSL_NO_RMD160
 | 
			
		||||
    {FUNC_TYPE_MD, "rmd160", dgst_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_SHA224
 | 
			
		||||
    {FUNC_TYPE_MD, "sha224", dgst_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_SHA256
 | 
			
		||||
    {FUNC_TYPE_MD, "sha256", dgst_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_SHA384
 | 
			
		||||
    {FUNC_TYPE_MD, "sha384", dgst_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_SHA512
 | 
			
		||||
    {FUNC_TYPE_MD, "sha512", dgst_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_AES
 | 
			
		||||
    {FUNC_TYPE_CIPHER, "aes-128-cbc", enc_main},
 | 
			
		||||
#endif
 | 
			
		||||
@@ -221,9 +189,6 @@ FUNCTION functions[] = {
 | 
			
		||||
    {FUNC_TYPE_CIPHER, "camellia-256-ecb", enc_main},
 | 
			
		||||
#endif
 | 
			
		||||
    {FUNC_TYPE_CIPHER, "base64", enc_main},
 | 
			
		||||
#ifdef ZLIB
 | 
			
		||||
    {FUNC_TYPE_CIPHER, "zlib", enc_main},
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_DES
 | 
			
		||||
    {FUNC_TYPE_CIPHER, "des", enc_main},
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
@@ -13,16 +13,12 @@ print <<'EOF';
 | 
			
		||||
#define FUNC_TYPE_GENERAL	1
 | 
			
		||||
#define FUNC_TYPE_MD		2
 | 
			
		||||
#define FUNC_TYPE_CIPHER	3
 | 
			
		||||
#define FUNC_TYPE_PKEY		4
 | 
			
		||||
#define FUNC_TYPE_MD_ALG	5
 | 
			
		||||
#define FUNC_TYPE_CIPHER_ALG	6
 | 
			
		||||
 | 
			
		||||
typedef struct {
 | 
			
		||||
	int type;
 | 
			
		||||
	const char *name;
 | 
			
		||||
	int (*func)(int argc,char *argv[]);
 | 
			
		||||
	} FUNCTION;
 | 
			
		||||
DECLARE_LHASH_OF(FUNCTION);
 | 
			
		||||
 | 
			
		||||
FUNCTION functions[] = {
 | 
			
		||||
EOF
 | 
			
		||||
@@ -32,7 +28,7 @@ foreach (@ARGV)
 | 
			
		||||
	push(@files,$_);
 | 
			
		||||
	$str="\t{FUNC_TYPE_GENERAL,\"$_\",${_}_main},\n";
 | 
			
		||||
	if (($_ =~ /^s_/) || ($_ =~ /^ciphers$/))
 | 
			
		||||
		{ print "#if !defined(OPENSSL_NO_SOCK)\n${str}#endif\n"; } 
 | 
			
		||||
		{ print "#if !defined(OPENSSL_NO_SOCK) && !(defined(OPENSSL_NO_SSL2) && defined(OPENSSL_NO_SSL3))\n${str}#endif\n"; } 
 | 
			
		||||
	elsif ( ($_ =~ /^speed$/))
 | 
			
		||||
		{ print "#ifndef OPENSSL_NO_SPEED\n${str}#endif\n"; }
 | 
			
		||||
	elsif ( ($_ =~ /^engine$/))
 | 
			
		||||
@@ -49,15 +45,11 @@ foreach (@ARGV)
 | 
			
		||||
		{ print "#if !defined(OPENSSL_NO_DES) && !defined(OPENSSL_NO_SHA1)\n${str}#endif\n"; }
 | 
			
		||||
	elsif ( ($_ =~ /^cms$/))
 | 
			
		||||
		{ print "#ifndef OPENSSL_NO_CMS\n${str}#endif\n"; }
 | 
			
		||||
	elsif ( ($_ =~ /^ocsp$/))
 | 
			
		||||
		{ print "#ifndef OPENSSL_NO_OCSP\n${str}#endif\n"; }
 | 
			
		||||
	elsif ( ($_ =~ /^srp$/))
 | 
			
		||||
		{ print "#ifndef OPENSSL_NO_SRP\n${str}#endif\n"; }
 | 
			
		||||
	else
 | 
			
		||||
		{ print $str; }
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
foreach ("md2","md4","md5","sha","sha1","mdc2","rmd160","sha224","sha256","sha384","sha512")
 | 
			
		||||
foreach ("md2","md4","md5","sha","sha1","mdc2","rmd160")
 | 
			
		||||
	{
 | 
			
		||||
	push(@files,$_);
 | 
			
		||||
	printf "#ifndef OPENSSL_NO_".uc($_)."\n\t{FUNC_TYPE_MD,\"".$_."\",dgst_main},\n#endif\n";
 | 
			
		||||
@@ -70,7 +62,7 @@ foreach (
 | 
			
		||||
	"camellia-128-cbc", "camellia-128-ecb",
 | 
			
		||||
	"camellia-192-cbc", "camellia-192-ecb",
 | 
			
		||||
	"camellia-256-cbc", "camellia-256-ecb",
 | 
			
		||||
	"base64", "zlib",
 | 
			
		||||
	"base64",
 | 
			
		||||
	"des", "des3", "desx", "idea", "seed", "rc4", "rc4-40",
 | 
			
		||||
	"rc2", "bf", "cast", "rc5",
 | 
			
		||||
	"des-ecb", "des-ede",    "des-ede3",
 | 
			
		||||
@@ -97,7 +89,6 @@ foreach (
 | 
			
		||||
	elsif ($_ =~ /bf/)   { $t="#ifndef OPENSSL_NO_BF\n${t}#endif\n"; }
 | 
			
		||||
	elsif ($_ =~ /cast/) { $t="#ifndef OPENSSL_NO_CAST\n${t}#endif\n"; }
 | 
			
		||||
	elsif ($_ =~ /rc5/)  { $t="#ifndef OPENSSL_NO_RC5\n${t}#endif\n"; }
 | 
			
		||||
	elsif ($_ =~ /zlib/)  { $t="#ifdef ZLIB\n${t}#endif\n"; }
 | 
			
		||||
	print $t;
 | 
			
		||||
	}
 | 
			
		||||
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										547
									
								
								apps/req.c
									
									
									
									
									
								
							
							
						
						
									
										547
									
								
								apps/req.c
									
									
									
									
									
								
							@@ -56,10 +56,21 @@
 | 
			
		||||
 * [including the GNU Public Licence.]
 | 
			
		||||
 */
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * Until the key-gen callbacks are modified to use newer prototypes, we allow
 | 
			
		||||
 * deprecated functions for openssl-internal code
 | 
			
		||||
 */
 | 
			
		||||
#ifdef OPENSSL_NO_DEPRECATED
 | 
			
		||||
# undef OPENSSL_NO_DEPRECATED
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#include <stdio.h>
 | 
			
		||||
#include <stdlib.h>
 | 
			
		||||
#include <time.h>
 | 
			
		||||
#include <string.h>
 | 
			
		||||
#ifdef OPENSSL_NO_STDIO
 | 
			
		||||
# define APPS_WIN16
 | 
			
		||||
#endif
 | 
			
		||||
#include "apps.h"
 | 
			
		||||
#include <openssl/bio.h>
 | 
			
		||||
#include <openssl/evp.h>
 | 
			
		||||
@@ -134,33 +145,39 @@ static int add_attribute_object(X509_REQ *req, char *text, const char *def,
 | 
			
		||||
static int add_DN_object(X509_NAME *n, char *text, const char *def,
 | 
			
		||||
                         char *value, int nid, int n_min, int n_max,
 | 
			
		||||
                         unsigned long chtype, int mval);
 | 
			
		||||
static int genpkey_cb(EVP_PKEY_CTX *ctx);
 | 
			
		||||
#ifndef OPENSSL_NO_RSA
 | 
			
		||||
static int MS_CALLBACK req_cb(int p, int n, BN_GENCB *cb);
 | 
			
		||||
#endif
 | 
			
		||||
static int req_check_len(int len, int n_min, int n_max);
 | 
			
		||||
static int check_end(const char *str, const char *end);
 | 
			
		||||
static EVP_PKEY_CTX *set_keygen_ctx(BIO *err, const char *gstr,
 | 
			
		||||
                                    int *pkey_type, long *pkeylen,
 | 
			
		||||
                                    char **palgnam, ENGINE *keygen_engine);
 | 
			
		||||
#ifndef MONOLITH
 | 
			
		||||
static char *default_config_file = NULL;
 | 
			
		||||
#endif
 | 
			
		||||
static CONF *req_conf = NULL;
 | 
			
		||||
static int batch = 0;
 | 
			
		||||
 | 
			
		||||
#define TYPE_RSA        1
 | 
			
		||||
#define TYPE_DSA        2
 | 
			
		||||
#define TYPE_DH         3
 | 
			
		||||
#define TYPE_EC         4
 | 
			
		||||
 | 
			
		||||
int MAIN(int, char **);
 | 
			
		||||
 | 
			
		||||
int MAIN(int argc, char **argv)
 | 
			
		||||
{
 | 
			
		||||
    ENGINE *e = NULL, *gen_eng = NULL;
 | 
			
		||||
    ENGINE *e = NULL;
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
    DSA *dsa_params = NULL;
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_ECDSA
 | 
			
		||||
    EC_KEY *ec_params = NULL;
 | 
			
		||||
#endif
 | 
			
		||||
    unsigned long nmflag = 0, reqflag = 0;
 | 
			
		||||
    int ex = 1, x509 = 0, days = 30;
 | 
			
		||||
    X509 *x509ss = NULL;
 | 
			
		||||
    X509_REQ *req = NULL;
 | 
			
		||||
    EVP_PKEY_CTX *genctx = NULL;
 | 
			
		||||
    const char *keyalg = NULL;
 | 
			
		||||
    char *keyalgstr = NULL;
 | 
			
		||||
    STACK_OF(OPENSSL_STRING) *pkeyopts = NULL, *sigopts = NULL;
 | 
			
		||||
    EVP_PKEY *pkey = NULL;
 | 
			
		||||
    int i = 0, badops = 0, newreq = 0, verbose = 0, pkey_type = -1;
 | 
			
		||||
    int i = 0, badops = 0, newreq = 0, verbose = 0, pkey_type = TYPE_RSA;
 | 
			
		||||
    long newkey = -1;
 | 
			
		||||
    BIO *in = NULL, *out = NULL;
 | 
			
		||||
    int informat, outformat, verify = 0, noout = 0, text = 0, keyform =
 | 
			
		||||
@@ -182,7 +199,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    char *p;
 | 
			
		||||
    char *subj = NULL;
 | 
			
		||||
    int multirdn = 0;
 | 
			
		||||
    const EVP_MD *md_alg = NULL, *digest = NULL;
 | 
			
		||||
    const EVP_MD *md_alg = NULL, *digest = EVP_sha1();
 | 
			
		||||
    unsigned long chtype = MBSTRING_ASC;
 | 
			
		||||
#ifndef MONOLITH
 | 
			
		||||
    char *to_free;
 | 
			
		||||
@@ -222,14 +239,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            engine = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-keygen_engine") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            gen_eng = ENGINE_by_id(*(++argv));
 | 
			
		||||
            if (gen_eng == NULL) {
 | 
			
		||||
                BIO_printf(bio_err, "Can't find keygen engine %s\n", *argv);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
        else if (strcmp(*argv, "-key") == 0) {
 | 
			
		||||
@@ -273,24 +282,116 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            inrand = *(++argv);
 | 
			
		||||
        } else if (strcmp(*argv, "-newkey") == 0) {
 | 
			
		||||
            int is_numeric;
 | 
			
		||||
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            keyalg = *(++argv);
 | 
			
		||||
            p = *(++argv);
 | 
			
		||||
            is_numeric = p[0] >= '0' && p[0] <= '9';
 | 
			
		||||
            if (strncmp("rsa:", p, 4) == 0 || is_numeric) {
 | 
			
		||||
                pkey_type = TYPE_RSA;
 | 
			
		||||
                if (!is_numeric)
 | 
			
		||||
                    p += 4;
 | 
			
		||||
                newkey = atoi(p);
 | 
			
		||||
            } else
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
            if (strncmp("dsa:", p, 4) == 0) {
 | 
			
		||||
                X509 *xtmp = NULL;
 | 
			
		||||
                EVP_PKEY *dtmp;
 | 
			
		||||
 | 
			
		||||
                pkey_type = TYPE_DSA;
 | 
			
		||||
                p += 4;
 | 
			
		||||
                if ((in = BIO_new_file(p, "r")) == NULL) {
 | 
			
		||||
                    perror(p);
 | 
			
		||||
                    goto end;
 | 
			
		||||
                }
 | 
			
		||||
                if ((dsa_params =
 | 
			
		||||
                     PEM_read_bio_DSAparams(in, NULL, NULL, NULL)) == NULL) {
 | 
			
		||||
                    ERR_clear_error();
 | 
			
		||||
                    (void)BIO_reset(in);
 | 
			
		||||
                    if ((xtmp =
 | 
			
		||||
                         PEM_read_bio_X509(in, NULL, NULL, NULL)) == NULL) {
 | 
			
		||||
                        BIO_printf(bio_err,
 | 
			
		||||
                                   "unable to load DSA parameters from file\n");
 | 
			
		||||
                        goto end;
 | 
			
		||||
                    }
 | 
			
		||||
 | 
			
		||||
                    if ((dtmp = X509_get_pubkey(xtmp)) == NULL)
 | 
			
		||||
                        goto end;
 | 
			
		||||
                    if (dtmp->type == EVP_PKEY_DSA)
 | 
			
		||||
                        dsa_params = DSAparams_dup(dtmp->pkey.dsa);
 | 
			
		||||
                    EVP_PKEY_free(dtmp);
 | 
			
		||||
                    X509_free(xtmp);
 | 
			
		||||
                    if (dsa_params == NULL) {
 | 
			
		||||
                        BIO_printf(bio_err,
 | 
			
		||||
                                   "Certificate does not contain DSA parameters\n");
 | 
			
		||||
                        goto end;
 | 
			
		||||
                    }
 | 
			
		||||
                }
 | 
			
		||||
                BIO_free(in);
 | 
			
		||||
                in = NULL;
 | 
			
		||||
                newkey = BN_num_bits(dsa_params->p);
 | 
			
		||||
            } else
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_ECDSA
 | 
			
		||||
            if (strncmp("ec:", p, 3) == 0) {
 | 
			
		||||
                X509 *xtmp = NULL;
 | 
			
		||||
                EVP_PKEY *dtmp;
 | 
			
		||||
                EC_GROUP *group;
 | 
			
		||||
 | 
			
		||||
                pkey_type = TYPE_EC;
 | 
			
		||||
                p += 3;
 | 
			
		||||
                if ((in = BIO_new_file(p, "r")) == NULL) {
 | 
			
		||||
                    perror(p);
 | 
			
		||||
                    goto end;
 | 
			
		||||
                }
 | 
			
		||||
                if ((ec_params = EC_KEY_new()) == NULL)
 | 
			
		||||
                    goto end;
 | 
			
		||||
                group = PEM_read_bio_ECPKParameters(in, NULL, NULL, NULL);
 | 
			
		||||
                if (group == NULL) {
 | 
			
		||||
                    EC_KEY_free(ec_params);
 | 
			
		||||
                    ERR_clear_error();
 | 
			
		||||
                    (void)BIO_reset(in);
 | 
			
		||||
                    if ((xtmp =
 | 
			
		||||
                         PEM_read_bio_X509(in, NULL, NULL, NULL)) == NULL) {
 | 
			
		||||
                        BIO_printf(bio_err,
 | 
			
		||||
                                   "unable to load EC parameters from file\n");
 | 
			
		||||
                        goto end;
 | 
			
		||||
                    }
 | 
			
		||||
 | 
			
		||||
                    if ((dtmp = X509_get_pubkey(xtmp)) == NULL)
 | 
			
		||||
                        goto end;
 | 
			
		||||
                    if (dtmp->type == EVP_PKEY_EC)
 | 
			
		||||
                        ec_params = EC_KEY_dup(dtmp->pkey.ec);
 | 
			
		||||
                    EVP_PKEY_free(dtmp);
 | 
			
		||||
                    X509_free(xtmp);
 | 
			
		||||
                    if (ec_params == NULL) {
 | 
			
		||||
                        BIO_printf(bio_err,
 | 
			
		||||
                                   "Certificate does not contain EC parameters\n");
 | 
			
		||||
                        goto end;
 | 
			
		||||
                    }
 | 
			
		||||
                } else {
 | 
			
		||||
                    if (EC_KEY_set_group(ec_params, group) == 0)
 | 
			
		||||
                        goto end;
 | 
			
		||||
                    EC_GROUP_free(group);
 | 
			
		||||
                }
 | 
			
		||||
 | 
			
		||||
                BIO_free(in);
 | 
			
		||||
                in = NULL;
 | 
			
		||||
                newkey = EC_GROUP_get_degree(EC_KEY_get0_group(ec_params));
 | 
			
		||||
            } else
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_DH
 | 
			
		||||
            if (strncmp("dh:", p, 4) == 0) {
 | 
			
		||||
                pkey_type = TYPE_DH;
 | 
			
		||||
                p += 3;
 | 
			
		||||
            } else
 | 
			
		||||
#endif
 | 
			
		||||
            {
 | 
			
		||||
                goto bad;
 | 
			
		||||
            }
 | 
			
		||||
 | 
			
		||||
            newreq = 1;
 | 
			
		||||
        } else if (strcmp(*argv, "-pkeyopt") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            if (!pkeyopts)
 | 
			
		||||
                pkeyopts = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            if (!pkeyopts || !sk_OPENSSL_STRING_push(pkeyopts, *(++argv)))
 | 
			
		||||
                goto bad;
 | 
			
		||||
        } else if (strcmp(*argv, "-sigopt") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            if (!sigopts)
 | 
			
		||||
                sigopts = sk_OPENSSL_STRING_new_null();
 | 
			
		||||
            if (!sigopts || !sk_OPENSSL_STRING_push(sigopts, *(++argv)))
 | 
			
		||||
                goto bad;
 | 
			
		||||
        } else if (strcmp(*argv, "-batch") == 0)
 | 
			
		||||
            batch = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-newhdr") == 0)
 | 
			
		||||
@@ -345,6 +446,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            serial = s2i_ASN1_INTEGER(NULL, *(++argv));
 | 
			
		||||
            if (!serial)
 | 
			
		||||
                goto bad;
 | 
			
		||||
        } else if ((md_alg = EVP_get_digestbyname(&((*argv)[1]))) != NULL) {
 | 
			
		||||
            /* ok */
 | 
			
		||||
            digest = md_alg;
 | 
			
		||||
        } else if (strcmp(*argv, "-extensions") == 0) {
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
@@ -353,9 +457,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            if (--argc < 1)
 | 
			
		||||
                goto bad;
 | 
			
		||||
            req_exts = *(++argv);
 | 
			
		||||
        } else if ((md_alg = EVP_get_digestbyname(&((*argv)[1]))) != NULL) {
 | 
			
		||||
            /* ok */
 | 
			
		||||
            digest = md_alg;
 | 
			
		||||
        } else {
 | 
			
		||||
            BIO_printf(bio_err, "unknown option %s\n", *argv);
 | 
			
		||||
            badops = 1;
 | 
			
		||||
@@ -604,6 +705,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (newreq && (pkey == NULL)) {
 | 
			
		||||
#ifndef OPENSSL_NO_RSA
 | 
			
		||||
        BN_GENCB cb;
 | 
			
		||||
#endif
 | 
			
		||||
        char *randfile = NCONF_get_string(req_conf, SECTION, "RANDFILE");
 | 
			
		||||
        if (randfile == NULL)
 | 
			
		||||
            ERR_clear_error();
 | 
			
		||||
@@ -611,60 +715,66 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        if (inrand)
 | 
			
		||||
            app_RAND_load_files(inrand);
 | 
			
		||||
 | 
			
		||||
        if (!NCONF_get_number(req_conf, SECTION, BITS, &newkey)) {
 | 
			
		||||
        if (newkey <= 0) {
 | 
			
		||||
            if (!NCONF_get_number(req_conf, SECTION, BITS, &newkey))
 | 
			
		||||
                newkey = DEFAULT_KEY_LENGTH;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (keyalg) {
 | 
			
		||||
            genctx = set_keygen_ctx(bio_err, keyalg, &pkey_type, &newkey,
 | 
			
		||||
                                    &keyalgstr, gen_eng);
 | 
			
		||||
            if (!genctx)
 | 
			
		||||
                goto end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (newkey < MIN_KEY_LENGTH
 | 
			
		||||
            && (pkey_type == EVP_PKEY_RSA || pkey_type == EVP_PKEY_DSA)) {
 | 
			
		||||
            && (pkey_type == TYPE_RSA || pkey_type == TYPE_DSA)) {
 | 
			
		||||
            BIO_printf(bio_err, "private key length is too short,\n");
 | 
			
		||||
            BIO_printf(bio_err, "it needs to be at least %d bits, not %ld\n",
 | 
			
		||||
                       MIN_KEY_LENGTH, newkey);
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (!genctx) {
 | 
			
		||||
            genctx = set_keygen_ctx(bio_err, NULL, &pkey_type, &newkey,
 | 
			
		||||
                                    &keyalgstr, gen_eng);
 | 
			
		||||
            if (!genctx)
 | 
			
		||||
                goto end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        if (pkeyopts) {
 | 
			
		||||
            char *genopt;
 | 
			
		||||
            for (i = 0; i < sk_OPENSSL_STRING_num(pkeyopts); i++) {
 | 
			
		||||
                genopt = sk_OPENSSL_STRING_value(pkeyopts, i);
 | 
			
		||||
                if (pkey_ctrl_string(genctx, genopt) <= 0) {
 | 
			
		||||
                    BIO_printf(bio_err, "parameter error \"%s\"\n", genopt);
 | 
			
		||||
                    ERR_print_errors(bio_err);
 | 
			
		||||
                    goto end;
 | 
			
		||||
                }
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        BIO_printf(bio_err, "Generating a %ld bit %s private key\n",
 | 
			
		||||
                   newkey, keyalgstr);
 | 
			
		||||
                   newkey, (pkey_type == TYPE_RSA) ? "RSA" :
 | 
			
		||||
                   (pkey_type == TYPE_DSA) ? "DSA" : "EC");
 | 
			
		||||
 | 
			
		||||
        EVP_PKEY_CTX_set_cb(genctx, genpkey_cb);
 | 
			
		||||
        EVP_PKEY_CTX_set_app_data(genctx, bio_err);
 | 
			
		||||
        if ((pkey = EVP_PKEY_new()) == NULL)
 | 
			
		||||
            goto end;
 | 
			
		||||
 | 
			
		||||
        if (EVP_PKEY_keygen(genctx, &pkey) <= 0) {
 | 
			
		||||
            BIO_puts(bio_err, "Error Generating Key\n");
 | 
			
		||||
#ifndef OPENSSL_NO_RSA
 | 
			
		||||
        BN_GENCB_set(&cb, req_cb, bio_err);
 | 
			
		||||
        if (pkey_type == TYPE_RSA) {
 | 
			
		||||
            RSA *rsa = RSA_new();
 | 
			
		||||
            BIGNUM *bn = BN_new();
 | 
			
		||||
            if (!bn || !rsa || !BN_set_word(bn, 0x10001) ||
 | 
			
		||||
                !RSA_generate_key_ex(rsa, newkey, bn, &cb) ||
 | 
			
		||||
                !EVP_PKEY_assign_RSA(pkey, rsa)) {
 | 
			
		||||
                if (bn)
 | 
			
		||||
                    BN_free(bn);
 | 
			
		||||
                if (rsa)
 | 
			
		||||
                    RSA_free(rsa);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
 | 
			
		||||
        EVP_PKEY_CTX_free(genctx);
 | 
			
		||||
        genctx = NULL;
 | 
			
		||||
            BN_free(bn);
 | 
			
		||||
        } else
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
        if (pkey_type == TYPE_DSA) {
 | 
			
		||||
            if (!DSA_generate_key(dsa_params))
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (!EVP_PKEY_assign_DSA(pkey, dsa_params))
 | 
			
		||||
                goto end;
 | 
			
		||||
            dsa_params = NULL;
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_ECDSA
 | 
			
		||||
        if (pkey_type == TYPE_EC) {
 | 
			
		||||
            if (!EC_KEY_generate_key(ec_params))
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (!EVP_PKEY_assign_EC_KEY(pkey, ec_params))
 | 
			
		||||
                goto end;
 | 
			
		||||
            ec_params = NULL;
 | 
			
		||||
        }
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
        app_RAND_write_file(randfile, bio_err);
 | 
			
		||||
 | 
			
		||||
        if (pkey == NULL)
 | 
			
		||||
            goto end;
 | 
			
		||||
 | 
			
		||||
        if (keyout == NULL) {
 | 
			
		||||
            keyout = NCONF_get_string(req_conf, SECTION, KEYFILE);
 | 
			
		||||
            if (keyout == NULL)
 | 
			
		||||
@@ -750,7 +860,14 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            BIO_printf(bio_err, "you need to specify a private key\n");
 | 
			
		||||
            goto end;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
        if (pkey->type == EVP_PKEY_DSA)
 | 
			
		||||
            digest = EVP_dss1();
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_ECDSA
 | 
			
		||||
        if (pkey->type == EVP_PKEY_EC)
 | 
			
		||||
            digest = EVP_ecdsa();
 | 
			
		||||
#endif
 | 
			
		||||
        if (req == NULL) {
 | 
			
		||||
            req = X509_REQ_new();
 | 
			
		||||
            if (req == NULL) {
 | 
			
		||||
@@ -790,7 +907,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (!X509_gmtime_adj(X509_get_notBefore(x509ss), 0))
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (!X509_time_adj_ex(X509_get_notAfter(x509ss), days, 0, NULL))
 | 
			
		||||
            if (!X509_gmtime_adj
 | 
			
		||||
                (X509_get_notAfter(x509ss), (long)60 * 60 * 24 * days))
 | 
			
		||||
                goto end;
 | 
			
		||||
            if (!X509_set_subject_name
 | 
			
		||||
                (x509ss, X509_REQ_get_subject_name(req)))
 | 
			
		||||
@@ -814,11 +932,8 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
 | 
			
		||||
            i = do_X509_sign(bio_err, x509ss, pkey, digest, sigopts);
 | 
			
		||||
            if (!i) {
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
            if (!(i = X509_sign(x509ss, pkey, digest)))
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
        } else {
 | 
			
		||||
            X509V3_CTX ext_ctx;
 | 
			
		||||
 | 
			
		||||
@@ -835,16 +950,13 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
                           req_exts);
 | 
			
		||||
                goto end;
 | 
			
		||||
            }
 | 
			
		||||
            i = do_X509_REQ_sign(bio_err, req, pkey, digest, sigopts);
 | 
			
		||||
            if (!i) {
 | 
			
		||||
                ERR_print_errors(bio_err);
 | 
			
		||||
            if (!(i = X509_REQ_sign(req, pkey, digest)))
 | 
			
		||||
                goto end;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (subj && x509) {
 | 
			
		||||
        BIO_printf(bio_err, "Cannot modify certificate subject\n");
 | 
			
		||||
        BIO_printf(bio_err, "Cannot modifiy certificate subject\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -959,7 +1071,7 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
        }
 | 
			
		||||
        fprintf(stdout, "Modulus=");
 | 
			
		||||
#ifndef OPENSSL_NO_RSA
 | 
			
		||||
        if (EVP_PKEY_base_id(tpubkey) == EVP_PKEY_RSA)
 | 
			
		||||
        if (tpubkey->type == EVP_PKEY_RSA)
 | 
			
		||||
            BN_print(out, tpubkey->pkey.rsa->n);
 | 
			
		||||
        else
 | 
			
		||||
#endif
 | 
			
		||||
@@ -1013,18 +1125,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    BIO_free(in);
 | 
			
		||||
    BIO_free_all(out);
 | 
			
		||||
    EVP_PKEY_free(pkey);
 | 
			
		||||
    if (genctx)
 | 
			
		||||
        EVP_PKEY_CTX_free(genctx);
 | 
			
		||||
    if (pkeyopts)
 | 
			
		||||
        sk_OPENSSL_STRING_free(pkeyopts);
 | 
			
		||||
    if (sigopts)
 | 
			
		||||
        sk_OPENSSL_STRING_free(sigopts);
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
    if (gen_eng)
 | 
			
		||||
        ENGINE_free(gen_eng);
 | 
			
		||||
#endif
 | 
			
		||||
    if (keyalgstr)
 | 
			
		||||
        OPENSSL_free(keyalgstr);
 | 
			
		||||
    X509_REQ_free(req);
 | 
			
		||||
    X509_free(x509ss);
 | 
			
		||||
    ASN1_INTEGER_free(serial);
 | 
			
		||||
@@ -1033,6 +1133,14 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    if (passargout && passout)
 | 
			
		||||
        OPENSSL_free(passout);
 | 
			
		||||
    OBJ_cleanup();
 | 
			
		||||
#ifndef OPENSSL_NO_DSA
 | 
			
		||||
    if (dsa_params != NULL)
 | 
			
		||||
        DSA_free(dsa_params);
 | 
			
		||||
#endif
 | 
			
		||||
#ifndef OPENSSL_NO_ECDSA
 | 
			
		||||
    if (ec_params != NULL)
 | 
			
		||||
        EC_KEY_free(ec_params);
 | 
			
		||||
#endif
 | 
			
		||||
    apps_shutdown();
 | 
			
		||||
    OPENSSL_EXIT(ex);
 | 
			
		||||
}
 | 
			
		||||
@@ -1079,13 +1187,15 @@ static int make_REQ(X509_REQ *req, EVP_PKEY *pkey, char *subj, int multirdn,
 | 
			
		||||
    if (!X509_REQ_set_version(req, 0L))
 | 
			
		||||
        goto err;               /* version 1 */
 | 
			
		||||
 | 
			
		||||
    if (no_prompt)
 | 
			
		||||
        i = auto_info(req, dn_sk, attr_sk, attribs, chtype);
 | 
			
		||||
    else {
 | 
			
		||||
        if (subj)
 | 
			
		||||
            i = build_subject(req, subj, chtype, multirdn);
 | 
			
		||||
    else if (no_prompt)
 | 
			
		||||
        i = auto_info(req, dn_sk, attr_sk, attribs, chtype);
 | 
			
		||||
        else
 | 
			
		||||
            i = prompt_info(req, dn_sk, dn_sect, attr_sk, attr_sect, attribs,
 | 
			
		||||
                            chtype);
 | 
			
		||||
    }
 | 
			
		||||
    if (!i)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
@@ -1470,6 +1580,28 @@ static int add_attribute_object(X509_REQ *req, char *text, const char *def,
 | 
			
		||||
    return (0);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#ifndef OPENSSL_NO_RSA
 | 
			
		||||
static int MS_CALLBACK req_cb(int p, int n, BN_GENCB *cb)
 | 
			
		||||
{
 | 
			
		||||
    char c = '*';
 | 
			
		||||
 | 
			
		||||
    if (p == 0)
 | 
			
		||||
        c = '.';
 | 
			
		||||
    if (p == 1)
 | 
			
		||||
        c = '+';
 | 
			
		||||
    if (p == 2)
 | 
			
		||||
        c = '*';
 | 
			
		||||
    if (p == 3)
 | 
			
		||||
        c = '\n';
 | 
			
		||||
    BIO_write(cb->arg, &c, 1);
 | 
			
		||||
    (void)BIO_flush(cb->arg);
 | 
			
		||||
# ifdef LINT
 | 
			
		||||
    p = n;
 | 
			
		||||
# endif
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
static int req_check_len(int len, int n_min, int n_max)
 | 
			
		||||
{
 | 
			
		||||
    if ((n_min > 0) && (len < n_min)) {
 | 
			
		||||
@@ -1499,218 +1631,3 @@ static int check_end(const char *str, const char *end)
 | 
			
		||||
    tmp = str + slen - elen;
 | 
			
		||||
    return strcmp(tmp, end);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static EVP_PKEY_CTX *set_keygen_ctx(BIO *err, const char *gstr,
 | 
			
		||||
                                    int *pkey_type, long *pkeylen,
 | 
			
		||||
                                    char **palgnam, ENGINE *keygen_engine)
 | 
			
		||||
{
 | 
			
		||||
    EVP_PKEY_CTX *gctx = NULL;
 | 
			
		||||
    EVP_PKEY *param = NULL;
 | 
			
		||||
    long keylen = -1;
 | 
			
		||||
    BIO *pbio = NULL;
 | 
			
		||||
    const char *paramfile = NULL;
 | 
			
		||||
 | 
			
		||||
    if (gstr == NULL) {
 | 
			
		||||
        *pkey_type = EVP_PKEY_RSA;
 | 
			
		||||
        keylen = *pkeylen;
 | 
			
		||||
    } else if (gstr[0] >= '0' && gstr[0] <= '9') {
 | 
			
		||||
        *pkey_type = EVP_PKEY_RSA;
 | 
			
		||||
        keylen = atol(gstr);
 | 
			
		||||
        *pkeylen = keylen;
 | 
			
		||||
    } else if (!strncmp(gstr, "param:", 6))
 | 
			
		||||
        paramfile = gstr + 6;
 | 
			
		||||
    else {
 | 
			
		||||
        const char *p = strchr(gstr, ':');
 | 
			
		||||
        int len;
 | 
			
		||||
        ENGINE *tmpeng;
 | 
			
		||||
        const EVP_PKEY_ASN1_METHOD *ameth;
 | 
			
		||||
 | 
			
		||||
        if (p)
 | 
			
		||||
            len = p - gstr;
 | 
			
		||||
        else
 | 
			
		||||
            len = strlen(gstr);
 | 
			
		||||
        /*
 | 
			
		||||
         * The lookup of a the string will cover all engines so keep a note
 | 
			
		||||
         * of the implementation.
 | 
			
		||||
         */
 | 
			
		||||
 | 
			
		||||
        ameth = EVP_PKEY_asn1_find_str(&tmpeng, gstr, len);
 | 
			
		||||
 | 
			
		||||
        if (!ameth) {
 | 
			
		||||
            BIO_printf(err, "Unknown algorithm %.*s\n", len, gstr);
 | 
			
		||||
            return NULL;
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        EVP_PKEY_asn1_get0_info(NULL, pkey_type, NULL, NULL, NULL, ameth);
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        if (tmpeng)
 | 
			
		||||
            ENGINE_finish(tmpeng);
 | 
			
		||||
#endif
 | 
			
		||||
        if (*pkey_type == EVP_PKEY_RSA) {
 | 
			
		||||
            if (p) {
 | 
			
		||||
                keylen = atol(p + 1);
 | 
			
		||||
                *pkeylen = keylen;
 | 
			
		||||
            } else
 | 
			
		||||
                keylen = *pkeylen;
 | 
			
		||||
        } else if (p)
 | 
			
		||||
            paramfile = p + 1;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (paramfile) {
 | 
			
		||||
        pbio = BIO_new_file(paramfile, "r");
 | 
			
		||||
        if (!pbio) {
 | 
			
		||||
            BIO_printf(err, "Can't open parameter file %s\n", paramfile);
 | 
			
		||||
            return NULL;
 | 
			
		||||
        }
 | 
			
		||||
        param = PEM_read_bio_Parameters(pbio, NULL);
 | 
			
		||||
 | 
			
		||||
        if (!param) {
 | 
			
		||||
            X509 *x;
 | 
			
		||||
            (void)BIO_reset(pbio);
 | 
			
		||||
            x = PEM_read_bio_X509(pbio, NULL, NULL, NULL);
 | 
			
		||||
            if (x) {
 | 
			
		||||
                param = X509_get_pubkey(x);
 | 
			
		||||
                X509_free(x);
 | 
			
		||||
            }
 | 
			
		||||
        }
 | 
			
		||||
 | 
			
		||||
        BIO_free(pbio);
 | 
			
		||||
 | 
			
		||||
        if (!param) {
 | 
			
		||||
            BIO_printf(err, "Error reading parameter file %s\n", paramfile);
 | 
			
		||||
            return NULL;
 | 
			
		||||
        }
 | 
			
		||||
        if (*pkey_type == -1)
 | 
			
		||||
            *pkey_type = EVP_PKEY_id(param);
 | 
			
		||||
        else if (*pkey_type != EVP_PKEY_base_id(param)) {
 | 
			
		||||
            BIO_printf(err, "Key Type does not match parameters\n");
 | 
			
		||||
            EVP_PKEY_free(param);
 | 
			
		||||
            return NULL;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (palgnam) {
 | 
			
		||||
        const EVP_PKEY_ASN1_METHOD *ameth;
 | 
			
		||||
        ENGINE *tmpeng;
 | 
			
		||||
        const char *anam;
 | 
			
		||||
        ameth = EVP_PKEY_asn1_find(&tmpeng, *pkey_type);
 | 
			
		||||
        if (!ameth) {
 | 
			
		||||
            BIO_puts(err, "Internal error: can't find key algorithm\n");
 | 
			
		||||
            return NULL;
 | 
			
		||||
        }
 | 
			
		||||
        EVP_PKEY_asn1_get0_info(NULL, NULL, NULL, NULL, &anam, ameth);
 | 
			
		||||
        *palgnam = BUF_strdup(anam);
 | 
			
		||||
#ifndef OPENSSL_NO_ENGINE
 | 
			
		||||
        if (tmpeng)
 | 
			
		||||
            ENGINE_finish(tmpeng);
 | 
			
		||||
#endif
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (param) {
 | 
			
		||||
        gctx = EVP_PKEY_CTX_new(param, keygen_engine);
 | 
			
		||||
        *pkeylen = EVP_PKEY_bits(param);
 | 
			
		||||
        EVP_PKEY_free(param);
 | 
			
		||||
    } else
 | 
			
		||||
        gctx = EVP_PKEY_CTX_new_id(*pkey_type, keygen_engine);
 | 
			
		||||
 | 
			
		||||
    if (!gctx) {
 | 
			
		||||
        BIO_puts(err, "Error allocating keygen context\n");
 | 
			
		||||
        ERR_print_errors(err);
 | 
			
		||||
        return NULL;
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    if (EVP_PKEY_keygen_init(gctx) <= 0) {
 | 
			
		||||
        BIO_puts(err, "Error initializing keygen context\n");
 | 
			
		||||
        ERR_print_errors(err);
 | 
			
		||||
        return NULL;
 | 
			
		||||
    }
 | 
			
		||||
#ifndef OPENSSL_NO_RSA
 | 
			
		||||
    if ((*pkey_type == EVP_PKEY_RSA) && (keylen != -1)) {
 | 
			
		||||
        if (EVP_PKEY_CTX_set_rsa_keygen_bits(gctx, keylen) <= 0) {
 | 
			
		||||
            BIO_puts(err, "Error setting RSA keysize\n");
 | 
			
		||||
            ERR_print_errors(err);
 | 
			
		||||
            EVP_PKEY_CTX_free(gctx);
 | 
			
		||||
            return NULL;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
    return gctx;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int genpkey_cb(EVP_PKEY_CTX *ctx)
 | 
			
		||||
{
 | 
			
		||||
    char c = '*';
 | 
			
		||||
    BIO *b = EVP_PKEY_CTX_get_app_data(ctx);
 | 
			
		||||
    int p;
 | 
			
		||||
    p = EVP_PKEY_CTX_get_keygen_info(ctx, 0);
 | 
			
		||||
    if (p == 0)
 | 
			
		||||
        c = '.';
 | 
			
		||||
    if (p == 1)
 | 
			
		||||
        c = '+';
 | 
			
		||||
    if (p == 2)
 | 
			
		||||
        c = '*';
 | 
			
		||||
    if (p == 3)
 | 
			
		||||
        c = '\n';
 | 
			
		||||
    BIO_write(b, &c, 1);
 | 
			
		||||
    (void)BIO_flush(b);
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int do_sign_init(BIO *err, EVP_MD_CTX *ctx, EVP_PKEY *pkey,
 | 
			
		||||
                        const EVP_MD *md, STACK_OF(OPENSSL_STRING) *sigopts)
 | 
			
		||||
{
 | 
			
		||||
    EVP_PKEY_CTX *pkctx = NULL;
 | 
			
		||||
    int i;
 | 
			
		||||
    EVP_MD_CTX_init(ctx);
 | 
			
		||||
    if (!EVP_DigestSignInit(ctx, &pkctx, md, NULL, pkey))
 | 
			
		||||
        return 0;
 | 
			
		||||
    for (i = 0; i < sk_OPENSSL_STRING_num(sigopts); i++) {
 | 
			
		||||
        char *sigopt = sk_OPENSSL_STRING_value(sigopts, i);
 | 
			
		||||
        if (pkey_ctrl_string(pkctx, sigopt) <= 0) {
 | 
			
		||||
            BIO_printf(err, "parameter error \"%s\"\n", sigopt);
 | 
			
		||||
            ERR_print_errors(bio_err);
 | 
			
		||||
            return 0;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    return 1;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
int do_X509_sign(BIO *err, X509 *x, EVP_PKEY *pkey, const EVP_MD *md,
 | 
			
		||||
                 STACK_OF(OPENSSL_STRING) *sigopts)
 | 
			
		||||
{
 | 
			
		||||
    int rv;
 | 
			
		||||
    EVP_MD_CTX mctx;
 | 
			
		||||
    EVP_MD_CTX_init(&mctx);
 | 
			
		||||
    rv = do_sign_init(err, &mctx, pkey, md, sigopts);
 | 
			
		||||
    if (rv > 0)
 | 
			
		||||
        rv = X509_sign_ctx(x, &mctx);
 | 
			
		||||
    EVP_MD_CTX_cleanup(&mctx);
 | 
			
		||||
    return rv > 0 ? 1 : 0;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
int do_X509_REQ_sign(BIO *err, X509_REQ *x, EVP_PKEY *pkey, const EVP_MD *md,
 | 
			
		||||
                     STACK_OF(OPENSSL_STRING) *sigopts)
 | 
			
		||||
{
 | 
			
		||||
    int rv;
 | 
			
		||||
    EVP_MD_CTX mctx;
 | 
			
		||||
    EVP_MD_CTX_init(&mctx);
 | 
			
		||||
    rv = do_sign_init(err, &mctx, pkey, md, sigopts);
 | 
			
		||||
    if (rv > 0)
 | 
			
		||||
        rv = X509_REQ_sign_ctx(x, &mctx);
 | 
			
		||||
    EVP_MD_CTX_cleanup(&mctx);
 | 
			
		||||
    return rv > 0 ? 1 : 0;
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
int do_X509_CRL_sign(BIO *err, X509_CRL *x, EVP_PKEY *pkey, const EVP_MD *md,
 | 
			
		||||
                     STACK_OF(OPENSSL_STRING) *sigopts)
 | 
			
		||||
{
 | 
			
		||||
    int rv;
 | 
			
		||||
    EVP_MD_CTX mctx;
 | 
			
		||||
    EVP_MD_CTX_init(&mctx);
 | 
			
		||||
    rv = do_sign_init(err, &mctx, pkey, md, sigopts);
 | 
			
		||||
    if (rv > 0)
 | 
			
		||||
        rv = X509_CRL_sign_ctx(x, &mctx);
 | 
			
		||||
    EVP_MD_CTX_cleanup(&mctx);
 | 
			
		||||
    return rv > 0 ? 1 : 0;
 | 
			
		||||
}
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										62
									
								
								apps/rsa.c
									
									
									
									
									
								
							
							
						
						
									
										62
									
								
								apps/rsa.c
									
									
									
									
									
								
							@@ -116,8 +116,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
# endif
 | 
			
		||||
    int modulus = 0;
 | 
			
		||||
 | 
			
		||||
    int pvk_encr = 2;
 | 
			
		||||
 | 
			
		||||
    apps_startup();
 | 
			
		||||
 | 
			
		||||
    if (bio_err == NULL)
 | 
			
		||||
@@ -174,16 +172,6 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
            pubin = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-pubout") == 0)
 | 
			
		||||
            pubout = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-RSAPublicKey_in") == 0)
 | 
			
		||||
            pubin = 2;
 | 
			
		||||
        else if (strcmp(*argv, "-RSAPublicKey_out") == 0)
 | 
			
		||||
            pubout = 2;
 | 
			
		||||
        else if (strcmp(*argv, "-pvk-strong") == 0)
 | 
			
		||||
            pvk_encr = 2;
 | 
			
		||||
        else if (strcmp(*argv, "-pvk-weak") == 0)
 | 
			
		||||
            pvk_encr = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-pvk-none") == 0)
 | 
			
		||||
            pvk_encr = 0;
 | 
			
		||||
        else if (strcmp(*argv, "-noout") == 0)
 | 
			
		||||
            noout = 1;
 | 
			
		||||
        else if (strcmp(*argv, "-text") == 0)
 | 
			
		||||
@@ -273,28 +261,19 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    {
 | 
			
		||||
        EVP_PKEY *pkey;
 | 
			
		||||
 | 
			
		||||
        if (pubin) {
 | 
			
		||||
            int tmpformat = -1;
 | 
			
		||||
            if (pubin == 2) {
 | 
			
		||||
                if (informat == FORMAT_PEM)
 | 
			
		||||
                    tmpformat = FORMAT_PEMRSA;
 | 
			
		||||
                else if (informat == FORMAT_ASN1)
 | 
			
		||||
                    tmpformat = FORMAT_ASN1RSA;
 | 
			
		||||
            } else if (informat == FORMAT_NETSCAPE && sgckey)
 | 
			
		||||
                tmpformat = FORMAT_IISSGC;
 | 
			
		||||
            else
 | 
			
		||||
                tmpformat = informat;
 | 
			
		||||
 | 
			
		||||
            pkey = load_pubkey(bio_err, infile, tmpformat, 1,
 | 
			
		||||
        if (pubin)
 | 
			
		||||
            pkey = load_pubkey(bio_err, infile,
 | 
			
		||||
                               (informat == FORMAT_NETSCAPE && sgckey ?
 | 
			
		||||
                                FORMAT_IISSGC : informat), 1,
 | 
			
		||||
                               passin, e, "Public Key");
 | 
			
		||||
        } else
 | 
			
		||||
        else
 | 
			
		||||
            pkey = load_key(bio_err, infile,
 | 
			
		||||
                            (informat == FORMAT_NETSCAPE && sgckey ?
 | 
			
		||||
                             FORMAT_IISSGC : informat), 1,
 | 
			
		||||
                            passin, e, "Private Key");
 | 
			
		||||
 | 
			
		||||
        if (pkey != NULL)
 | 
			
		||||
            rsa = EVP_PKEY_get1_RSA(pkey);
 | 
			
		||||
            rsa = pkey == NULL ? NULL : EVP_PKEY_get1_RSA(pkey);
 | 
			
		||||
        EVP_PKEY_free(pkey);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
@@ -362,12 +341,9 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
    BIO_printf(bio_err, "writing RSA key\n");
 | 
			
		||||
    if (outformat == FORMAT_ASN1) {
 | 
			
		||||
        if (pubout || pubin) {
 | 
			
		||||
            if (pubout == 2)
 | 
			
		||||
                i = i2d_RSAPublicKey_bio(out, rsa);
 | 
			
		||||
            else
 | 
			
		||||
        if (pubout || pubin)
 | 
			
		||||
            i = i2d_RSA_PUBKEY_bio(out, rsa);
 | 
			
		||||
        } else
 | 
			
		||||
        else
 | 
			
		||||
            i = i2d_RSAPrivateKey_bio(out, rsa);
 | 
			
		||||
    }
 | 
			
		||||
# ifndef OPENSSL_NO_RC4
 | 
			
		||||
@@ -388,32 +364,16 @@ int MAIN(int argc, char **argv)
 | 
			
		||||
    }
 | 
			
		||||
# endif
 | 
			
		||||
    else if (outformat == FORMAT_PEM) {
 | 
			
		||||
        if (pubout || pubin) {
 | 
			
		||||
            if (pubout == 2)
 | 
			
		||||
                i = PEM_write_bio_RSAPublicKey(out, rsa);
 | 
			
		||||
            else
 | 
			
		||||
        if (pubout || pubin)
 | 
			
		||||
            i = PEM_write_bio_RSA_PUBKEY(out, rsa);
 | 
			
		||||
        } else
 | 
			
		||||
        else
 | 
			
		||||
            i = PEM_write_bio_RSAPrivateKey(out, rsa,
 | 
			
		||||
                                            enc, NULL, 0, NULL, passout);
 | 
			
		||||
# if !defined(OPENSSL_NO_DSA) && !defined(OPENSSL_NO_RC4)
 | 
			
		||||
    } else if (outformat == FORMAT_MSBLOB || outformat == FORMAT_PVK) {
 | 
			
		||||
        EVP_PKEY *pk;
 | 
			
		||||
        pk = EVP_PKEY_new();
 | 
			
		||||
        EVP_PKEY_set1_RSA(pk, rsa);
 | 
			
		||||
        if (outformat == FORMAT_PVK)
 | 
			
		||||
            i = i2b_PVK_bio(out, pk, pvk_encr, 0, passout);
 | 
			
		||||
        else if (pubin || pubout)
 | 
			
		||||
            i = i2b_PublicKey_bio(out, pk);
 | 
			
		||||
        else
 | 
			
		||||
            i = i2b_PrivateKey_bio(out, pk);
 | 
			
		||||
        EVP_PKEY_free(pk);
 | 
			
		||||
# endif
 | 
			
		||||
    } else {
 | 
			
		||||
        BIO_printf(bio_err, "bad output format specified for outfile\n");
 | 
			
		||||
        goto end;
 | 
			
		||||
    }
 | 
			
		||||
    if (i <= 0) {
 | 
			
		||||
    if (!i) {
 | 
			
		||||
        BIO_printf(bio_err, "unable to write key\n");
 | 
			
		||||
        ERR_print_errors(bio_err);
 | 
			
		||||
    } else
 | 
			
		||||
 
 | 
			
		||||
@@ -361,10 +361,4 @@ static void usage()
 | 
			
		||||
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#else                           /* !OPENSSL_NO_RSA */
 | 
			
		||||
 | 
			
		||||
# if PEDANTIC
 | 
			
		||||
static void *dummy = &dummy;
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
@@ -118,7 +118,7 @@
 | 
			
		||||
# include <conio.h>
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
#if defined(OPENSSL_SYS_MSDOS) && !defined(_WIN32)
 | 
			
		||||
#ifdef OPENSSL_SYS_MSDOS
 | 
			
		||||
# define _kbhit kbhit
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
@@ -152,70 +152,33 @@ typedef fd_mask fd_set;
 | 
			
		||||
#define PROTOCOL        "tcp"
 | 
			
		||||
 | 
			
		||||
int do_server(int port, int type, int *ret,
 | 
			
		||||
              int (*cb) (char *hostname, int s, int stype,
 | 
			
		||||
                         unsigned char *context), unsigned char *context,
 | 
			
		||||
              int naccept);
 | 
			
		||||
#ifndef NO_SYS_UN_H
 | 
			
		||||
int do_server_unix(const char *path, int *ret,
 | 
			
		||||
                   int (*cb) (char *hostname, int s, int stype,
 | 
			
		||||
                              unsigned char *context), unsigned char *context,
 | 
			
		||||
                   int naccept);
 | 
			
		||||
#endif
 | 
			
		||||
              int (*cb) (char *hostname, int s, unsigned char *context),
 | 
			
		||||
              unsigned char *context);
 | 
			
		||||
#ifdef HEADER_X509_H
 | 
			
		||||
int verify_callback(int ok, X509_STORE_CTX *ctx);
 | 
			
		||||
int MS_CALLBACK verify_callback(int ok, X509_STORE_CTX *ctx);
 | 
			
		||||
#endif
 | 
			
		||||
#ifdef HEADER_SSL_H
 | 
			
		||||
int set_cert_stuff(SSL_CTX *ctx, char *cert_file, char *key_file);
 | 
			
		||||
int set_cert_key_stuff(SSL_CTX *ctx, X509 *cert, EVP_PKEY *key,
 | 
			
		||||
                       STACK_OF(X509) *chain, int build_chain);
 | 
			
		||||
int ssl_print_sigalgs(BIO *out, SSL *s);
 | 
			
		||||
int ssl_print_point_formats(BIO *out, SSL *s);
 | 
			
		||||
int ssl_print_curves(BIO *out, SSL *s, int noshared);
 | 
			
		||||
#endif
 | 
			
		||||
int ssl_print_tmp_key(BIO *out, SSL *s);
 | 
			
		||||
int init_client(int *sock, const char *server, int port, int type);
 | 
			
		||||
#ifndef NO_SYS_UN_H
 | 
			
		||||
int init_client_unix(int *sock, const char *server);
 | 
			
		||||
int set_cert_key_stuff(SSL_CTX *ctx, X509 *cert, EVP_PKEY *key);
 | 
			
		||||
#endif
 | 
			
		||||
int init_client(int *sock, char *server, int port, int type);
 | 
			
		||||
int should_retry(int i);
 | 
			
		||||
int extract_port(const char *str, short *port_ptr);
 | 
			
		||||
int extract_port(char *str, short *port_ptr);
 | 
			
		||||
int extract_host_port(char *str, char **host_ptr, unsigned char *ip,
 | 
			
		||||
                      short *p);
 | 
			
		||||
 | 
			
		||||
long bio_dump_callback(BIO *bio, int cmd, const char *argp,
 | 
			
		||||
long MS_CALLBACK bio_dump_callback(BIO *bio, int cmd, const char *argp,
 | 
			
		||||
                                   int argi, long argl, long ret);
 | 
			
		||||
 | 
			
		||||
#ifdef HEADER_SSL_H
 | 
			
		||||
void apps_ssl_info_callback(const SSL *s, int where, int ret);
 | 
			
		||||
void msg_cb(int write_p, int version, int content_type, const void *buf,
 | 
			
		||||
            size_t len, SSL *ssl, void *arg);
 | 
			
		||||
void tlsext_cb(SSL *s, int client_server, int type, unsigned char *data,
 | 
			
		||||
               int len, void *arg);
 | 
			
		||||
void MS_CALLBACK apps_ssl_info_callback(const SSL *s, int where, int ret);
 | 
			
		||||
void MS_CALLBACK msg_cb(int write_p, int version, int content_type,
 | 
			
		||||
                        const void *buf, size_t len, SSL *ssl, void *arg);
 | 
			
		||||
void MS_CALLBACK tlsext_cb(SSL *s, int client_server, int type,
 | 
			
		||||
                           unsigned char *data, int len, void *arg);
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
int generate_cookie_callback(SSL *ssl, unsigned char *cookie,
 | 
			
		||||
int MS_CALLBACK generate_cookie_callback(SSL *ssl, unsigned char *cookie,
 | 
			
		||||
                                         unsigned int *cookie_len);
 | 
			
		||||
int verify_cookie_callback(SSL *ssl, unsigned char *cookie,
 | 
			
		||||
int MS_CALLBACK verify_cookie_callback(SSL *ssl, unsigned char *cookie,
 | 
			
		||||
                                       unsigned int cookie_len);
 | 
			
		||||
 | 
			
		||||
typedef struct ssl_excert_st SSL_EXCERT;
 | 
			
		||||
 | 
			
		||||
void ssl_ctx_set_excert(SSL_CTX *ctx, SSL_EXCERT *exc);
 | 
			
		||||
void ssl_excert_free(SSL_EXCERT *exc);
 | 
			
		||||
int args_excert(char ***pargs, int *pargc,
 | 
			
		||||
                int *badarg, BIO *err, SSL_EXCERT **pexc);
 | 
			
		||||
int load_excert(SSL_EXCERT **pexc, BIO *err);
 | 
			
		||||
void print_ssl_summary(BIO *bio, SSL *s);
 | 
			
		||||
#ifdef HEADER_SSL_H
 | 
			
		||||
int args_ssl(char ***pargs, int *pargc, SSL_CONF_CTX *cctx,
 | 
			
		||||
             int *badarg, BIO *err, STACK_OF(OPENSSL_STRING) **pstr);
 | 
			
		||||
int args_ssl_call(SSL_CTX *ctx, BIO *err, SSL_CONF_CTX *cctx,
 | 
			
		||||
                  STACK_OF(OPENSSL_STRING) *str, int no_ecdhe, int no_jpake);
 | 
			
		||||
int ssl_ctx_add_crls(SSL_CTX *ctx, STACK_OF(X509_CRL) *crls,
 | 
			
		||||
                     int crl_download);
 | 
			
		||||
int ssl_load_stores(SSL_CTX *ctx, const char *vfyCApath,
 | 
			
		||||
                    const char *vfyCAfile, const char *chCApath,
 | 
			
		||||
                    const char *chCAfile, STACK_OF(X509_CRL) *crls,
 | 
			
		||||
                    int crl_download);
 | 
			
		||||
void ssl_ctx_security_debug(SSL_CTX *ctx, BIO *out, int verbose);
 | 
			
		||||
#endif
 | 
			
		||||
 
 | 
			
		||||
							
								
								
									
										1278
									
								
								apps/s_cb.c
									
									
									
									
									
								
							
							
						
						
									
										1278
									
								
								apps/s_cb.c
									
									
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										1068
									
								
								apps/s_client.c
									
									
									
									
									
								
							
							
						
						
									
										1068
									
								
								apps/s_client.c
									
									
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										1510
									
								
								apps/s_server.c
									
									
									
									
									
								
							
							
						
						
									
										1510
									
								
								apps/s_server.c
									
									
									
									
									
								
							
										
											
												File diff suppressed because it is too large
												Load Diff
											
										
									
								
							
							
								
								
									
										251
									
								
								apps/s_socket.c
									
									
									
									
									
								
							
							
						
						
									
										251
									
								
								apps/s_socket.c
									
									
									
									
									
								
							@@ -64,6 +64,12 @@
 | 
			
		||||
#include <errno.h>
 | 
			
		||||
#include <signal.h>
 | 
			
		||||
 | 
			
		||||
#ifdef FLAT_INC
 | 
			
		||||
# include "e_os2.h"
 | 
			
		||||
#else
 | 
			
		||||
# include "../e_os2.h"
 | 
			
		||||
#endif
 | 
			
		||||
 | 
			
		||||
/*
 | 
			
		||||
 * With IPv6, it looks like Digital has mixed up the proper order of
 | 
			
		||||
 * recursive header file inclusion, resulting in the compiler complaining
 | 
			
		||||
@@ -95,20 +101,21 @@ typedef unsigned int u_int;
 | 
			
		||||
#  include "netdb.h"
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
static struct hostent *GetHostByName(const char *name);
 | 
			
		||||
static struct hostent *GetHostByName(char *name);
 | 
			
		||||
# if defined(OPENSSL_SYS_WINDOWS) || (defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK))
 | 
			
		||||
static void ssl_sock_cleanup(void);
 | 
			
		||||
# endif
 | 
			
		||||
static int ssl_sock_init(void);
 | 
			
		||||
static int init_client_ip(int *sock, const unsigned char ip[4], int port,
 | 
			
		||||
                          int type);
 | 
			
		||||
static int init_client_ip(int *sock, unsigned char ip[4], int port, int type);
 | 
			
		||||
static int init_server(int *sock, int port, int type);
 | 
			
		||||
static int init_server_long(int *sock, int port, char *ip, int type);
 | 
			
		||||
static int do_accept(int acc_sock, int *sock, char **host);
 | 
			
		||||
static int host_ip(const char *str, unsigned char ip[4]);
 | 
			
		||||
# ifndef NO_SYS_UN_H
 | 
			
		||||
static int init_server_unix(int *sock, const char *path);
 | 
			
		||||
static int do_accept_unix(int acc_sock, int *sock);
 | 
			
		||||
static int host_ip(char *str, unsigned char ip[4]);
 | 
			
		||||
 | 
			
		||||
# ifdef OPENSSL_SYS_WIN16
 | 
			
		||||
#  define SOCKET_PROTOCOL 0     /* more microsoft stupidity */
 | 
			
		||||
# else
 | 
			
		||||
#  define SOCKET_PROTOCOL IPPROTO_TCP
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
# if defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK)
 | 
			
		||||
@@ -119,6 +126,34 @@ static int wsa_init_done = 0;
 | 
			
		||||
static struct WSAData wsa_state;
 | 
			
		||||
static int wsa_init_done = 0;
 | 
			
		||||
 | 
			
		||||
#  ifdef OPENSSL_SYS_WIN16
 | 
			
		||||
static HWND topWnd = 0;
 | 
			
		||||
static FARPROC lpTopWndProc = NULL;
 | 
			
		||||
static FARPROC lpTopHookProc = NULL;
 | 
			
		||||
extern HINSTANCE _hInstance;    /* nice global CRT provides */
 | 
			
		||||
 | 
			
		||||
static LONG FAR PASCAL topHookProc(HWND hwnd, UINT message, WPARAM wParam,
 | 
			
		||||
                                   LPARAM lParam)
 | 
			
		||||
{
 | 
			
		||||
    if (hwnd == topWnd) {
 | 
			
		||||
        switch (message) {
 | 
			
		||||
        case WM_DESTROY:
 | 
			
		||||
        case WM_CLOSE:
 | 
			
		||||
            SetWindowLong(topWnd, GWL_WNDPROC, (LONG) lpTopWndProc);
 | 
			
		||||
            ssl_sock_cleanup();
 | 
			
		||||
            break;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
    return CallWindowProc(lpTopWndProc, hwnd, message, wParam, lParam);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static BOOL CALLBACK enumproc(HWND hwnd, LPARAM lParam)
 | 
			
		||||
{
 | 
			
		||||
    topWnd = hwnd;
 | 
			
		||||
    return (FALSE);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
#  endif                        /* OPENSSL_SYS_WIN32 */
 | 
			
		||||
# endif                         /* OPENSSL_SYS_WINDOWS */
 | 
			
		||||
 | 
			
		||||
# ifdef OPENSSL_SYS_WINDOWS
 | 
			
		||||
@@ -164,6 +199,13 @@ static int ssl_sock_init(void)
 | 
			
		||||
                       err);
 | 
			
		||||
            return (0);
 | 
			
		||||
        }
 | 
			
		||||
#  ifdef OPENSSL_SYS_WIN16
 | 
			
		||||
        EnumTaskWindows(GetCurrentTask(), enumproc, 0L);
 | 
			
		||||
        lpTopWndProc = (FARPROC) GetWindowLong(topWnd, GWL_WNDPROC);
 | 
			
		||||
        lpTopHookProc = MakeProcInstance((FARPROC) topHookProc, _hInstance);
 | 
			
		||||
 | 
			
		||||
        SetWindowLong(topWnd, GWL_WNDPROC, (LONG) lpTopHookProc);
 | 
			
		||||
#  endif                        /* OPENSSL_SYS_WIN16 */
 | 
			
		||||
    }
 | 
			
		||||
# elif defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK)
 | 
			
		||||
    WORD wVerReq;
 | 
			
		||||
@@ -189,18 +231,20 @@ static int ssl_sock_init(void)
 | 
			
		||||
    return (1);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
int init_client(int *sock, const char *host, int port, int type)
 | 
			
		||||
int init_client(int *sock, char *host, int port, int type)
 | 
			
		||||
{
 | 
			
		||||
    unsigned char ip[4];
 | 
			
		||||
    short p = 0;
 | 
			
		||||
 | 
			
		||||
    ip[0] = ip[1] = ip[2] = ip[3] = 0;
 | 
			
		||||
    if (!host_ip(host, &(ip[0])))
 | 
			
		||||
        return 0;
 | 
			
		||||
    return init_client_ip(sock, ip, port, type);
 | 
			
		||||
    if (!host_ip(host, &(ip[0]))) {
 | 
			
		||||
        return (0);
 | 
			
		||||
    }
 | 
			
		||||
    if (p != 0)
 | 
			
		||||
        port = p;
 | 
			
		||||
    return (init_client_ip(sock, ip, port, type));
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int init_client_ip(int *sock, const unsigned char ip[4], int port,
 | 
			
		||||
                          int type)
 | 
			
		||||
static int init_client_ip(int *sock, unsigned char ip[4], int port, int type)
 | 
			
		||||
{
 | 
			
		||||
    unsigned long addr;
 | 
			
		||||
    struct sockaddr_in them;
 | 
			
		||||
@@ -219,7 +263,7 @@ static int init_client_ip(int *sock, const unsigned char ip[4], int port,
 | 
			
		||||
    them.sin_addr.s_addr = htonl(addr);
 | 
			
		||||
 | 
			
		||||
    if (type == SOCK_STREAM)
 | 
			
		||||
        s = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
 | 
			
		||||
        s = socket(AF_INET, SOCK_STREAM, SOCKET_PROTOCOL);
 | 
			
		||||
    else                        /* ( type == SOCK_DGRAM) */
 | 
			
		||||
        s = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP);
 | 
			
		||||
 | 
			
		||||
@@ -227,12 +271,11 @@ static int init_client_ip(int *sock, const unsigned char ip[4], int port,
 | 
			
		||||
        perror("socket");
 | 
			
		||||
        return (0);
 | 
			
		||||
    }
 | 
			
		||||
# if defined(SO_KEEPALIVE)
 | 
			
		||||
# ifndef OPENSSL_SYS_MPE
 | 
			
		||||
    if (type == SOCK_STREAM) {
 | 
			
		||||
        i = 0;
 | 
			
		||||
        i = setsockopt(s, SOL_SOCKET, SO_KEEPALIVE, (char *)&i, sizeof(i));
 | 
			
		||||
        if (i < 0) {
 | 
			
		||||
            closesocket(s);
 | 
			
		||||
            perror("keepalive");
 | 
			
		||||
            return (0);
 | 
			
		||||
        }
 | 
			
		||||
@@ -240,7 +283,7 @@ static int init_client_ip(int *sock, const unsigned char ip[4], int port,
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
    if (connect(s, (struct sockaddr *)&them, sizeof(them)) == -1) {
 | 
			
		||||
        closesocket(s);
 | 
			
		||||
        close(s);
 | 
			
		||||
        perror("connect");
 | 
			
		||||
        return (0);
 | 
			
		||||
    }
 | 
			
		||||
@@ -248,45 +291,13 @@ static int init_client_ip(int *sock, const unsigned char ip[4], int port,
 | 
			
		||||
    return (1);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# ifndef NO_SYS_UN_H
 | 
			
		||||
int init_client_unix(int *sock, const char *server)
 | 
			
		||||
{
 | 
			
		||||
    struct sockaddr_un them;
 | 
			
		||||
    int s;
 | 
			
		||||
 | 
			
		||||
    if (strlen(server) > (UNIX_PATH_MAX + 1))
 | 
			
		||||
        return (0);
 | 
			
		||||
    if (!ssl_sock_init())
 | 
			
		||||
        return (0);
 | 
			
		||||
 | 
			
		||||
    s = socket(AF_UNIX, SOCK_STREAM, 0);
 | 
			
		||||
    if (s == INVALID_SOCKET) {
 | 
			
		||||
        perror("socket");
 | 
			
		||||
        return (0);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    memset((char *)&them, 0, sizeof(them));
 | 
			
		||||
    them.sun_family = AF_UNIX;
 | 
			
		||||
    strcpy(them.sun_path, server);
 | 
			
		||||
 | 
			
		||||
    if (connect(s, (struct sockaddr *)&them, sizeof(them)) == -1) {
 | 
			
		||||
        closesocket(s);
 | 
			
		||||
        perror("connect");
 | 
			
		||||
        return (0);
 | 
			
		||||
    }
 | 
			
		||||
    *sock = s;
 | 
			
		||||
    return (1);
 | 
			
		||||
}
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
int do_server(int port, int type, int *ret,
 | 
			
		||||
              int (*cb) (char *hostname, int s, int stype,
 | 
			
		||||
                         unsigned char *context), unsigned char *context,
 | 
			
		||||
              int naccept)
 | 
			
		||||
              int (*cb) (char *hostname, int s, unsigned char *context),
 | 
			
		||||
              unsigned char *context)
 | 
			
		||||
{
 | 
			
		||||
    int sock;
 | 
			
		||||
    char *name = NULL;
 | 
			
		||||
    int accept_socket = 0;
 | 
			
		||||
    int accept_socket;
 | 
			
		||||
    int i;
 | 
			
		||||
 | 
			
		||||
    if (!init_server(&accept_socket, port, type))
 | 
			
		||||
@@ -298,67 +309,24 @@ int do_server(int port, int type, int *ret,
 | 
			
		||||
    }
 | 
			
		||||
    for (;;) {
 | 
			
		||||
        if (type == SOCK_STREAM) {
 | 
			
		||||
# ifdef OPENSSL_SSL_DEBUG_BROKEN_PROTOCOL
 | 
			
		||||
            if (do_accept(accept_socket, &sock, NULL) == 0)
 | 
			
		||||
# else
 | 
			
		||||
            if (do_accept(accept_socket, &sock, &name) == 0)
 | 
			
		||||
# endif
 | 
			
		||||
            {
 | 
			
		||||
            if (do_accept(accept_socket, &sock, &name) == 0) {
 | 
			
		||||
                SHUTDOWN(accept_socket);
 | 
			
		||||
                return (0);
 | 
			
		||||
            }
 | 
			
		||||
        } else
 | 
			
		||||
            sock = accept_socket;
 | 
			
		||||
        i = (*cb) (name, sock, type, context);
 | 
			
		||||
        i = (*cb) (name, sock, context);
 | 
			
		||||
        if (name != NULL)
 | 
			
		||||
            OPENSSL_free(name);
 | 
			
		||||
        if (type == SOCK_STREAM)
 | 
			
		||||
            SHUTDOWN2(sock);
 | 
			
		||||
        if (naccept != -1)
 | 
			
		||||
            naccept--;
 | 
			
		||||
        if (i < 0 || naccept == 0) {
 | 
			
		||||
        if (i < 0) {
 | 
			
		||||
            SHUTDOWN2(accept_socket);
 | 
			
		||||
            return (i);
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# ifndef NO_SYS_UN_H
 | 
			
		||||
int do_server_unix(const char *path, int *ret,
 | 
			
		||||
                   int (*cb) (char *hostname, int s, int stype,
 | 
			
		||||
                              unsigned char *context), unsigned char *context,
 | 
			
		||||
                   int naccept)
 | 
			
		||||
{
 | 
			
		||||
    int sock;
 | 
			
		||||
    int accept_socket = 0;
 | 
			
		||||
    int i;
 | 
			
		||||
 | 
			
		||||
    if (!init_server_unix(&accept_socket, path))
 | 
			
		||||
        return (0);
 | 
			
		||||
 | 
			
		||||
    if (ret != NULL)
 | 
			
		||||
        *ret = accept_socket;
 | 
			
		||||
    for (;;) {
 | 
			
		||||
        if (do_accept_unix(accept_socket, &sock) == 0) {
 | 
			
		||||
            SHUTDOWN(accept_socket);
 | 
			
		||||
            i = 0;
 | 
			
		||||
            goto out;
 | 
			
		||||
        }
 | 
			
		||||
        i = (*cb) (NULL, sock, 0, context);
 | 
			
		||||
        SHUTDOWN2(sock);
 | 
			
		||||
        if (naccept != -1)
 | 
			
		||||
            naccept--;
 | 
			
		||||
        if (i < 0 || naccept == 0) {
 | 
			
		||||
            SHUTDOWN2(accept_socket);
 | 
			
		||||
            goto out;
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
 out:
 | 
			
		||||
    unlink(path);
 | 
			
		||||
    return (i);
 | 
			
		||||
}
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
static int init_server_long(int *sock, int port, char *ip, int type)
 | 
			
		||||
{
 | 
			
		||||
    int ret = 0;
 | 
			
		||||
@@ -382,7 +350,7 @@ static int init_server_long(int *sock, int port, char *ip, int type)
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
    if (type == SOCK_STREAM)
 | 
			
		||||
        s = socket(AF_INET, SOCK_STREAM, IPPROTO_TCP);
 | 
			
		||||
        s = socket(AF_INET, SOCK_STREAM, SOCKET_PROTOCOL);
 | 
			
		||||
    else                        /* type == SOCK_DGRAM */
 | 
			
		||||
        s = socket(AF_INET, SOCK_DGRAM, IPPROTO_UDP);
 | 
			
		||||
 | 
			
		||||
@@ -417,50 +385,6 @@ static int init_server(int *sock, int port, int type)
 | 
			
		||||
    return (init_server_long(sock, port, NULL, type));
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# ifndef NO_SYS_UN_H
 | 
			
		||||
static int init_server_unix(int *sock, const char *path)
 | 
			
		||||
{
 | 
			
		||||
    int ret = 0;
 | 
			
		||||
    struct sockaddr_un server;
 | 
			
		||||
    int s = -1;
 | 
			
		||||
 | 
			
		||||
    if (strlen(path) > (UNIX_PATH_MAX + 1))
 | 
			
		||||
        return (0);
 | 
			
		||||
    if (!ssl_sock_init())
 | 
			
		||||
        return (0);
 | 
			
		||||
 | 
			
		||||
    s = socket(AF_UNIX, SOCK_STREAM, 0);
 | 
			
		||||
    if (s == INVALID_SOCKET)
 | 
			
		||||
        goto err;
 | 
			
		||||
 | 
			
		||||
    memset((char *)&server, 0, sizeof(server));
 | 
			
		||||
    server.sun_family = AF_UNIX;
 | 
			
		||||
    strcpy(server.sun_path, path);
 | 
			
		||||
 | 
			
		||||
    if (bind(s, (struct sockaddr *)&server, sizeof(server)) == -1) {
 | 
			
		||||
#  ifndef OPENSSL_SYS_WINDOWS
 | 
			
		||||
        perror("bind");
 | 
			
		||||
#  endif
 | 
			
		||||
        goto err;
 | 
			
		||||
    }
 | 
			
		||||
    /* Make it 128 for linux */
 | 
			
		||||
    if (listen(s, 128) == -1) {
 | 
			
		||||
#  ifndef OPENSSL_SYS_WINDOWS
 | 
			
		||||
        perror("listen");
 | 
			
		||||
#  endif
 | 
			
		||||
        unlink(path);
 | 
			
		||||
        goto err;
 | 
			
		||||
    }
 | 
			
		||||
    *sock = s;
 | 
			
		||||
    ret = 1;
 | 
			
		||||
 err:
 | 
			
		||||
    if ((ret == 0) && (s != -1)) {
 | 
			
		||||
        SHUTDOWN(s);
 | 
			
		||||
    }
 | 
			
		||||
    return (ret);
 | 
			
		||||
}
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
static int do_accept(int acc_sock, int *sock, char **host)
 | 
			
		||||
{
 | 
			
		||||
    int ret;
 | 
			
		||||
@@ -530,7 +454,6 @@ static int do_accept(int acc_sock, int *sock, char **host)
 | 
			
		||||
    } else {
 | 
			
		||||
        if ((*host = (char *)OPENSSL_malloc(strlen(h1->h_name) + 1)) == NULL) {
 | 
			
		||||
            perror("OPENSSL_malloc");
 | 
			
		||||
            closesocket(ret);
 | 
			
		||||
            return (0);
 | 
			
		||||
        }
 | 
			
		||||
        BUF_strlcpy(*host, h1->h_name, strlen(h1->h_name) + 1);
 | 
			
		||||
@@ -538,12 +461,10 @@ static int do_accept(int acc_sock, int *sock, char **host)
 | 
			
		||||
        h2 = GetHostByName(*host);
 | 
			
		||||
        if (h2 == NULL) {
 | 
			
		||||
            BIO_printf(bio_err, "gethostbyname failure\n");
 | 
			
		||||
            closesocket(ret);
 | 
			
		||||
            return (0);
 | 
			
		||||
        }
 | 
			
		||||
        if (h2->h_addrtype != AF_INET) {
 | 
			
		||||
            BIO_printf(bio_err, "gethostbyname addr is not AF_INET\n");
 | 
			
		||||
            closesocket(ret);
 | 
			
		||||
            return (0);
 | 
			
		||||
        }
 | 
			
		||||
    }
 | 
			
		||||
@@ -552,33 +473,6 @@ static int do_accept(int acc_sock, int *sock, char **host)
 | 
			
		||||
    return (1);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
# ifndef NO_SYS_UN_H
 | 
			
		||||
static int do_accept_unix(int acc_sock, int *sock)
 | 
			
		||||
{
 | 
			
		||||
    int ret;
 | 
			
		||||
 | 
			
		||||
    if (!ssl_sock_init())
 | 
			
		||||
        return (0);
 | 
			
		||||
 | 
			
		||||
 redoit:
 | 
			
		||||
    ret = accept(acc_sock, NULL, NULL);
 | 
			
		||||
    if (ret == INVALID_SOCKET) {
 | 
			
		||||
        if (errno == EINTR) {
 | 
			
		||||
            /*
 | 
			
		||||
             * check_timeout();
 | 
			
		||||
             */
 | 
			
		||||
            goto redoit;
 | 
			
		||||
        }
 | 
			
		||||
        fprintf(stderr, "errno=%d ", errno);
 | 
			
		||||
        perror("accept");
 | 
			
		||||
        return (0);
 | 
			
		||||
    }
 | 
			
		||||
 | 
			
		||||
    *sock = ret;
 | 
			
		||||
    return (1);
 | 
			
		||||
}
 | 
			
		||||
# endif
 | 
			
		||||
 | 
			
		||||
int extract_host_port(char *str, char **host_ptr, unsigned char *ip,
 | 
			
		||||
                      short *port_ptr)
 | 
			
		||||
{
 | 
			
		||||
@@ -604,7 +498,7 @@ int extract_host_port(char *str, char **host_ptr, unsigned char *ip,
 | 
			
		||||
    return (0);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
static int host_ip(const char *str, unsigned char ip[4])
 | 
			
		||||
static int host_ip(char *str, unsigned char ip[4])
 | 
			
		||||
{
 | 
			
		||||
    unsigned int in[4];
 | 
			
		||||
    int i;
 | 
			
		||||
@@ -631,7 +525,8 @@ static int host_ip(const char *str, unsigned char ip[4])
 | 
			
		||||
            BIO_printf(bio_err, "gethostbyname failure\n");
 | 
			
		||||
            goto err;
 | 
			
		||||
        }
 | 
			
		||||
        if (he->h_addrtype != AF_INET) {
 | 
			
		||||
        /* cast to short because of win16 winsock definition */
 | 
			
		||||
        if ((short)he->h_addrtype != AF_INET) {
 | 
			
		||||
            BIO_printf(bio_err, "gethostbyname addr is not AF_INET\n");
 | 
			
		||||
            return (0);
 | 
			
		||||
        }
 | 
			
		||||
@@ -645,7 +540,7 @@ static int host_ip(const char *str, unsigned char ip[4])
 | 
			
		||||
    return (0);
 | 
			
		||||
}
 | 
			
		||||
 | 
			
		||||
int extract_port(const char *str, short *port_ptr)
 | 
			
		||||
int extract_port(char *str, short *port_ptr)
 | 
			
		||||
{
 | 
			
		||||
    int i;
 | 
			
		||||
    struct servent *s;
 | 
			
		||||
@@ -674,7 +569,7 @@ static struct ghbn_cache_st {
 | 
			
		||||
static unsigned long ghbn_hits = 0L;
 | 
			
		||||
static unsigned long ghbn_miss = 0L;
 | 
			
		||||
 | 
			
		||||
static struct hostent *GetHostByName(const char *name)
 | 
			
		||||
static struct hostent *GetHostByName(char *name)
 | 
			
		||||
{
 | 
			
		||||
    struct hostent *ret;
 | 
			
		||||
    int i, lowi = 0;
 | 
			
		||||
 
 | 
			
		||||
Some files were not shown because too many files have changed in this diff Show More
		Reference in New Issue
	
	Block a user