Leaked source code of windows server 2003
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.

5122 lines
126 KiB

  1. //+-------------------------------------------------------------------------n-
  2. //
  3. // Microsoft Windows
  4. // Copyright (C) Microsoft Corporation, 1996 - 1999
  5. //
  6. // File: crl.cpp
  7. //
  8. // Contents: Cert Server CRL processing
  9. //
  10. //---------------------------------------------------------------------------
  11. #include <pch.cpp>
  12. #pragma hdrstop
  13. #include <stdio.h>
  14. #include <esent.h>
  15. #include "cscom.h"
  16. #include "csprop.h"
  17. #include "dbtable.h"
  18. #include "resource.h"
  19. #include "elog.h"
  20. #include "certlog.h"
  21. #include <winldap.h>
  22. #include "csldap.h"
  23. #include "cainfop.h"
  24. #define __dwFILE__ __dwFILE_CERTSRV_CRL_CPP__
  25. HANDLE g_hCRLManualPublishEvent = NULL;
  26. FILETIME g_ftCRLNextPublish;
  27. FILETIME g_ftDeltaCRLNextPublish;
  28. BOOL g_fCRLPublishDisabled = FALSE; // manual publishing always allowed
  29. BOOL g_fDeltaCRLPublishDisabled = FALSE; // controls manual publishing, too
  30. DWORD g_dwCRLFlags = CRLF_DELETE_EXPIRED_CRLS;
  31. LDAP *g_pld = NULL;
  32. typedef struct _CSMEMBLOCK
  33. {
  34. struct _CSMEMBLOCK *pNext;
  35. BYTE *pbFree;
  36. DWORD cbFree;
  37. } CSMEMBLOCK;
  38. #define CBMEMBLOCK 4096
  39. typedef struct _CSCRLELEMENT
  40. {
  41. USHORT usRevocationReason;
  42. USHORT uscbSerialNumber;
  43. BYTE *pbSerialNumber;
  44. FILETIME ftRevocationDate;
  45. } CSCRLELEMENT;
  46. // size the structure just under CBMEMBLOCK to keep it from being just over
  47. // a page size.
  48. #define CCRLELEMENT ((CBMEMBLOCK - 2 * sizeof(DWORD)) / sizeof(CSCRLELEMENT))
  49. typedef struct _CSCRLBLOCK
  50. {
  51. struct _CSCRLBLOCK *pNext;
  52. DWORD cCRLElement;
  53. CSCRLELEMENT aCRLElement[CCRLELEMENT];
  54. } CSCRLBLOCK;
  55. typedef struct _CSCRLREASON
  56. {
  57. struct _CSCRLREASON *pNext;
  58. DWORD RevocationReason;
  59. CERT_EXTENSION ExtReason;
  60. } CSCRLREASON;
  61. typedef struct _CSCRLPERIOD
  62. {
  63. LONG lCRLPeriodCount;
  64. ENUM_PERIOD enumCRLPeriod;
  65. DWORD dwCRLOverlapMinutes;
  66. } CSCRLPERIOD;
  67. #ifdef DBG_CERTSRV_DEBUG_PRINT
  68. # define DPT_DATE 1
  69. # define DPT_DELTA 2
  70. # define DPT_DELTASEC 3
  71. # define DPT_DELTAMS 4
  72. # define DBGPRINTTIME(pfDelta, pszName, Type, ft) \
  73. DbgPrintTime((pfDelta), (pszName), __LINE__, (Type), (ft))
  74. VOID
  75. DbgPrintTime(
  76. OPTIONAL IN BOOL const *pfDelta,
  77. IN char const *pszName,
  78. IN DWORD Line,
  79. IN DWORD Type,
  80. IN FILETIME ft)
  81. {
  82. HRESULT hr;
  83. WCHAR *pwszTime = NULL;
  84. WCHAR awc[1];
  85. LLFILETIME llft;
  86. llft.ft = ft;
  87. if (Type == DPT_DATE)
  88. {
  89. if (0 != llft.ll)
  90. {
  91. hr = myGMTFileTimeToWszLocalTime(&ft, TRUE, &pwszTime);
  92. _PrintIfError(hr, "myGMTFileTimeToWszLocalTime");
  93. }
  94. }
  95. else
  96. {
  97. if (DPT_DELTAMS == Type)
  98. {
  99. llft.ll /= 1000; // milliseconds to seconds
  100. Type = DPT_DELTASEC;
  101. }
  102. if (DPT_DELTASEC == Type)
  103. {
  104. llft.ll *= CVT_BASE; // seconds to FILETIME period
  105. }
  106. llft.ll = -llft.ll; // FILETIME Period must be negative
  107. if (0 != llft.ll)
  108. {
  109. hr = myFileTimePeriodToWszTimePeriod(
  110. &llft.ft,
  111. TRUE, // fExact
  112. &pwszTime);
  113. _PrintIfError(hr, "myFileTimePeriodToWszTimePeriod");
  114. }
  115. }
  116. if (NULL == pwszTime)
  117. {
  118. awc[0] = L'\0';
  119. pwszTime = awc;
  120. }
  121. DBGPRINT((
  122. DBG_SS_CERTSRVI,
  123. "%hs(%d):%hs time(%hs): %lx:%08lx %ws\n",
  124. "crl.cpp",
  125. Line,
  126. NULL == pfDelta? "" : (*pfDelta? " Delta CRL" : " Base CRL"),
  127. pszName,
  128. ft.dwHighDateTime,
  129. ft.dwLowDateTime,
  130. pwszTime));
  131. //error:
  132. if (NULL != pwszTime && awc != pwszTime)
  133. {
  134. LocalFree(pwszTime);
  135. }
  136. }
  137. VOID
  138. CertSrvDbgPrintTime(
  139. IN char const *pszDesc,
  140. IN FILETIME const *pftGMT)
  141. {
  142. HRESULT hr;
  143. WCHAR *pwszTime = NULL;
  144. WCHAR awc[1];
  145. hr = myGMTFileTimeToWszLocalTime(pftGMT, TRUE, &pwszTime);
  146. _PrintIfError(hr, "myGMTFileTimeToWszLocalTime");
  147. if (S_OK != hr)
  148. {
  149. awc[0] = L'\0';
  150. pwszTime = awc;
  151. }
  152. DBGPRINT((DBG_SS_CERTSRV, "%hs: %ws\n", pszDesc, pwszTime));
  153. //error:
  154. if (NULL != pwszTime && awc != pwszTime)
  155. {
  156. LocalFree(pwszTime);
  157. }
  158. }
  159. #else // DBG_CERTSRV_DEBUG_PRINT
  160. # define DBGPRINTTIME(pfDelta, pszName, Type, ft)
  161. #endif // DBG_CERTSRV_DEBUG_PRINT
  162. HRESULT
  163. crlMemBlockAlloc(
  164. IN OUT CSMEMBLOCK **ppBlock,
  165. IN DWORD cb,
  166. OUT BYTE **ppb)
  167. {
  168. HRESULT hr;
  169. CSMEMBLOCK *pBlock = *ppBlock;
  170. *ppb = NULL;
  171. cb = POINTERROUND(cb);
  172. if (NULL == pBlock || cb > pBlock->cbFree)
  173. {
  174. pBlock = (CSMEMBLOCK *) LocalAlloc(LMEM_FIXED, CBMEMBLOCK);
  175. if (NULL == pBlock)
  176. {
  177. hr = E_OUTOFMEMORY;
  178. _JumpError(hr, error, "LocalAlloc");
  179. }
  180. pBlock->pNext = *ppBlock;
  181. pBlock->pbFree = (BYTE *) Add2Ptr(pBlock, sizeof(CSMEMBLOCK));
  182. pBlock->cbFree = CBMEMBLOCK - sizeof(CSMEMBLOCK);
  183. *ppBlock = pBlock;
  184. }
  185. CSASSERT(cb <= pBlock->cbFree);
  186. *ppb = pBlock->pbFree;
  187. pBlock->pbFree += cb;
  188. pBlock->cbFree -= cb;
  189. hr = S_OK;
  190. error:
  191. return(hr);
  192. }
  193. VOID
  194. crlBlockListFree(
  195. IN OUT CSMEMBLOCK *pBlock)
  196. {
  197. CSMEMBLOCK *pBlockNext;
  198. while (NULL != pBlock)
  199. {
  200. pBlockNext = pBlock->pNext;
  201. LocalFree(pBlock);
  202. pBlock = pBlockNext;
  203. }
  204. }
  205. HRESULT
  206. crlElementAlloc(
  207. IN OUT CSCRLBLOCK **ppBlock,
  208. OUT CSCRLELEMENT **ppCRLElement)
  209. {
  210. HRESULT hr;
  211. CSCRLBLOCK *pBlock = *ppBlock;
  212. *ppCRLElement = NULL;
  213. if (NULL == pBlock ||
  214. ARRAYSIZE(pBlock->aCRLElement) <= pBlock->cCRLElement)
  215. {
  216. pBlock = (CSCRLBLOCK *) LocalAlloc(LMEM_FIXED, sizeof(*pBlock));
  217. if (NULL == pBlock)
  218. {
  219. hr = E_OUTOFMEMORY;
  220. _JumpError(hr, error, "LocalAlloc");
  221. }
  222. pBlock->pNext = *ppBlock;
  223. pBlock->cCRLElement = 0;
  224. *ppBlock = pBlock;
  225. }
  226. CSASSERT(ARRAYSIZE(pBlock->aCRLElement) > pBlock->cCRLElement);
  227. *ppCRLElement = &pBlock->aCRLElement[pBlock->cCRLElement++];
  228. hr = S_OK;
  229. error:
  230. return(hr);
  231. }
  232. VOID
  233. crlFreeCRLArray(
  234. IN OUT VOID *pvBlockSerial,
  235. IN OUT CRL_ENTRY *paCRL)
  236. {
  237. crlBlockListFree((CSMEMBLOCK *) pvBlockSerial);
  238. if (NULL != paCRL)
  239. {
  240. LocalFree(paCRL);
  241. }
  242. }
  243. HRESULT
  244. crlCreateCRLReason(
  245. IN OUT CSMEMBLOCK **ppBlock,
  246. IN OUT CSCRLREASON **ppReason,
  247. IN DWORD RevocationReason,
  248. OUT DWORD *pcExtension,
  249. OUT CERT_EXTENSION **ppExtension)
  250. {
  251. HRESULT hr;
  252. CSCRLREASON *pReason = *ppReason;
  253. BYTE *pbEncoded = NULL;
  254. DWORD cbEncoded;
  255. for (pReason = *ppReason; NULL != pReason; pReason = pReason->pNext)
  256. {
  257. if (RevocationReason == pReason->RevocationReason)
  258. {
  259. break;
  260. }
  261. }
  262. if (NULL == pReason)
  263. {
  264. if (!myEncodeObject(
  265. X509_ASN_ENCODING,
  266. X509_ENUMERATED,
  267. (const void *) &RevocationReason,
  268. 0,
  269. CERTLIB_USE_LOCALALLOC,
  270. &pbEncoded,
  271. &cbEncoded))
  272. {
  273. hr = myHLastError();
  274. _JumpError(hr, error, "myEncodeObject");
  275. }
  276. hr = crlMemBlockAlloc(
  277. ppBlock,
  278. sizeof(CSCRLREASON) + cbEncoded,
  279. (BYTE **) &pReason);
  280. _JumpIfError(hr, error, "crlMemBlockAlloc");
  281. pReason->pNext = *ppReason;
  282. pReason->RevocationReason = RevocationReason;
  283. pReason->ExtReason.pszObjId = szOID_CRL_REASON_CODE;
  284. pReason->ExtReason.fCritical = FALSE;
  285. pReason->ExtReason.Value.pbData =
  286. (BYTE *) Add2Ptr(pReason, sizeof(*pReason));
  287. pReason->ExtReason.Value.cbData = cbEncoded;
  288. CopyMemory(pReason->ExtReason.Value.pbData, pbEncoded, cbEncoded);
  289. *ppReason = pReason;
  290. //printf("crlCreateCRLReason: new %x cb %x\n", RevocationReason, cbEncoded);
  291. }
  292. //printf("crlCreateCRLReason: %x\n", RevocationReason);
  293. CSASSERT(NULL != pReason && RevocationReason == pReason->RevocationReason);
  294. *pcExtension = 1;
  295. *ppExtension = &pReason->ExtReason;
  296. hr = S_OK;
  297. error:
  298. if (NULL != pbEncoded)
  299. {
  300. LocalFree(pbEncoded);
  301. }
  302. return(hr);
  303. }
  304. // Convert linked list of CRL blocks to an array.
  305. // If the output array pointer is NULL, just free the list.
  306. HRESULT
  307. ConvertOrFreeCRLList(
  308. IN OUT CSCRLBLOCK **ppBlockCRL, // Freed
  309. IN OUT CSMEMBLOCK **ppBlockReason, // Used to allocate reason extensions
  310. IN DWORD cCRL,
  311. OPTIONAL OUT CRL_ENTRY **paCRL)
  312. {
  313. HRESULT hr;
  314. CSCRLREASON *pReasonList = NULL; // linked list of reason extensions
  315. CSCRLBLOCK *pBlockCRL = *ppBlockCRL;
  316. CRL_ENTRY *aCRL = NULL;
  317. CRL_ENTRY *pCRL;
  318. DWORD i;
  319. if (NULL != paCRL)
  320. {
  321. aCRL = (CRL_ENTRY *) LocalAlloc(LMEM_FIXED, sizeof(aCRL[0]) * cCRL);
  322. if (NULL == aCRL)
  323. {
  324. hr = E_OUTOFMEMORY;
  325. _JumpError(hr, error, "LocalAlloc");
  326. }
  327. }
  328. pCRL = aCRL;
  329. while (NULL != pBlockCRL)
  330. {
  331. CSCRLBLOCK *pBlockCRLNext;
  332. if (NULL != pCRL)
  333. {
  334. for (i = 0; i < pBlockCRL->cCRLElement; i++)
  335. {
  336. CSCRLELEMENT *pCRLElement = &pBlockCRL->aCRLElement[i];
  337. pCRL->SerialNumber.pbData = pCRLElement->pbSerialNumber;
  338. pCRL->SerialNumber.cbData = pCRLElement->uscbSerialNumber;
  339. pCRL->RevocationDate = pCRLElement->ftRevocationDate;
  340. pCRL->cExtension = 0;
  341. pCRL->rgExtension = NULL;
  342. if (CRL_REASON_UNSPECIFIED != pCRLElement->usRevocationReason)
  343. {
  344. hr = crlCreateCRLReason(
  345. ppBlockReason,
  346. &pReasonList,
  347. pCRLElement->usRevocationReason,
  348. &pCRL->cExtension,
  349. &pCRL->rgExtension);
  350. _JumpIfError(hr, error, "crlCreateCRLReason");
  351. }
  352. pCRL++;
  353. }
  354. }
  355. pBlockCRLNext = pBlockCRL->pNext;
  356. LocalFree(pBlockCRL);
  357. pBlockCRL = pBlockCRLNext;
  358. }
  359. if (NULL != paCRL)
  360. {
  361. CSASSERT(pCRL == &aCRL[cCRL]);
  362. *paCRL = aCRL;
  363. aCRL = NULL;
  364. }
  365. CSASSERT(NULL == pBlockCRL);
  366. hr = S_OK;
  367. error:
  368. *ppBlockCRL = pBlockCRL;
  369. if (NULL != aCRL)
  370. {
  371. LocalFree(aCRL);
  372. }
  373. return(hr);
  374. }
  375. HRESULT
  376. AddCRLElement(
  377. IN OUT CSMEMBLOCK **ppBlockSerial,
  378. IN OUT CSCRLBLOCK **ppBlockCRL,
  379. IN WCHAR const *pwszSerialNumber,
  380. IN FILETIME const *pftRevokedEffectiveWhen,
  381. IN DWORD RevocationReason)
  382. {
  383. HRESULT hr;
  384. CSCRLELEMENT *pCRLElement;
  385. DWORD cbSerial;
  386. BYTE *pbSerial = NULL;
  387. hr = crlElementAlloc(ppBlockCRL, &pCRLElement);
  388. _JumpIfError(hr, error, "crlElementAlloc");
  389. hr = WszToMultiByteInteger(
  390. FALSE,
  391. pwszSerialNumber,
  392. &cbSerial,
  393. &pbSerial);
  394. _JumpIfError(hr, error, "WszToMultiByteInteger");
  395. hr = crlMemBlockAlloc(ppBlockSerial, cbSerial, &pCRLElement->pbSerialNumber);
  396. _JumpIfError(hr, error, "crlMemBlockAlloc");
  397. CopyMemory(pCRLElement->pbSerialNumber, pbSerial, cbSerial);
  398. pCRLElement->ftRevocationDate = *pftRevokedEffectiveWhen;
  399. pCRLElement->usRevocationReason = (USHORT) RevocationReason;
  400. pCRLElement->uscbSerialNumber = (USHORT) cbSerial;
  401. CSASSERT(pCRLElement->usRevocationReason == RevocationReason);
  402. CSASSERT(pCRLElement->uscbSerialNumber == cbSerial);
  403. error:
  404. if (NULL != pbSerial)
  405. {
  406. LocalFree(pbSerial);
  407. }
  408. return(hr);
  409. }
  410. DWORD g_aColCRL[] = {
  411. #define ICOL_DISPOSITION 0
  412. DTI_REQUESTTABLE | DTR_REQUESTDISPOSITION,
  413. #define ICOL_SERIAL 1
  414. DTI_CERTIFICATETABLE | DTC_CERTIFICATESERIALNUMBER,
  415. #define ICOL_EFFECTIVEWHEN 2
  416. DTI_REQUESTTABLE | DTR_REQUESTREVOKEDEFFECTIVEWHEN,
  417. #define ICOL_REASON 3
  418. DTI_REQUESTTABLE | DTR_REQUESTREVOKEDREASON,
  419. };
  420. HRESULT
  421. BuildCRLList(
  422. IN BOOL fDelta,
  423. IN DWORD iKey,
  424. OPTIONAL IN FILETIME const *pftQueryMinimum,
  425. IN FILETIME const *pftThisPublish,
  426. IN FILETIME const *pftLastPublishBase,
  427. IN OUT DWORD *pcCRL,
  428. IN OUT CSCRLBLOCK **ppBlockCRL,
  429. IN OUT CSMEMBLOCK **ppBlockSerial)
  430. {
  431. HRESULT hr;
  432. CERTVIEWRESTRICTION acvr[5];
  433. CERTVIEWRESTRICTION *pcvr;
  434. IEnumCERTDBRESULTROW *pView = NULL;
  435. DWORD celtFetched;
  436. DWORD NameIdMin;
  437. DWORD NameIdMax;
  438. DWORD i;
  439. BOOL fEnd;
  440. CERTDBRESULTROW aResult[10];
  441. BOOL fResultActive = FALSE;
  442. DWORD cCRL = *pcCRL;
  443. CSCRLBLOCK *pBlockCRL = *ppBlockCRL;
  444. CSMEMBLOCK *pBlockSerial = *ppBlockSerial;
  445. DBGPRINTTIME(NULL, "*pftThisPublish", DPT_DATE, *pftThisPublish);
  446. // Set up restrictions as follows:
  447. pcvr = acvr;
  448. // Request.RevokedEffectiveWhen <= *pftThisPublish (indexed column)
  449. pcvr->ColumnIndex = DTI_REQUESTTABLE | DTR_REQUESTREVOKEDEFFECTIVEWHEN;
  450. pcvr->SeekOperator = CVR_SEEK_LE;
  451. pcvr->SortOrder = CVR_SORT_DESCEND;
  452. pcvr->pbValue = (BYTE *) pftThisPublish;
  453. pcvr->cbValue = sizeof(*pftThisPublish);
  454. pcvr++;
  455. // Cert.NotAfter >= *pftLastPublishBase
  456. if (0 == (CRLF_PUBLISH_EXPIRED_CERT_CRLS & g_dwCRLFlags))
  457. {
  458. pcvr->ColumnIndex = DTI_CERTIFICATETABLE | DTC_CERTIFICATENOTAFTERDATE;
  459. pcvr->SeekOperator = CVR_SEEK_GE;
  460. pcvr->SortOrder = CVR_SORT_NONE;
  461. pcvr->pbValue = (BYTE *) pftLastPublishBase;
  462. pcvr->cbValue = sizeof(*pftLastPublishBase);
  463. pcvr++;
  464. }
  465. // NameId >= MAKECANAMEID(iCert == 0, iKey)
  466. NameIdMin = MAKECANAMEID(0, iKey);
  467. pcvr->ColumnIndex = DTI_CERTIFICATETABLE | DTC_CERTIFICATEISSUERNAMEID;
  468. pcvr->SeekOperator = CVR_SEEK_GE;
  469. pcvr->SortOrder = CVR_SORT_NONE;
  470. pcvr->pbValue = (BYTE *) &NameIdMin;
  471. pcvr->cbValue = sizeof(NameIdMin);
  472. pcvr++;
  473. // NameId <= MAKECANAMEID(iCert == _16BITMASK, iKey)
  474. NameIdMax = MAKECANAMEID(_16BITMASK, iKey);
  475. pcvr->ColumnIndex = DTI_CERTIFICATETABLE | DTC_CERTIFICATEISSUERNAMEID;
  476. pcvr->SeekOperator = CVR_SEEK_LE;
  477. pcvr->SortOrder = CVR_SORT_NONE;
  478. pcvr->pbValue = (BYTE *) &NameIdMax;
  479. pcvr->cbValue = sizeof(NameIdMax);
  480. pcvr++;
  481. CSASSERT(ARRAYSIZE(acvr) > SAFE_SUBTRACT_POINTERS(pcvr, acvr));
  482. if (NULL != pftQueryMinimum)
  483. {
  484. // Request.RevokedWhen >= *pftQueryMinimum
  485. pcvr->ColumnIndex = DTI_REQUESTTABLE | DTR_REQUESTREVOKEDWHEN;
  486. pcvr->SeekOperator = CVR_SEEK_GE;
  487. pcvr->SortOrder = CVR_SORT_NONE;
  488. pcvr->pbValue = (BYTE *) pftQueryMinimum;
  489. pcvr->cbValue = sizeof(*pftQueryMinimum);
  490. pcvr++;
  491. CSASSERT(ARRAYSIZE(acvr) >= SAFE_SUBTRACT_POINTERS(pcvr, acvr));
  492. }
  493. celtFetched = 0;
  494. hr = g_pCertDB->OpenView(
  495. SAFE_SUBTRACT_POINTERS(pcvr, acvr),
  496. acvr,
  497. ARRAYSIZE(g_aColCRL),
  498. g_aColCRL,
  499. 0, // no worker thread
  500. &pView);
  501. _JumpIfError(hr, error, "OpenView");
  502. fEnd = FALSE;
  503. while (!fEnd)
  504. {
  505. hr = pView->Next(NULL, ARRAYSIZE(aResult), aResult, &celtFetched);
  506. if (S_FALSE == hr)
  507. {
  508. fEnd = TRUE;
  509. if (0 == celtFetched)
  510. {
  511. break;
  512. }
  513. hr = S_OK;
  514. }
  515. _JumpIfError(hr, error, "Next");
  516. fResultActive = TRUE;
  517. CSASSERT(ARRAYSIZE(aResult) >= celtFetched);
  518. for (i = 0; i < celtFetched; i++)
  519. {
  520. DWORD Disposition;
  521. DWORD Reason;
  522. CERTDBRESULTROW *pResult = &aResult[i];
  523. CSASSERT(ARRAYSIZE(g_aColCRL) == pResult->ccol);
  524. CSASSERT(NULL != pResult->acol[ICOL_DISPOSITION].pbValue);
  525. CSASSERT(PROPTYPE_LONG == (PROPTYPE_MASK & pResult->acol[ICOL_DISPOSITION].Type));
  526. CSASSERT(sizeof(Disposition) == pResult->acol[ICOL_DISPOSITION].cbValue);
  527. Disposition = *(DWORD *) pResult->acol[ICOL_DISPOSITION].pbValue;
  528. CSASSERT(NULL != pResult->acol[ICOL_SERIAL].pbValue);
  529. CSASSERT(PROPTYPE_STRING == (PROPTYPE_MASK & pResult->acol[ICOL_SERIAL].Type));
  530. CSASSERT(0 < pResult->acol[ICOL_SERIAL].cbValue);
  531. if (NULL == pResult->acol[ICOL_EFFECTIVEWHEN].pbValue)
  532. {
  533. continue;
  534. }
  535. CSASSERT(sizeof(FILETIME) == pResult->acol[ICOL_EFFECTIVEWHEN].cbValue);
  536. CSASSERT(PROPTYPE_DATE == (PROPTYPE_MASK & pResult->acol[ICOL_EFFECTIVEWHEN].Type));
  537. CSASSERT(PROPTYPE_LONG == (PROPTYPE_MASK & pResult->acol[ICOL_REASON].Type));
  538. Reason = CRL_REASON_UNSPECIFIED;
  539. if (NULL != pResult->acol[ICOL_REASON].pbValue)
  540. {
  541. CSASSERT(sizeof(Reason) == pResult->acol[ICOL_REASON].cbValue);
  542. Reason = *(DWORD *) pResult->acol[ICOL_REASON].pbValue;
  543. }
  544. if (NULL == pResult->acol[ICOL_SERIAL].pbValue ||
  545. CRL_REASON_REMOVE_FROM_CRL == Reason)
  546. {
  547. continue;
  548. }
  549. // Add to CRL unless it's:
  550. // not a revoked issued cert &&
  551. // not a root CA cert &&
  552. // not an unrevoked issued cert
  553. if (DB_DISP_REVOKED != Disposition &&
  554. !(DB_DISP_CA_CERT == Disposition && IsRootCA(g_CAType)) &&
  555. !(DB_DISP_ISSUED == Disposition && MAXDWORD == Reason))
  556. {
  557. continue;
  558. }
  559. if (MAXDWORD == Reason)
  560. {
  561. if (!fDelta)
  562. {
  563. continue;
  564. }
  565. Reason = CRL_REASON_REMOVE_FROM_CRL;
  566. }
  567. hr = AddCRLElement(
  568. &pBlockSerial,
  569. &pBlockCRL,
  570. (WCHAR const *) pResult->acol[ICOL_SERIAL].pbValue,
  571. (FILETIME const *) pResult->acol[ICOL_EFFECTIVEWHEN].pbValue,
  572. Reason);
  573. _JumpIfError(hr, error, "AddCRLElement");
  574. CONSOLEPRINT3((
  575. DBG_SS_CERTSRV,
  576. "Cert is %ws: %ws: %d\n",
  577. CRL_REASON_REMOVE_FROM_CRL == Reason?
  578. L"UNREVOKED" : L"Revoked",
  579. pResult->acol[ICOL_SERIAL].pbValue,
  580. Reason));
  581. cCRL++;
  582. }
  583. pView->ReleaseResultRow(celtFetched, aResult);
  584. fResultActive = FALSE;
  585. }
  586. *pcCRL = cCRL;
  587. hr = S_OK;
  588. error:
  589. *ppBlockSerial = pBlockSerial;
  590. *ppBlockCRL = pBlockCRL;
  591. if (NULL != pView)
  592. {
  593. if (fResultActive)
  594. {
  595. pView->ReleaseResultRow(celtFetched, aResult);
  596. }
  597. pView->Release();
  598. }
  599. return(hr);
  600. }
  601. #undef ICOL_DISPOSITION
  602. #undef ICOL_SERIAL
  603. #undef ICOL_EFFECTIVEWHEN
  604. #undef ICOL_REASON
  605. HRESULT
  606. crlBuildCRLArray(
  607. IN BOOL fDelta,
  608. OPTIONAL IN FILETIME const *pftQueryMinimum,
  609. IN FILETIME const *pftThisPublish,
  610. IN FILETIME const *pftLastPublishBase,
  611. IN DWORD iKey,
  612. OUT DWORD *pcCRL,
  613. OUT CRL_ENTRY **paCRL,
  614. OUT VOID **ppvBlock)
  615. {
  616. HRESULT hr;
  617. BOOL fCoInitialized = FALSE;
  618. CSCRLBLOCK *pBlockCRL = NULL;
  619. CSMEMBLOCK *pBlockSerial = NULL;
  620. *pcCRL = 0;
  621. *paCRL = NULL;
  622. *ppvBlock = NULL;
  623. hr = CoInitializeEx(NULL, GetCertsrvComThreadingModel());
  624. if (S_OK != hr && S_FALSE != hr)
  625. {
  626. _JumpError(hr, error, "CoInitializeEx");
  627. }
  628. fCoInitialized = TRUE;
  629. hr = BuildCRLList(
  630. fDelta,
  631. iKey,
  632. pftQueryMinimum,
  633. pftThisPublish,
  634. pftLastPublishBase,
  635. pcCRL,
  636. &pBlockCRL,
  637. &pBlockSerial);
  638. _JumpIfError(hr, error, "BuildCRLList");
  639. hr = ConvertOrFreeCRLList(&pBlockCRL, &pBlockSerial, *pcCRL, paCRL);
  640. _JumpIfError(hr, error, "ConvertOrFreeCRLList");
  641. *ppvBlock = pBlockSerial;
  642. pBlockSerial = NULL;
  643. error:
  644. if (NULL != pBlockCRL)
  645. {
  646. ConvertOrFreeCRLList(&pBlockCRL, NULL, 0, NULL);
  647. }
  648. if (NULL != pBlockSerial)
  649. {
  650. crlBlockListFree(pBlockSerial);
  651. }
  652. if (fCoInitialized)
  653. {
  654. CoUninitialize();
  655. }
  656. return(hr);
  657. }
  658. HRESULT
  659. crlGetRegCRLNextPublish(
  660. IN BOOL DBGPARMREFERENCED(fDelta),
  661. IN WCHAR const *pwszSanitizedName,
  662. IN WCHAR const *pwszRegName,
  663. OUT FILETIME *pftNextPublish)
  664. {
  665. HRESULT hr;
  666. BYTE *pbData = NULL;
  667. DWORD cbData;
  668. DWORD dwType;
  669. hr = myGetCertRegValue(
  670. NULL,
  671. pwszSanitizedName,
  672. NULL,
  673. NULL,
  674. pwszRegName,
  675. &pbData, // free using LocalFree
  676. &cbData,
  677. &dwType);
  678. if (HRESULT_FROM_WIN32(ERROR_FILE_NOT_FOUND) == hr)
  679. {
  680. hr = S_OK;
  681. goto error;
  682. }
  683. _JumpIfErrorStr(hr, error, "myGetCertRegValue", pwszRegName);
  684. if (REG_BINARY != dwType || sizeof(*pftNextPublish) != cbData)
  685. {
  686. hr = HRESULT_FROM_WIN32(ERROR_INVALID_DATA);
  687. goto error;
  688. }
  689. *pftNextPublish = *(FILETIME *) pbData;
  690. DBGPRINTTIME(&fDelta, "*pftNextPublish", DPT_DATE, *pftNextPublish);
  691. error:
  692. if (NULL != pbData)
  693. {
  694. LocalFree(pbData);
  695. }
  696. return(hr);
  697. }
  698. HRESULT
  699. crlSetRegCRLNextPublish(
  700. IN BOOL DBGPARMREFERENCED(fDelta),
  701. IN WCHAR const *pwszSanitizedName,
  702. IN WCHAR const *pwszRegName,
  703. IN FILETIME const *pftNextPublish)
  704. {
  705. HRESULT hr;
  706. hr = mySetCertRegValue(
  707. NULL,
  708. pwszSanitizedName,
  709. NULL,
  710. NULL,
  711. pwszRegName,
  712. REG_BINARY,
  713. (BYTE const *) pftNextPublish,
  714. sizeof(*pftNextPublish),
  715. FALSE);
  716. _JumpIfErrorStr(hr, error, "mySetCertRegValue", pwszRegName);
  717. DBGPRINTTIME(&fDelta, "*pftNextPublish", DPT_DATE, *pftNextPublish);
  718. error:
  719. return(hr);
  720. }
  721. // called from CoreInit
  722. // inits process-static data: g_ftCRLNextPublish, etc.
  723. HRESULT
  724. CRLInit(
  725. IN WCHAR const *pwszSanitizedName)
  726. {
  727. HRESULT hr;
  728. DWORD dw;
  729. ZeroMemory(&g_ftCRLNextPublish, sizeof(g_ftCRLNextPublish));
  730. ZeroMemory(&g_ftDeltaCRLNextPublish, sizeof(g_ftDeltaCRLNextPublish));
  731. hr = crlGetRegCRLNextPublish(
  732. FALSE,
  733. pwszSanitizedName,
  734. wszREGCRLNEXTPUBLISH,
  735. &g_ftCRLNextPublish);
  736. _JumpIfError(hr, error, "crlGetRegCRLNextPublish");
  737. hr = crlGetRegCRLNextPublish(
  738. TRUE,
  739. pwszSanitizedName,
  740. wszREGCRLDELTANEXTPUBLISH,
  741. &g_ftDeltaCRLNextPublish);
  742. _JumpIfError(hr, error, "crlGetRegCRLNextPublish");
  743. hr = myGetCertRegDWValue(
  744. pwszSanitizedName,
  745. NULL,
  746. NULL,
  747. wszREGCRLFLAGS,
  748. (DWORD *) &dw);
  749. _PrintIfErrorStr(hr, "myGetCertRegDWValue", wszREGCRLFLAGS);
  750. if (S_OK == hr)
  751. {
  752. g_dwCRLFlags = dw;
  753. }
  754. hr = S_OK;
  755. error:
  756. return(hr);
  757. }
  758. VOID
  759. CRLTerminate()
  760. {
  761. if (NULL != g_pld)
  762. {
  763. ldap_unbind(g_pld);
  764. g_pld = NULL;
  765. }
  766. }
  767. HRESULT
  768. crlGetRegPublishParams(
  769. IN BOOL fDelta,
  770. IN WCHAR const *pwszSanitizedName,
  771. IN WCHAR const *pwszRegCRLPeriodCount,
  772. IN WCHAR const *pwszRegCRLPeriodString,
  773. IN WCHAR const *pwszRegCRLOverlapPeriodCount,
  774. IN WCHAR const *pwszRegCRLOverlapPeriodString,
  775. IN LONG lPeriodCountDefault,
  776. IN WCHAR const *pwszPeriodStringDefault,
  777. OPTIONAL OUT CSCRLPERIOD *pccp,
  778. OUT BOOL *pfCRLPublishDisabled)
  779. {
  780. HRESULT hr;
  781. WCHAR *pwszCRLPeriodString = NULL;
  782. WCHAR *pwszCRLOverlapPeriodString = NULL;
  783. CSCRLPERIOD ccp;
  784. if (NULL == pccp)
  785. {
  786. pccp = &ccp;
  787. }
  788. ZeroMemory(pccp, sizeof(*pccp));
  789. CSASSERT(NULL != pfCRLPublishDisabled);
  790. // get if need lCRLPeriodCount OR enumCRLPeriod
  791. // if any of these fail, skip to error handling below
  792. hr = myGetCertRegDWValue(
  793. pwszSanitizedName,
  794. NULL,
  795. NULL,
  796. pwszRegCRLPeriodCount,
  797. (DWORD *) &pccp->lCRLPeriodCount);
  798. _PrintIfErrorStr(hr, "myGetCertRegDWValue", pwszRegCRLPeriodCount);
  799. if (hr == S_OK)
  800. {
  801. hr = myGetCertRegStrValue(
  802. pwszSanitizedName,
  803. NULL,
  804. NULL,
  805. pwszRegCRLPeriodString,
  806. &pwszCRLPeriodString);
  807. _PrintIfErrorStr(hr, "myGetCertRegDWValue", pwszRegCRLPeriodString);
  808. if (hr == S_OK)
  809. {
  810. hr = myTranslatePeriodUnits(
  811. pwszCRLPeriodString,
  812. pccp->lCRLPeriodCount,
  813. &pccp->enumCRLPeriod,
  814. &pccp->lCRLPeriodCount);
  815. _PrintIfError(hr, "myTranslatePeriodUnits");
  816. }
  817. // don't allow base to be disabled anymore: force defaults to be loaded
  818. if (!fDelta &&
  819. (0 == pccp->lCRLPeriodCount || -1 == pccp->lCRLPeriodCount))
  820. {
  821. hr = E_INVALIDARG;
  822. }
  823. }
  824. if (hr != S_OK)
  825. {
  826. _PrintError(hr, "Error reading CRLPub params. Overwriting with defaults.");
  827. if (CERTLOG_WARNING <= g_dwLogLevel)
  828. {
  829. hr = LogEvent(
  830. EVENTLOG_WARNING_TYPE,
  831. MSG_INVALID_CRL_SETTINGS,
  832. 0,
  833. NULL);
  834. _PrintIfError(hr, "LogEvent");
  835. }
  836. // slam default publishing to whatever the caller said
  837. hr = myTranslatePeriodUnits(
  838. pwszPeriodStringDefault,
  839. lPeriodCountDefault,
  840. &pccp->enumCRLPeriod,
  841. &pccp->lCRLPeriodCount);
  842. _JumpIfError(hr, error, "myTranslatePeriodUnits");
  843. // blindly reset defaults
  844. mySetCertRegDWValue(
  845. pwszSanitizedName,
  846. NULL,
  847. NULL,
  848. pwszRegCRLPeriodCount,
  849. pccp->lCRLPeriodCount);
  850. mySetCertRegStrValue(
  851. pwszSanitizedName,
  852. NULL,
  853. NULL,
  854. pwszRegCRLPeriodString,
  855. pwszPeriodStringDefault);
  856. }
  857. *pfCRLPublishDisabled = 0 == pccp->lCRLPeriodCount;
  858. if (&ccp != pccp) // If caller wants the data
  859. {
  860. BOOL fRegistryOverlap = FALSE;
  861. DWORD dwCRLOverlapCount;
  862. ENUM_PERIOD enumCRLOverlap;
  863. LLFILETIME llftDeltaPeriod;
  864. // try and gather overlap values from registry - bail on any failure
  865. enumCRLOverlap = ENUM_PERIOD_YEARS;
  866. hr = myGetCertRegDWValue(
  867. pwszSanitizedName,
  868. NULL,
  869. NULL,
  870. pwszRegCRLOverlapPeriodCount,
  871. &dwCRLOverlapCount);
  872. if (hr == S_OK && 0 != dwCRLOverlapCount) // if not disabled
  873. {
  874. hr = myGetCertRegStrValue(
  875. pwszSanitizedName,
  876. NULL,
  877. NULL,
  878. pwszRegCRLOverlapPeriodString,
  879. &pwszCRLOverlapPeriodString);// free w/ LocalFree
  880. if (hr == S_OK)
  881. {
  882. hr = myTranslatePeriodUnits(
  883. pwszCRLOverlapPeriodString,
  884. dwCRLOverlapCount,
  885. &enumCRLOverlap,
  886. (LONG *) &dwCRLOverlapCount);
  887. // we have enough info to override overlap calculation
  888. if (hr == S_OK)
  889. {
  890. fRegistryOverlap = TRUE;
  891. DBGPRINT((
  892. DBG_SS_CERTSRVI,
  893. "Loaded CRL Overlap values. Overriding overlap calculation with specified values.\n"));
  894. }
  895. }
  896. }
  897. // always possible to revert to calculated value
  898. if (fRegistryOverlap)
  899. {
  900. LLFILETIME llftOverlap;
  901. // convert registry-specified CRL overlap to FILETIME
  902. llftOverlap.ll = 0;
  903. myMakeExprDateTime(
  904. &llftOverlap.ft,
  905. dwCRLOverlapCount,
  906. enumCRLOverlap);
  907. DBGPRINTTIME(&fDelta, "ftdelta1", DPT_DELTA, llftOverlap.ft);
  908. llftOverlap.ll /= CVT_BASE; // now in seconds
  909. // (DELTA sec / 60 secpermin)
  910. pccp->dwCRLOverlapMinutes = (DWORD) (llftOverlap.ll / CVT_MINUTES);
  911. }
  912. // convert CRL period to FILETIME
  913. llftDeltaPeriod.ll = 0;
  914. myMakeExprDateTime(
  915. &llftDeltaPeriod.ft,
  916. pccp->lCRLPeriodCount,
  917. pccp->enumCRLPeriod);
  918. DBGPRINTTIME(&fDelta, "ftdelta2", DPT_DELTA, llftDeltaPeriod.ft);
  919. llftDeltaPeriod.ll /= CVT_BASE; // now in seconds
  920. llftDeltaPeriod.ll /= CVT_MINUTES; // now in minutes
  921. if (!fRegistryOverlap)
  922. {
  923. if (fDelta)
  924. {
  925. // default CRLOverlap for delta CRLs: same as period
  926. pccp->dwCRLOverlapMinutes = llftDeltaPeriod.ft.dwLowDateTime;
  927. }
  928. else
  929. {
  930. // default CRLOverlap for base CRLs: 10% of period
  931. pccp->dwCRLOverlapMinutes = (DWORD) (llftDeltaPeriod.ll / 10);
  932. }
  933. // Clamp computed overlap to less than 12 hours
  934. if (pccp->dwCRLOverlapMinutes > 12 * 60)
  935. {
  936. pccp->dwCRLOverlapMinutes = 12 * 60;
  937. }
  938. }
  939. // Always clamp lower bound: (1.5 * skew) < g_dwCRLOverlapMinutes
  940. // must be at least 1.5x skew
  941. dwCRLOverlapCount = (3 * g_dwClockSkewMinutes) >> 1;
  942. if (pccp->dwCRLOverlapMinutes < dwCRLOverlapCount)
  943. {
  944. pccp->dwCRLOverlapMinutes = dwCRLOverlapCount;
  945. }
  946. // Always clamp upper bound: must be no more than CRL period
  947. if (pccp->dwCRLOverlapMinutes > llftDeltaPeriod.ft.dwLowDateTime)
  948. {
  949. pccp->dwCRLOverlapMinutes = llftDeltaPeriod.ft.dwLowDateTime;
  950. }
  951. }
  952. hr = S_OK;
  953. error:
  954. if (NULL != pwszCRLPeriodString)
  955. {
  956. LocalFree(pwszCRLPeriodString);
  957. }
  958. if (NULL != pwszCRLOverlapPeriodString)
  959. {
  960. LocalFree(pwszCRLOverlapPeriodString);
  961. }
  962. return(hr);
  963. }
  964. // Reload publication params during each CRL publication
  965. HRESULT
  966. crlGetRegCRLPublishParams(
  967. IN WCHAR const *pwszSanitizedName,
  968. OPTIONAL OUT CSCRLPERIOD *pccpBase,
  969. OPTIONAL OUT CSCRLPERIOD *pccpDelta)
  970. {
  971. HRESULT hr;
  972. hr = crlGetRegPublishParams(
  973. FALSE,
  974. pwszSanitizedName,
  975. wszREGCRLPERIODCOUNT,
  976. wszREGCRLPERIODSTRING,
  977. wszREGCRLOVERLAPPERIODCOUNT,
  978. wszREGCRLOVERLAPPERIODSTRING,
  979. dwCRLPERIODCOUNTDEFAULT, // default period
  980. wszCRLPERIODSTRINGDEFAULT, // default period
  981. pccpBase,
  982. &g_fCRLPublishDisabled);
  983. _JumpIfError(hr, error, "crlGetRegPublishParams");
  984. hr = crlGetRegPublishParams(
  985. TRUE,
  986. pwszSanitizedName,
  987. wszREGCRLDELTAPERIODCOUNT,
  988. wszREGCRLDELTAPERIODSTRING,
  989. wszREGCRLDELTAOVERLAPPERIODCOUNT,
  990. wszREGCRLDELTAOVERLAPPERIODSTRING,
  991. dwCRLDELTAPERIODCOUNTDEFAULT, // default period
  992. wszCRLDELTAPERIODSTRINGDEFAULT, // default period
  993. pccpDelta,
  994. &g_fDeltaCRLPublishDisabled);
  995. _JumpIfError(hr, error, "crlGetRegPublishParams");
  996. error:
  997. return(hr);
  998. }
  999. #define CERTSRV_CRLPUB_RETRY_COUNT_DEFAULT 10
  1000. #define CERTSRV_CRLPUB_RETRY_SECONDS (10 * CVT_MINUTES)
  1001. VOID
  1002. crlComputeTimeOutSub(
  1003. OPTIONAL IN BOOL *DBGPARMREFERENCED(pfDelta),
  1004. IN FILETIME const *pftFirst,
  1005. IN FILETIME const *pftLast,
  1006. OUT DWORD *pdwMSTimeOut)
  1007. {
  1008. LLFILETIME llft;
  1009. // llft.ll = *pftLast - *pftFirst;
  1010. llft.ll = mySubtractFileTimes(pftLast, pftFirst);
  1011. DBGPRINTTIME(pfDelta, "*pftFirst", DPT_DATE, *pftFirst);
  1012. DBGPRINTTIME(pfDelta, "*pftLast", DPT_DATE, *pftLast);
  1013. llft.ll /= (CVT_BASE / 1000); // convert 100ns to msecs
  1014. DBGPRINTTIME(pfDelta, "llft", DPT_DELTAMS, llft.ft);
  1015. if (0 > llft.ll || MAXLONG < llft.ll)
  1016. {
  1017. // wait as long as we can without going infinite
  1018. llft.ll = MAXLONG;
  1019. }
  1020. *pdwMSTimeOut = llft.ft.dwLowDateTime;
  1021. }
  1022. VOID
  1023. crlComputeTimeOutEx(
  1024. IN BOOL fDelta,
  1025. IN FILETIME const *pftFirst,
  1026. IN FILETIME const *pftLast,
  1027. OUT DWORD *pdwMSTimeOut)
  1028. {
  1029. crlComputeTimeOutSub(&fDelta, pftFirst, pftLast, pdwMSTimeOut);
  1030. }
  1031. VOID
  1032. CRLComputeTimeOut(
  1033. IN FILETIME const *pftFirst,
  1034. IN FILETIME const *pftLast,
  1035. OUT DWORD *pdwMSTimeOut)
  1036. {
  1037. crlComputeTimeOutSub(NULL, pftFirst, pftLast, pdwMSTimeOut);
  1038. }
  1039. #ifdef DBG_CERTSRV_DEBUG_PRINT
  1040. VOID
  1041. DbgPrintRemainTime(
  1042. IN BOOL fDelta,
  1043. IN FILETIME const *pftCurrent,
  1044. IN FILETIME const *pftCRLNextPublish)
  1045. {
  1046. HRESULT hr;
  1047. LLFILETIME llftDelta;
  1048. WCHAR *pwszTime = NULL;
  1049. WCHAR awc[1];
  1050. llftDelta.ll = mySubtractFileTimes(pftCRLNextPublish, pftCurrent);
  1051. DBGPRINTTIME(&fDelta, "delta", DPT_DELTA, llftDelta.ft);
  1052. llftDelta.ll = -llftDelta.ll;
  1053. hr = myFileTimePeriodToWszTimePeriod(
  1054. &llftDelta.ft,
  1055. TRUE, // fExact
  1056. &pwszTime);
  1057. _PrintIfError(hr, "myFileTimePeriodToWszTimePeriod");
  1058. if (S_OK != hr)
  1059. {
  1060. awc[0] = L'\0';
  1061. pwszTime = awc;
  1062. }
  1063. DBGPRINT((
  1064. DBG_SS_CERTSRV,
  1065. "CRLPubWakeupEvent(tid=%d): Next %hs CRL: %ws\n",
  1066. GetCurrentThreadId(),
  1067. fDelta? "Delta" : "Base",
  1068. pwszTime));
  1069. if (NULL != pwszTime && awc != pwszTime)
  1070. {
  1071. LocalFree(pwszTime);
  1072. }
  1073. }
  1074. #endif // DBG_CERTSRV_DEBUG_PRINT
  1075. DWORD g_aColExpiredCRL[] = {
  1076. #define ICOLEXP_ROWID 0
  1077. DTI_CRLTABLE | DTL_ROWID,
  1078. #define ICOLEXP_MINBASE 1
  1079. DTI_CRLTABLE | DTL_MINBASE,
  1080. #define ICOLEXP_CRLNEXTUPDATE 2
  1081. DTI_CRLTABLE | DTL_NEXTUPDATEDATE,
  1082. };
  1083. HRESULT
  1084. crlDeleteExpiredCRLs(
  1085. IN FILETIME const *pftCurrent,
  1086. IN FILETIME const *pftQueryDeltaDelete,
  1087. IN DWORD RowIdBase)
  1088. {
  1089. HRESULT hr;
  1090. CERTVIEWRESTRICTION acvr[1];
  1091. CERTVIEWRESTRICTION *pcvr;
  1092. IEnumCERTDBRESULTROW *pView = NULL;
  1093. BOOL fResultActive = FALSE;
  1094. CERTDBRESULTROW aResult[1];
  1095. CERTDBRESULTROW *pResult;
  1096. DWORD celtFetched;
  1097. celtFetched = 0;
  1098. if (CRLF_DELETE_EXPIRED_CRLS & g_dwCRLFlags)
  1099. {
  1100. DBGPRINTTIME(NULL, "DeleteCRL:*pftCurrent", DPT_DATE, *pftCurrent);
  1101. DBGPRINTTIME(NULL, "DeleteCRL:*pftQueryDeltaDelete", DPT_DATE, *pftQueryDeltaDelete);
  1102. // Set up restrictions as follows:
  1103. pcvr = acvr;
  1104. // CRL Expiration < ftCurrent (indexed column)
  1105. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_NEXTPUBLISHDATE;
  1106. pcvr->SeekOperator = CVR_SEEK_LT;
  1107. pcvr->SortOrder = CVR_SORT_ASCEND; // Oldest propagated CRL first
  1108. pcvr->pbValue = (BYTE *) pftCurrent;
  1109. pcvr->cbValue = sizeof(*pftCurrent);
  1110. pcvr++;
  1111. CSASSERT(ARRAYSIZE(acvr) == SAFE_SUBTRACT_POINTERS(pcvr, acvr));
  1112. hr = g_pCertDB->OpenView(
  1113. ARRAYSIZE(acvr),
  1114. acvr,
  1115. ARRAYSIZE(g_aColExpiredCRL),
  1116. g_aColExpiredCRL,
  1117. 0, // no worker thread
  1118. &pView);
  1119. _JumpIfError(hr, error, "OpenView");
  1120. for (;;)
  1121. {
  1122. DWORD RowId;
  1123. DWORD MinBase;
  1124. FILETIME ftNextUpdate;
  1125. BOOL fDelete;
  1126. hr = pView->Next(NULL, ARRAYSIZE(aResult), aResult, &celtFetched);
  1127. if (S_FALSE == hr)
  1128. {
  1129. if (0 == celtFetched)
  1130. {
  1131. break;
  1132. }
  1133. }
  1134. _JumpIfError(hr, error, "Next");
  1135. fResultActive = TRUE;
  1136. CSASSERT(ARRAYSIZE(aResult) == celtFetched);
  1137. pResult = &aResult[0];
  1138. CSASSERT(ARRAYSIZE(g_aColExpiredCRL) == pResult->ccol);
  1139. CSASSERT(NULL != pResult->acol[ICOLEXP_ROWID].pbValue);
  1140. CSASSERT(PROPTYPE_LONG == (PROPTYPE_MASK & pResult->acol[ICOLEXP_ROWID].Type));
  1141. CSASSERT(sizeof(RowId) == pResult->acol[ICOLEXP_ROWID].cbValue);
  1142. RowId = *(DWORD *) pResult->acol[ICOLEXP_ROWID].pbValue;
  1143. CSASSERT(NULL != pResult->acol[ICOLEXP_MINBASE].pbValue);
  1144. CSASSERT(PROPTYPE_LONG == (PROPTYPE_MASK & pResult->acol[ICOLEXP_MINBASE].Type));
  1145. CSASSERT(sizeof(MinBase) == pResult->acol[ICOLEXP_MINBASE].cbValue);
  1146. MinBase = *(DWORD *) pResult->acol[ICOLEXP_MINBASE].pbValue;
  1147. if (NULL != pResult->acol[ICOLEXP_CRLNEXTUPDATE].pbValue)
  1148. {
  1149. CSASSERT(PROPTYPE_DATE == (PROPTYPE_MASK & pResult->acol[ICOLEXP_CRLNEXTUPDATE].Type));
  1150. CSASSERT(sizeof(FILETIME) == pResult->acol[ICOLEXP_CRLNEXTUPDATE].cbValue);
  1151. ftNextUpdate = *(FILETIME *) pResult->acol[ICOLEXP_CRLNEXTUPDATE].pbValue;
  1152. }
  1153. else
  1154. {
  1155. ftNextUpdate.dwLowDateTime = 0;
  1156. ftNextUpdate.dwHighDateTime = 0;
  1157. }
  1158. pView->ReleaseResultRow(celtFetched, aResult);
  1159. fResultActive = FALSE;
  1160. CSASSERT(0 != RowId);
  1161. // Delete the CRL row if it is not the current Base CRL and the
  1162. // row represents a CRL that expired prior to the current Base CRL.
  1163. fDelete = FALSE;
  1164. if (0 != ftNextUpdate.dwLowDateTime ||
  1165. 0 != ftNextUpdate.dwHighDateTime)
  1166. {
  1167. if (RowIdBase != RowId &&
  1168. 0 < CompareFileTime(pftQueryDeltaDelete, &ftNextUpdate))
  1169. {
  1170. fDelete = TRUE;
  1171. }
  1172. }
  1173. DBGPRINTTIME(NULL, "DeleteCRL:ftNextUpdate", DPT_DATE, ftNextUpdate);
  1174. DBGPRINT((
  1175. DBG_SS_CERTSRVI,
  1176. "crlDeleteExpiredCRLs(RowId=%x) %ws\n",
  1177. RowId,
  1178. fDelete? L"DELETE" : L"SKIP"));
  1179. if (fDelete)
  1180. {
  1181. ICertDBRow *prow;
  1182. hr = g_pCertDB->OpenRow(
  1183. PROPOPEN_DELETE | PROPTABLE_CRL,
  1184. RowId,
  1185. NULL,
  1186. &prow);
  1187. _JumpIfError(hr, error, "OpenRow");
  1188. hr = prow->Delete();
  1189. _PrintIfError(hr, "Delete");
  1190. if (S_OK == hr)
  1191. {
  1192. hr = prow->CommitTransaction(TRUE);
  1193. _PrintIfError(hr, "CommitTransaction");
  1194. }
  1195. if (S_OK != hr)
  1196. {
  1197. HRESULT hr2 = prow->CommitTransaction(FALSE);
  1198. _PrintIfError(hr2, "CommitTransaction");
  1199. }
  1200. prow->Release();
  1201. }
  1202. }
  1203. }
  1204. hr = S_OK;
  1205. error:
  1206. if (NULL != pView)
  1207. {
  1208. if (fResultActive)
  1209. {
  1210. pView->ReleaseResultRow(celtFetched, aResult);
  1211. }
  1212. pView->Release();
  1213. }
  1214. return(hr);
  1215. }
  1216. #undef ICOLEXP_ROWID
  1217. #undef ICOLEXP_MINBASE
  1218. #undef ICOLEXP_CRLNEXTUPDATE
  1219. ///////////////////////////////////////////////////
  1220. // CRLPubWakeupEvent is the handler for wakeup notifications.
  1221. //
  1222. // This function is called at miscellaneous times and
  1223. // determines whether or not it is time to rebuild the
  1224. // CRL to be published.
  1225. //
  1226. // It then calls CRLPublishCRLs and advises it as to whether to
  1227. // rebuild or not.
  1228. //
  1229. // Its final task is to recalculate the next wakeup time, which
  1230. // depends on current time, if the exit module needs to be retried,
  1231. // or whether CRL publishing is disabled.
  1232. HRESULT
  1233. CRLPubWakeupEvent(
  1234. OUT DWORD *pdwMSTimeOut)
  1235. {
  1236. HRESULT hr;
  1237. HRESULT hrPublish;
  1238. FILETIME ftZero;
  1239. FILETIME ftCurrent;
  1240. BOOL fBaseTrigger = TRUE;
  1241. BOOL fRebuildCRL = FALSE;
  1242. BOOL fForceRepublish = FALSE;
  1243. BOOL fShadowDelta = FALSE;
  1244. BOOL fSetRetryTimer = FALSE;
  1245. DWORD dwMSTimeOut = CERTSRV_CRLPUB_RETRY_SECONDS * 1000;
  1246. DWORD State = 0;
  1247. static BOOL s_fFirstWakeup = TRUE;
  1248. CSASSERT(NULL != pdwMSTimeOut);
  1249. // if anything goes wrong, call us again after a pause
  1250. hr = CertSrvEnterServer(&State);
  1251. _JumpIfError(hr, error, "CertSrvEnterServer");
  1252. __try
  1253. {
  1254. BOOL fCRLPublishDisabledOld = g_fCRLPublishDisabled;
  1255. BOOL fDeltaCRLPublishDisabledOld = g_fDeltaCRLPublishDisabled;
  1256. // Recalc Timeout
  1257. GetSystemTimeAsFileTime(&ftCurrent);
  1258. #ifdef DBG_CERTSRV_DEBUG_PRINT
  1259. {
  1260. WCHAR *pwszNow = NULL;
  1261. myGMTFileTimeToWszLocalTime(&ftCurrent, TRUE, &pwszNow);
  1262. DBGPRINT((DBG_SS_CERTSRV, "CRLPubWakeupEvent(%ws)\n", pwszNow));
  1263. if (NULL != pwszNow)
  1264. {
  1265. LocalFree(pwszNow);
  1266. }
  1267. }
  1268. #endif // DBG_CERTSRV_DEBUG_PRINT
  1269. // get current publish params
  1270. hr = crlGetRegCRLPublishParams(g_wszSanitizedName, NULL, NULL);
  1271. _LeaveIfError(hr, "crlGetRegCRLPublishParams");
  1272. if (s_fFirstWakeup)
  1273. {
  1274. s_fFirstWakeup = FALSE;
  1275. if (g_fDBRecovered)
  1276. {
  1277. fForceRepublish = TRUE;
  1278. }
  1279. }
  1280. else
  1281. {
  1282. if (!g_fCRLPublishDisabled &&
  1283. (fCRLPublishDisabledOld ||
  1284. g_fDeltaCRLPublishDisabled != fDeltaCRLPublishDisabledOld))
  1285. {
  1286. fRebuildCRL = TRUE; // state change: force new CRLs
  1287. // If delta CRLs were just now disabled, make one attempt to
  1288. // publish shadow deltas; force clients to fetch a new base CRL.
  1289. if (!fDeltaCRLPublishDisabledOld && g_fDeltaCRLPublishDisabled)
  1290. {
  1291. fShadowDelta = TRUE; // force shadow delta
  1292. }
  1293. }
  1294. }
  1295. // if "not yet ready"
  1296. if (0 < CompareFileTime(&g_ftCRLNextPublish, &ftCurrent))
  1297. {
  1298. fBaseTrigger = FALSE;
  1299. #ifdef DBG_CERTSRV_DEBUG_PRINT
  1300. // give next pub status
  1301. DbgPrintRemainTime(FALSE, &ftCurrent, &g_ftCRLNextPublish);
  1302. #endif // DBG_CERTSRV_DEBUG_PRINT
  1303. }
  1304. // if "not yet ready"
  1305. if (!fBaseTrigger &&
  1306. (g_fDeltaCRLPublishDisabled ||
  1307. 0 < CompareFileTime(&g_ftDeltaCRLNextPublish, &ftCurrent)))
  1308. {
  1309. #ifdef DBG_CERTSRV_DEBUG_PRINT
  1310. // give next pub status
  1311. if (!g_fDeltaCRLPublishDisabled)
  1312. {
  1313. DbgPrintRemainTime(TRUE, &ftCurrent, &g_ftDeltaCRLNextPublish);
  1314. }
  1315. #endif // DBG_CERTSRV_DEBUG_PRINT
  1316. }
  1317. else // "ready to publish" trigger
  1318. {
  1319. if (!g_fCRLPublishDisabled) // is publishing enabled?
  1320. {
  1321. fRebuildCRL = TRUE; // ENABLED, ready to go!
  1322. }
  1323. else
  1324. {
  1325. DBGPRINT((
  1326. DBG_SS_CERTSRV,
  1327. "CRLPubWakeupEvent(tid=%d): Publishing disabled\n",
  1328. GetCurrentThreadId() ));
  1329. }
  1330. }
  1331. ftZero.dwLowDateTime = 0;
  1332. ftZero.dwHighDateTime = 0;
  1333. for (;;)
  1334. {
  1335. hr = CRLPublishCRLs(
  1336. fRebuildCRL,
  1337. fForceRepublish,
  1338. NULL, // pwszUserName
  1339. !fForceRepublish && // fDeltaOnly
  1340. !fBaseTrigger &&
  1341. !g_fDeltaCRLPublishDisabled &&
  1342. !fDeltaCRLPublishDisabledOld,
  1343. fShadowDelta,
  1344. ftZero,
  1345. &fSetRetryTimer,
  1346. &hrPublish);
  1347. if (S_OK == hr)
  1348. {
  1349. break;
  1350. }
  1351. _PrintError(hr, "CRLPublishCRLs");
  1352. if (!fForceRepublish || fRebuildCRL)
  1353. {
  1354. _leave; // give up
  1355. }
  1356. // We failed to republish existing CRLs after a database restore
  1357. // and recovery; generate new base and delta CRLs and publish them.
  1358. fRebuildCRL = TRUE;
  1359. }
  1360. _PrintIfError(hrPublish, "CRLPublishCRLs(hrPublish)");
  1361. // if we called CRLPublishCRLs, clear the manual event it'll trigger
  1362. ResetEvent(g_hCRLManualPublishEvent);
  1363. // how many ms until next publish? set dwMSTimeOut
  1364. if (g_fCRLPublishDisabled)
  1365. {
  1366. // if disabled, don't set timeout
  1367. dwMSTimeOut = INFINITE;
  1368. CONSOLEPRINT1((
  1369. DBG_SS_CERTSRV,
  1370. "CRL Publishing Disabled, TimeOut=INFINITE (%d ms)\n",
  1371. dwMSTimeOut));
  1372. }
  1373. else
  1374. {
  1375. DWORD dwMSTimeOutDelta;
  1376. WCHAR *pwszCRLType = NULL;
  1377. crlComputeTimeOutEx(
  1378. FALSE,
  1379. &ftCurrent,
  1380. &g_ftCRLNextPublish,
  1381. &dwMSTimeOut);
  1382. if (g_fDeltaCRLPublishDisabled)
  1383. {
  1384. pwszCRLType = L"Base";
  1385. }
  1386. else
  1387. {
  1388. crlComputeTimeOutEx(
  1389. TRUE,
  1390. &ftCurrent,
  1391. &g_ftDeltaCRLNextPublish,
  1392. &dwMSTimeOutDelta);
  1393. if (dwMSTimeOut > dwMSTimeOutDelta)
  1394. {
  1395. dwMSTimeOut = dwMSTimeOutDelta;
  1396. }
  1397. pwszCRLType = L"Base + Delta";
  1398. }
  1399. if (NULL != pwszCRLType)
  1400. {
  1401. LONGLONG ll;
  1402. WCHAR *pwszTimePeriod = NULL;
  1403. WCHAR awc[1];
  1404. ll = dwMSTimeOut;
  1405. ll *= CVT_BASE / 1000; // milliseconds to FILETIME Period
  1406. ll = -ll; // FILETIME Period must be negative
  1407. hr = myFileTimePeriodToWszTimePeriod(
  1408. (FILETIME const *) &ll,
  1409. TRUE, // fExact
  1410. &pwszTimePeriod);
  1411. _PrintIfError(hr, "myFileTimePeriodToWszTimePeriod");
  1412. if (S_OK != hr)
  1413. {
  1414. awc[0] = L'\0';
  1415. pwszTimePeriod = awc;
  1416. }
  1417. CONSOLEPRINT3((
  1418. DBG_SS_CERTSRV,
  1419. "%ws CRL Publishing Enabled, TimeOut=%ds, %ws\n",
  1420. pwszCRLType,
  1421. dwMSTimeOut/1000,
  1422. pwszTimePeriod));
  1423. if (NULL != pwszTimePeriod && awc != pwszTimePeriod)
  1424. {
  1425. LocalFree(pwszTimePeriod);
  1426. }
  1427. }
  1428. }
  1429. // if we need to retry, wait no longer than the retry period
  1430. if (fSetRetryTimer)
  1431. {
  1432. if (dwMSTimeOut > CERTSRV_CRLPUB_RETRY_SECONDS * 1000)
  1433. {
  1434. dwMSTimeOut = CERTSRV_CRLPUB_RETRY_SECONDS * 1000;
  1435. CONSOLEPRINT1((
  1436. DBG_SS_CERTSRV,
  1437. "CRL Publishing periodic retry, TimeOut=%ds\n",
  1438. dwMSTimeOut/1000));
  1439. }
  1440. }
  1441. hr = S_OK;
  1442. }
  1443. __except(hr = myHEXCEPTIONCODE(), EXCEPTION_EXECUTE_HANDLER)
  1444. {
  1445. _PrintError(hr, "Exception");
  1446. }
  1447. error:
  1448. *pdwMSTimeOut = dwMSTimeOut;
  1449. CertSrvExitServer(State, hr);
  1450. return(hr);
  1451. }
  1452. HRESULT
  1453. CRLWriteToLockedFile(
  1454. IN BYTE const *pbEncoded,
  1455. IN DWORD cbEncoded,
  1456. IN BOOL fDelete,
  1457. IN WCHAR const *pwszFile)
  1458. {
  1459. HRESULT hr;
  1460. WCHAR *pwszDir = NULL;
  1461. WCHAR *pwszT;
  1462. WCHAR wszTmpPrepFile[MAX_PATH];
  1463. WCHAR wszTmpInUseFile[MAX_PATH];
  1464. BYTE *pbData = NULL;
  1465. DWORD cbData;
  1466. // According to JohnL, the best way to do this is to gen a temp
  1467. // file name, rename the existing file to that, then delete it.
  1468. //
  1469. // Logic:
  1470. // create unique preparation filename
  1471. // write new data to prep file
  1472. // create unique destination filename for old file (possibly locked)
  1473. // move old file to destination filename
  1474. // move prep file to (vacated) file name
  1475. // delete old file from destination filename
  1476. if (!fDelete)
  1477. {
  1478. hr = DecodeFileW(pwszFile, &pbData, &cbData, CRYPT_STRING_BINARY);
  1479. if (S_OK == hr &&
  1480. cbEncoded == cbData &&
  1481. 0 == memcmp(pbData, pbEncoded, cbData))
  1482. {
  1483. CSASSERT(S_OK == hr);
  1484. goto error; // already written, do nothing
  1485. }
  1486. }
  1487. // create a prep file
  1488. hr = myDupString(pwszFile, &pwszDir);
  1489. _JumpIfError(hr, error, "myDupString");
  1490. pwszT = wcsrchr(pwszDir, L'\\');
  1491. if (NULL != pwszT)
  1492. {
  1493. *pwszT = L'\0'; // for dir path, remove "\filename.ext"
  1494. }
  1495. if (!fDelete)
  1496. {
  1497. if (0 == GetTempFileName(pwszDir, L"pre", 0, wszTmpPrepFile))
  1498. {
  1499. hr = myHLastError();
  1500. _JumpError(hr, error, "GetTempFileName");
  1501. }
  1502. // write file to prep area
  1503. hr = EncodeToFileW(
  1504. wszTmpPrepFile,
  1505. pbEncoded,
  1506. cbEncoded,
  1507. DECF_FORCEOVERWRITE | CRYPT_STRING_BINARY);
  1508. _JumpIfError(hr, error, "EncodeToFileW");
  1509. }
  1510. if (0 == GetTempFileName(pwszDir, L"crl", 0, wszTmpInUseFile))
  1511. {
  1512. hr = myHLastError();
  1513. _JumpError(hr, error, "GetTempFileName");
  1514. }
  1515. // move old to "in use" file (empty file already exists from
  1516. // GetTempFileName call) may not exist, so don't bother checking status
  1517. MoveFileEx(
  1518. pwszFile,
  1519. wszTmpInUseFile,
  1520. MOVEFILE_WRITE_THROUGH | MOVEFILE_REPLACE_EXISTING);
  1521. // move prepared file to current file
  1522. if (!fDelete)
  1523. {
  1524. if (!MoveFileEx(wszTmpPrepFile, pwszFile, MOVEFILE_WRITE_THROUGH))
  1525. {
  1526. hr = myHLastError();
  1527. _JumpError(hr, error, "MoveFileEx");
  1528. }
  1529. }
  1530. // The "in use" file may not exist, so don't bother checking status.
  1531. DeleteFile(wszTmpInUseFile);
  1532. hr = S_OK;
  1533. error:
  1534. if (NULL != pwszDir)
  1535. {
  1536. LocalFree(pwszDir);
  1537. }
  1538. if (NULL != pbData)
  1539. {
  1540. LocalFree(pbData);
  1541. }
  1542. return(hr);
  1543. }
  1544. WCHAR const g_wszPropCRLNumber[] = wszPROPCRLNUMBER;
  1545. WCHAR const g_wszPropCRLMinBase[] = wszPROPCRLMINBASE;
  1546. WCHAR const g_wszPropCRLNameId[] = wszPROPCRLNAMEID;
  1547. WCHAR const g_wszPropCRLCount[] = wszPROPCRLCOUNT;
  1548. WCHAR const g_wszPropCRLThisUpdateDate[] = wszPROPCRLTHISUPDATE;
  1549. WCHAR const g_wszPropCRLNextUpdateDate[] = wszPROPCRLNEXTUPDATE;
  1550. WCHAR const g_wszPropCRLThisPublishDate[] = wszPROPCRLTHISPUBLISH;
  1551. WCHAR const g_wszPropCRLNextPublishDate[] = wszPROPCRLNEXTPUBLISH;
  1552. WCHAR const g_wszPropCRLEffectiveDate[] = wszPROPCRLEFFECTIVE;
  1553. WCHAR const g_wszPropCRLPropagationCompleteDate[] = wszPROPCRLPROPAGATIONCOMPLETE;
  1554. WCHAR const g_wszPropCRLLastPublished[] = wszPROPCRLLASTPUBLISHED;
  1555. WCHAR const g_wszPropCRLPublishAttempts[] = wszPROPCRLPUBLISHATTEMPTS;
  1556. WCHAR const g_wszPropCRLPublishFlags[] = wszPROPCRLPUBLISHFLAGS;
  1557. WCHAR const g_wszPropCRLPublishStatusCode[] = wszPROPCRLPUBLISHSTATUSCODE;
  1558. WCHAR const g_wszPropCRLPublishError[] = wszPROPCRLPUBLISHERROR;
  1559. WCHAR const g_wszPropCRLRawCRL[] = wszPROPCRLRAWCRL;
  1560. HRESULT
  1561. crlWriteCRLToDB(
  1562. IN DWORD CRLNumber,
  1563. IN DWORD CRLMinBase, // 0 implies base CRL
  1564. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  1565. IN BOOL fShadowDelta, // empty delta CRL with new MinBaseCRL
  1566. IN DWORD CRLNameId,
  1567. IN DWORD CRLCount,
  1568. IN FILETIME const *pftThisUpdate,
  1569. OPTIONAL IN FILETIME const *pftNextUpdate,
  1570. IN FILETIME const *pftThisPublish,
  1571. OPTIONAL IN FILETIME const *pftNextPublish,
  1572. OPTIONAL IN FILETIME const *pftQuery,
  1573. IN FILETIME const *pftPropagationComplete,
  1574. OPTIONAL IN BYTE const *pbCRL,
  1575. IN DWORD cbCRL,
  1576. OUT DWORD *pdwRowId)
  1577. {
  1578. HRESULT hr;
  1579. ICertDBRow *prow = NULL;
  1580. DWORD CRLPublishFlags;
  1581. BOOL fCommitted = FALSE;
  1582. *pdwRowId = 0;
  1583. // Create a new CRL table entry
  1584. hr = g_pCertDB->OpenRow(
  1585. PROPTABLE_CRL,
  1586. 0,
  1587. NULL,
  1588. &prow);
  1589. _JumpIfError(hr, error, "OpenRow");
  1590. prow->GetRowId(pdwRowId);
  1591. hr = prow->SetProperty(
  1592. g_wszPropCRLNumber,
  1593. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  1594. sizeof(CRLNumber),
  1595. (BYTE const *) &CRLNumber);
  1596. _JumpIfError(hr, error, "SetProperty");
  1597. hr = prow->SetProperty(
  1598. g_wszPropCRLMinBase,
  1599. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  1600. sizeof(CRLMinBase),
  1601. (BYTE const *) &CRLMinBase);
  1602. _JumpIfError(hr, error, "SetProperty");
  1603. hr = prow->SetProperty(
  1604. g_wszPropCRLNameId,
  1605. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  1606. sizeof(CRLNameId),
  1607. (BYTE const *) &CRLNameId);
  1608. _JumpIfError(hr, error, "SetProperty");
  1609. hr = prow->SetProperty(
  1610. g_wszPropCRLCount,
  1611. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  1612. sizeof(CRLCount),
  1613. (BYTE const *) &CRLCount);
  1614. _JumpIfError(hr, error, "SetProperty");
  1615. hr = prow->SetProperty(
  1616. g_wszPropCRLThisUpdateDate,
  1617. PROPTYPE_DATE | PROPCALLER_SERVER | PROPTABLE_CRL,
  1618. sizeof(*pftThisUpdate),
  1619. (BYTE const *) pftThisUpdate);
  1620. _JumpIfError(hr, error, "SetProperty");
  1621. if (NULL != pftNextUpdate)
  1622. {
  1623. hr = prow->SetProperty(
  1624. g_wszPropCRLNextUpdateDate,
  1625. PROPTYPE_DATE | PROPCALLER_SERVER | PROPTABLE_CRL,
  1626. sizeof(*pftNextUpdate),
  1627. (BYTE const *) pftNextUpdate);
  1628. _JumpIfError(hr, error, "SetProperty");
  1629. }
  1630. hr = prow->SetProperty(
  1631. g_wszPropCRLThisPublishDate,
  1632. PROPTYPE_DATE | PROPCALLER_SERVER | PROPTABLE_CRL,
  1633. sizeof(*pftThisPublish),
  1634. (BYTE const *) pftThisPublish);
  1635. _JumpIfError(hr, error, "SetProperty");
  1636. if (NULL != pftNextPublish)
  1637. {
  1638. hr = prow->SetProperty(
  1639. g_wszPropCRLNextPublishDate,
  1640. PROPTYPE_DATE | PROPCALLER_SERVER | PROPTABLE_CRL,
  1641. sizeof(*pftNextPublish),
  1642. (BYTE const *) pftNextPublish);
  1643. _JumpIfError(hr, error, "SetProperty");
  1644. }
  1645. if (NULL != pftQuery)
  1646. {
  1647. hr = prow->SetProperty(
  1648. g_wszPropCRLEffectiveDate,
  1649. PROPTYPE_DATE | PROPCALLER_SERVER | PROPTABLE_CRL,
  1650. sizeof(*pftQuery),
  1651. (BYTE const *) pftQuery);
  1652. _JumpIfError(hr, error, "SetProperty");
  1653. }
  1654. hr = prow->SetProperty(
  1655. g_wszPropCRLPropagationCompleteDate,
  1656. PROPTYPE_DATE | PROPCALLER_SERVER | PROPTABLE_CRL,
  1657. sizeof(*pftPropagationComplete),
  1658. (BYTE const *) pftPropagationComplete);
  1659. _JumpIfError(hr, error, "SetProperty");
  1660. CRLPublishFlags = 0 == CRLMinBase? CPF_BASE : CPF_DELTA;
  1661. if (fShadowDelta)
  1662. {
  1663. CRLPublishFlags |= CPF_SHADOW;
  1664. }
  1665. if (NULL != pwszUserName)
  1666. {
  1667. CRLPublishFlags |= CPF_MANUAL;
  1668. }
  1669. hr = prow->SetProperty(
  1670. g_wszPropCRLPublishFlags,
  1671. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  1672. sizeof(CRLPublishFlags),
  1673. (BYTE const *) &CRLPublishFlags);
  1674. _JumpIfError(hr, error, "SetProperty");
  1675. hr = prow->SetProperty(
  1676. g_wszPropCRLRawCRL,
  1677. PROPTYPE_BINARY | PROPCALLER_SERVER | PROPTABLE_CRL,
  1678. cbCRL,
  1679. pbCRL);
  1680. _JumpIfError(hr, error, "SetProperty");
  1681. hr = prow->CommitTransaction(TRUE);
  1682. _JumpIfError(hr, error, "CommitTransaction");
  1683. fCommitted = TRUE;
  1684. error:
  1685. if (NULL != prow)
  1686. {
  1687. if (S_OK != hr && !fCommitted)
  1688. {
  1689. HRESULT hr2 = prow->CommitTransaction(FALSE);
  1690. _PrintIfError(hr2, "CommitTransaction");
  1691. }
  1692. prow->Release();
  1693. }
  1694. return(hr);
  1695. }
  1696. // crlSplitStrings -- split newline separated strings into pwszz
  1697. HRESULT
  1698. crlSplitStrings(
  1699. IN WCHAR const *pwszIn,
  1700. OUT WCHAR **ppwszzOut)
  1701. {
  1702. HRESULT hr;
  1703. DWORD cwc;
  1704. WCHAR *pwsz;
  1705. *ppwszzOut = NULL;
  1706. cwc = wcslen(pwszIn) + 1;
  1707. pwsz = (WCHAR *) LocalAlloc(LMEM_FIXED, (cwc + 1) * sizeof(WCHAR));
  1708. if (NULL == pwsz)
  1709. {
  1710. hr = E_OUTOFMEMORY;
  1711. _JumpError(hr, error, "LocalAlloc");
  1712. }
  1713. *ppwszzOut = pwsz;
  1714. wcscpy(pwsz, pwszIn);
  1715. pwsz[cwc] = L'\0'; // double terminate
  1716. for (;;)
  1717. {
  1718. pwsz = wcschr(pwsz, L'\n');
  1719. if (NULL == pwsz)
  1720. {
  1721. break;
  1722. }
  1723. *pwsz++ = L'\0';
  1724. }
  1725. hr = S_OK;
  1726. error:
  1727. return(hr);
  1728. }
  1729. // crlUnsplitStrings -- combine pwszz list in-place into newline separated list
  1730. VOID
  1731. crlUnsplitStrings(
  1732. IN OUT WCHAR *pwszInOut)
  1733. {
  1734. WCHAR *pwsz;
  1735. if (NULL != pwszInOut)
  1736. {
  1737. pwsz = pwszInOut;
  1738. while (L'\0' != *pwsz)
  1739. {
  1740. pwsz += wcslen(pwsz);
  1741. *pwsz++ = L'\n';
  1742. }
  1743. if (pwsz > pwszInOut && L'\n' == *--pwsz)
  1744. {
  1745. *pwsz = L'\0'; // no newline terminator!
  1746. }
  1747. }
  1748. }
  1749. DWORD
  1750. CRLIsStringInList(
  1751. IN WCHAR const *pwszSearch,
  1752. OPTIONAL IN WCHAR const *pwszzList)
  1753. {
  1754. DWORD iRet = MAXDWORD;
  1755. if (NULL != pwszzList)
  1756. {
  1757. DWORD i = 0;
  1758. WCHAR const *pwsz;
  1759. for (pwsz = pwszzList; L'\0' != *pwsz; pwsz += wcslen(pwsz) + 1)
  1760. {
  1761. if (0 == mylstrcmpiL(pwsz, pwszSearch))
  1762. {
  1763. iRet = i;
  1764. break;
  1765. }
  1766. i++;
  1767. }
  1768. }
  1769. return(iRet);
  1770. }
  1771. // crlMergeURLList -- merge two newline separated URL lists into a pwszz list
  1772. HRESULT
  1773. crlMergeURLList(
  1774. OPTIONAL IN WCHAR const *pwszURLsOld,
  1775. OPTIONAL IN WCHAR const *pwszURLsNew,
  1776. OUT WCHAR **ppwszzURLsMerged)
  1777. {
  1778. HRESULT hr;
  1779. WCHAR *pwszzURLsOld = NULL;
  1780. WCHAR *pwszzURLsNew = NULL;
  1781. WCHAR const *pwsz;
  1782. DWORD cwc;
  1783. DWORD cwcT;
  1784. WCHAR *pwszzMerged = NULL;
  1785. WCHAR *pwszNext;
  1786. *ppwszzURLsMerged = NULL;
  1787. cwc = 0;
  1788. if (NULL != pwszURLsOld)
  1789. {
  1790. hr = crlSplitStrings(pwszURLsOld, &pwszzURLsOld);
  1791. _JumpIfError(hr, error, "crlSplitStrings");
  1792. for (pwsz = pwszzURLsOld; L'\0' != *pwsz; pwsz += cwcT)
  1793. {
  1794. cwcT = wcslen(pwsz) + 1;
  1795. cwc += cwcT;
  1796. }
  1797. }
  1798. if (NULL != pwszURLsNew)
  1799. {
  1800. hr = crlSplitStrings(pwszURLsNew, &pwszzURLsNew);
  1801. _JumpIfError(hr, error, "crlSplitStrings");
  1802. for (pwsz = pwszzURLsNew; L'\0' != *pwsz; pwsz += cwcT)
  1803. {
  1804. cwcT = wcslen(pwsz) + 1;
  1805. if (MAXDWORD == CRLIsStringInList(pwsz, pwszzURLsOld))
  1806. {
  1807. cwc += cwcT;
  1808. }
  1809. }
  1810. }
  1811. if (0 == cwc)
  1812. {
  1813. hr = S_OK;
  1814. goto error;
  1815. }
  1816. pwszzMerged = (WCHAR *) LocalAlloc(LMEM_FIXED, (cwc + 1) * sizeof(WCHAR));
  1817. if (NULL == pwszzMerged)
  1818. {
  1819. hr = E_OUTOFMEMORY;
  1820. _JumpError(hr, error, "LocalAlloc");
  1821. }
  1822. pwszNext = pwszzMerged;
  1823. if (NULL != pwszzURLsOld)
  1824. {
  1825. for (pwsz = pwszzURLsOld; L'\0' != *pwsz; pwsz += cwcT)
  1826. {
  1827. cwcT = wcslen(pwsz) + 1;
  1828. wcscpy(pwszNext, pwsz);
  1829. pwszNext += cwcT;
  1830. }
  1831. }
  1832. if (NULL != pwszzURLsNew)
  1833. {
  1834. for (pwsz = pwszzURLsNew; L'\0' != *pwsz; pwsz += cwcT)
  1835. {
  1836. cwcT = wcslen(pwsz) + 1;
  1837. if (MAXDWORD == CRLIsStringInList(pwsz, pwszzURLsOld))
  1838. {
  1839. wcscpy(pwszNext, pwsz);
  1840. pwszNext += cwcT;
  1841. }
  1842. }
  1843. }
  1844. *pwszNext = L'\0';
  1845. *ppwszzURLsMerged = pwszzMerged;
  1846. hr = S_OK;
  1847. error:
  1848. if (NULL != pwszzURLsOld)
  1849. {
  1850. LocalFree(pwszzURLsOld);
  1851. }
  1852. if (NULL != pwszzURLsNew)
  1853. {
  1854. LocalFree(pwszzURLsNew);
  1855. }
  1856. return(hr);
  1857. }
  1858. // crlBuildUserURLReferenceList -- construct a new User and URL reference list
  1859. //
  1860. // "-" means the system published successfully (no failed URLs).
  1861. // "Published by User\Domain" means User\Domain published successfully.
  1862. // "Published by User\Domain -- 0 3" means User\Domain published CRLs, but
  1863. // publishing failed for URLs 0 and 3 in the merged URL list.
  1864. HRESULT
  1865. crlBuildUserURLReferenceList(
  1866. OPTIONAL IN WCHAR const *pwszUserName,
  1867. OPTIONAL IN WCHAR const *pwszURLsNew,
  1868. OPTIONAL IN WCHAR const *pwszzURLsMerged,
  1869. OUT WCHAR **ppwszUserURLReference)
  1870. {
  1871. HRESULT hr;
  1872. DWORD cwc;
  1873. WCHAR *pwszzURLsNew = NULL;
  1874. WCHAR const *pwsz;
  1875. WCHAR *pwszT;
  1876. DWORD cURL;
  1877. WCHAR *pwszUserURLReference;
  1878. *ppwszUserURLReference = NULL;
  1879. cwc = 1;
  1880. if (NULL != pwszUserName)
  1881. {
  1882. cwc = wcslen(g_pwszPublishedBy) + wcslen(pwszUserName);
  1883. }
  1884. cURL = 0;
  1885. if (NULL != pwszURLsNew)
  1886. {
  1887. hr = crlSplitStrings(pwszURLsNew, &pwszzURLsNew);
  1888. _JumpIfError(hr, error, "crlSplitStrings");
  1889. for (pwsz = pwszzURLsNew; L'\0' != *pwsz; pwsz += wcslen(pwsz) + 1)
  1890. {
  1891. cURL++;
  1892. }
  1893. if (0 != cURL)
  1894. {
  1895. cwc += 3 + (1 + cwcDWORDSPRINTF) * cURL;
  1896. }
  1897. }
  1898. pwszUserURLReference = (WCHAR *) LocalAlloc(
  1899. LMEM_FIXED,
  1900. (cwc + 1) * sizeof(WCHAR));
  1901. if (NULL == pwszUserURLReference)
  1902. {
  1903. hr = E_OUTOFMEMORY;
  1904. _JumpError(hr, error, "LocalAlloc");
  1905. }
  1906. wcscpy(pwszUserURLReference, L"-");
  1907. if (NULL != pwszUserName)
  1908. {
  1909. swprintf(pwszUserURLReference, g_pwszPublishedBy, pwszUserName);
  1910. }
  1911. if (0 != cURL)
  1912. {
  1913. pwszT = wcschr(pwszUserURLReference, L'\0');
  1914. wcscpy(pwszT, L" --");
  1915. for (pwsz = pwszzURLsNew; L'\0' != *pwsz; pwsz += wcslen(pwsz) + 1)
  1916. {
  1917. pwszT += wcslen(pwszT);
  1918. swprintf(pwszT, L" %u", CRLIsStringInList(pwsz, pwszzURLsMerged));
  1919. }
  1920. }
  1921. CSASSERT(wcslen(pwszUserURLReference) <= cwc);
  1922. *ppwszUserURLReference = pwszUserURLReference;
  1923. hr = S_OK;
  1924. error:
  1925. if (NULL != pwszzURLsNew)
  1926. {
  1927. LocalFree(pwszzURLsNew);
  1928. }
  1929. return(hr);
  1930. }
  1931. // crlCombineCRLError -- merge new and existing CRL error strings
  1932. //
  1933. // pwszCRLError consists of "Url0\nUrl1..."
  1934. //
  1935. // pwszCRLErrorNew will consist of "User\n\nUrl0\nUrl1..."
  1936. // After second and third attempts, pwszCRLErrorNew will consist of
  1937. // "User\nUser\n\nUrl0\nUrl1..." and "User\nUser\nUser\n\nUrl0\nUrl1..."
  1938. //
  1939. //
  1940. // pwszCRLErrorNew will consist of "User -- 0 1 ...\n\nUrl0\nUrl1..."
  1941. // After second and third attempts, pwszCRLErrorNew will consist of
  1942. // "User -- 0 1 ...\nUser -- 1\n\nUrl0\nUrl1..." and
  1943. // "User -- 0 1 ...\nUser -- 1\nUser -- 1\n\nUrl0\nUrl1..."
  1944. HRESULT
  1945. crlCombineCRLError(
  1946. IN ICertDBRow *prow,
  1947. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  1948. OPTIONAL IN WCHAR const *pwszURLsNew, // else no errors
  1949. OUT WCHAR **ppwszCRLErrorNew)
  1950. {
  1951. HRESULT hr;
  1952. WCHAR *pwszUserListOld = NULL;
  1953. WCHAR *pwszCRLErrorNew = NULL;
  1954. WCHAR *pwszURLsOld;
  1955. WCHAR *pwszzURLsMerged = NULL;
  1956. WCHAR *pwszUserURLReference = NULL;
  1957. DWORD cwc;
  1958. *ppwszCRLErrorNew = NULL;
  1959. hr = PKCSGetProperty(
  1960. prow,
  1961. g_wszPropCRLPublishError,
  1962. PROPTYPE_STRING | PROPCALLER_SERVER | PROPTABLE_CRL,
  1963. NULL,
  1964. (BYTE **) &pwszUserListOld);
  1965. _PrintIfError2(hr, "PKCSGetProperty", CERTSRV_E_PROPERTY_EMPTY);
  1966. pwszURLsOld = NULL;
  1967. if (NULL != pwszUserListOld)
  1968. {
  1969. pwszURLsOld = wcsstr(pwszUserListOld, L"\n\n");
  1970. if (NULL != pwszURLsOld)
  1971. {
  1972. // truncate user list and point to the URL List
  1973. *pwszURLsOld++ = L'\0';
  1974. pwszURLsOld++;
  1975. if (L'\0' == *pwszURLsOld)
  1976. {
  1977. pwszURLsOld = NULL;
  1978. }
  1979. }
  1980. }
  1981. hr = crlMergeURLList(pwszURLsOld, pwszURLsNew, &pwszzURLsMerged);
  1982. _JumpIfError(hr, error, "crlMergeURLList");
  1983. hr = crlBuildUserURLReferenceList(
  1984. pwszUserName,
  1985. pwszURLsNew,
  1986. pwszzURLsMerged,
  1987. &pwszUserURLReference);
  1988. _JumpIfError(hr, error, "crlBuildUserURLReferenceList");
  1989. // convert pwszz string list into newline separated strings
  1990. crlUnsplitStrings(pwszzURLsMerged);
  1991. cwc = 0;
  1992. if (NULL != pwszUserListOld)
  1993. {
  1994. cwc += wcslen(pwszUserListOld) + 1; // newline separator
  1995. }
  1996. cwc += wcslen(pwszUserURLReference);
  1997. if (NULL != pwszzURLsMerged)
  1998. {
  1999. cwc += 2 + wcslen(pwszzURLsMerged); // double newline separator
  2000. }
  2001. pwszCRLErrorNew = (WCHAR *) LocalAlloc(
  2002. LMEM_FIXED,
  2003. (cwc + 1) * sizeof(WCHAR));
  2004. if (NULL == pwszCRLErrorNew)
  2005. {
  2006. hr = E_OUTOFMEMORY;
  2007. _JumpError(hr, error, "LocalAlloc");
  2008. }
  2009. *pwszCRLErrorNew = L'\0';
  2010. if (NULL != pwszUserListOld && L'\0' != *pwszUserListOld)
  2011. {
  2012. wcscat(pwszCRLErrorNew, pwszUserListOld);
  2013. wcscat(pwszCRLErrorNew, L"\n");
  2014. }
  2015. wcscat(pwszCRLErrorNew, pwszUserURLReference);
  2016. if (NULL != pwszzURLsMerged)
  2017. {
  2018. wcscat(pwszCRLErrorNew, L"\n\n"); // double newline separator
  2019. wcscat(pwszCRLErrorNew, pwszzURLsMerged);
  2020. }
  2021. CSASSERT(wcslen(pwszCRLErrorNew) <= cwc);
  2022. *ppwszCRLErrorNew = pwszCRLErrorNew;
  2023. pwszCRLErrorNew = NULL;
  2024. hr = S_OK;
  2025. error:
  2026. if (NULL != pwszUserURLReference)
  2027. {
  2028. LocalFree(pwszUserURLReference);
  2029. }
  2030. if (NULL != pwszzURLsMerged)
  2031. {
  2032. LocalFree(pwszzURLsMerged);
  2033. }
  2034. if (NULL != pwszUserListOld)
  2035. {
  2036. LocalFree(pwszUserListOld);
  2037. }
  2038. if (NULL != pwszCRLErrorNew)
  2039. {
  2040. LocalFree(pwszCRLErrorNew);
  2041. }
  2042. return(hr);
  2043. }
  2044. HRESULT
  2045. crlUpdateCRLPublishStateInDB(
  2046. IN DWORD RowId,
  2047. IN FILETIME const *pftCurrent,
  2048. IN HRESULT hrCRLPublish,
  2049. IN DWORD CRLPublishFlags,
  2050. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  2051. OPTIONAL IN WCHAR const *pwszCRLError)
  2052. {
  2053. HRESULT hr;
  2054. ICertDBRow *prow = NULL;
  2055. WCHAR *pwszCRLErrorNew = NULL;
  2056. DWORD cb;
  2057. DWORD dw;
  2058. BOOL fCommitted = FALSE;
  2059. hr = g_pCertDB->OpenRow(
  2060. PROPTABLE_CRL,
  2061. RowId,
  2062. NULL,
  2063. &prow);
  2064. _JumpIfError(hr, error, "OpenRow");
  2065. hr = prow->SetProperty(
  2066. g_wszPropCRLLastPublished,
  2067. PROPTYPE_DATE | PROPCALLER_SERVER | PROPTABLE_CRL,
  2068. sizeof(*pftCurrent),
  2069. (BYTE const *) pftCurrent);
  2070. _JumpIfError(hr, error, "SetProperty");
  2071. cb = sizeof(dw);
  2072. hr = prow->GetProperty(
  2073. g_wszPropCRLPublishAttempts,
  2074. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  2075. NULL,
  2076. &cb,
  2077. (BYTE *) &dw);
  2078. if (S_OK != hr)
  2079. {
  2080. dw = 0;
  2081. }
  2082. dw++;
  2083. hr = prow->SetProperty(
  2084. g_wszPropCRLPublishAttempts,
  2085. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  2086. sizeof(dw),
  2087. (BYTE const *) &dw);
  2088. _JumpIfError(hr, error, "SetProperty");
  2089. cb = sizeof(dw);
  2090. hr = prow->GetProperty(
  2091. g_wszPropCRLPublishFlags,
  2092. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  2093. NULL,
  2094. &cb,
  2095. (BYTE *) &dw);
  2096. if (S_OK != hr)
  2097. {
  2098. dw = 0;
  2099. }
  2100. CRLPublishFlags |= (CPF_BASE | CPF_DELTA | CPF_SHADOW | CPF_MANUAL) & dw;
  2101. if (S_OK == hrCRLPublish)
  2102. {
  2103. CRLPublishFlags |= CPF_COMPLETE;
  2104. }
  2105. hr = prow->SetProperty(
  2106. g_wszPropCRLPublishFlags,
  2107. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  2108. sizeof(CRLPublishFlags),
  2109. (BYTE const *) &CRLPublishFlags);
  2110. _JumpIfError(hr, error, "SetProperty");
  2111. // Always set error string property to clear out previous errors.
  2112. hr = prow->SetProperty(
  2113. g_wszPropCRLPublishStatusCode,
  2114. PROPTYPE_LONG | PROPCALLER_SERVER | PROPTABLE_CRL,
  2115. sizeof(hrCRLPublish),
  2116. (BYTE const *) &hrCRLPublish);
  2117. _JumpIfError(hr, error, "SetProperty");
  2118. hr = crlCombineCRLError(prow, pwszUserName, pwszCRLError, &pwszCRLErrorNew);
  2119. _JumpIfError(hr, error, "crlCombineCRLError");
  2120. if (NULL != pwszCRLErrorNew)
  2121. {
  2122. hr = prow->SetProperty(
  2123. g_wszPropCRLPublishError,
  2124. PROPTYPE_STRING | PROPCALLER_SERVER | PROPTABLE_CRL,
  2125. MAXDWORD,
  2126. (BYTE const *) pwszCRLErrorNew);
  2127. _JumpIfError(hr, error, "SetProperty");
  2128. }
  2129. hr = prow->CommitTransaction(TRUE);
  2130. _JumpIfError(hr, error, "CommitTransaction");
  2131. fCommitted = TRUE;
  2132. error:
  2133. if (NULL != prow)
  2134. {
  2135. if (S_OK != hr && !fCommitted)
  2136. {
  2137. HRESULT hr2 = prow->CommitTransaction(FALSE);
  2138. _PrintIfError(hr2, "CommitTransaction");
  2139. }
  2140. prow->Release();
  2141. }
  2142. if (NULL != pwszCRLErrorNew)
  2143. {
  2144. LocalFree(pwszCRLErrorNew);
  2145. }
  2146. return(hr);
  2147. }
  2148. HRESULT
  2149. WriteCRLToDSAttribute(
  2150. IN WCHAR const *pwszCRLDN,
  2151. IN BOOL fDelta,
  2152. IN BYTE const *pbCRL,
  2153. IN DWORD cbCRL,
  2154. OUT WCHAR **ppwszError)
  2155. {
  2156. HRESULT hr;
  2157. DWORD ldaperr;
  2158. BOOL fRebind = FALSE;
  2159. LDAPMod crlmod;
  2160. struct berval crlberval;
  2161. struct berval *crlVals[2];
  2162. LDAPMod *mods[2];
  2163. for (;;)
  2164. {
  2165. if (NULL == g_pld)
  2166. {
  2167. hr = myRobustLdapBindEx(
  2168. 0, // dwFlags1
  2169. RLBF_REQUIRE_SECURE_LDAP, // dwFlags2
  2170. LDAP_VERSION2, // uVersion
  2171. NULL, // pwszDomainName
  2172. &g_pld,
  2173. NULL); // ppwszForestDNSName
  2174. _JumpIfError(hr, error, "myRobustLdapBindEx");
  2175. }
  2176. mods[0] = &crlmod;
  2177. mods[1] = NULL;
  2178. crlmod.mod_op = LDAP_MOD_BVALUES | LDAP_MOD_REPLACE;
  2179. crlmod.mod_type = fDelta? wszDSDELTACRLATTRIBUTE : wszDSBASECRLATTRIBUTE;
  2180. crlmod.mod_bvalues = crlVals;
  2181. crlVals[0] = &crlberval;
  2182. crlVals[1] = NULL;
  2183. crlberval.bv_len = cbCRL;
  2184. crlberval.bv_val = (char *) pbCRL;
  2185. ldaperr = ldap_modify_ext_s(
  2186. g_pld,
  2187. const_cast<WCHAR *>(pwszCRLDN),
  2188. mods,
  2189. NULL,
  2190. NULL);
  2191. hr = myHLdapError(g_pld, ldaperr, ppwszError);
  2192. _PrintIfErrorStr(hr, "ldap_modify_ext_s", pwszCRLDN);
  2193. if (fRebind || S_OK == hr)
  2194. {
  2195. break;
  2196. }
  2197. if (!myLdapRebindRequired(ldaperr, g_pld))
  2198. {
  2199. _JumpErrorStr(hr, error, "ldap_modify_ext_s", pwszCRLDN);
  2200. }
  2201. fRebind = TRUE;
  2202. if (NULL != g_pld)
  2203. {
  2204. ldap_unbind(g_pld);
  2205. g_pld = NULL;
  2206. }
  2207. }
  2208. error:
  2209. return(hr);
  2210. }
  2211. HRESULT
  2212. crlParseURLPrefix(
  2213. IN WCHAR const *pwszIn,
  2214. IN DWORD cwcPrefix,
  2215. OUT WCHAR *pwcPrefix,
  2216. OUT WCHAR const **ppwszOut)
  2217. {
  2218. HRESULT hr;
  2219. WCHAR const *pwsz;
  2220. CSASSERT(6 <= cwcPrefix);
  2221. wcscpy(pwcPrefix, L"file:");
  2222. *ppwszOut = pwszIn;
  2223. if (L'\\' != pwszIn[0] || L'\\' != pwszIn[1])
  2224. {
  2225. pwsz = wcschr(pwszIn, L':');
  2226. if (NULL != pwsz)
  2227. {
  2228. DWORD cwc;
  2229. pwsz++;
  2230. cwc = SAFE_SUBTRACT_POINTERS(pwsz, pwszIn);
  2231. if (2 < cwc && cwc < cwcPrefix)
  2232. {
  2233. CopyMemory(pwcPrefix, pwszIn, cwc * sizeof(WCHAR));
  2234. pwcPrefix[cwc] = L'\0';
  2235. if (0 == LSTRCMPIS(pwcPrefix, L"file:") &&
  2236. L'/' == pwsz[0] &&
  2237. L'/' == pwsz[1])
  2238. {
  2239. pwsz += 2;
  2240. }
  2241. *ppwszOut = pwsz;
  2242. }
  2243. }
  2244. }
  2245. hr = S_OK;
  2246. //error:
  2247. return(hr);
  2248. }
  2249. VOID
  2250. crlLogError(
  2251. IN BOOL fDelta,
  2252. IN BOOL fLdapURL,
  2253. IN DWORD iKey,
  2254. IN WCHAR const *pwszURL,
  2255. IN WCHAR const *pwszError,
  2256. IN HRESULT hrPublish)
  2257. {
  2258. HRESULT hr;
  2259. WCHAR const *apwsz[6];
  2260. WORD cpwsz;
  2261. WCHAR wszKey[cwcDWORDSPRINTF];
  2262. WCHAR awchr[cwcHRESULTSTRING];
  2263. WCHAR const *pwszMessageText = NULL;
  2264. WCHAR *pwszHostName = NULL;
  2265. DWORD LogMsg;
  2266. if (fLdapURL && NULL != g_pld)
  2267. {
  2268. myLdapGetDSHostName(g_pld, &pwszHostName);
  2269. }
  2270. wsprintf(wszKey, L"%u", iKey);
  2271. pwszMessageText = myGetErrorMessageText(hrPublish, TRUE);
  2272. if (NULL == pwszMessageText)
  2273. {
  2274. pwszMessageText = myHResultToStringRaw(awchr, hrPublish);
  2275. }
  2276. cpwsz = 0;
  2277. apwsz[cpwsz++] = wszKey;
  2278. apwsz[cpwsz++] = pwszURL;
  2279. apwsz[cpwsz++] = pwszMessageText;
  2280. LogMsg = fDelta?
  2281. MSG_E_DELTA_CRL_PUBLICATION : MSG_E_BASE_CRL_PUBLICATION;
  2282. if (NULL != pwszHostName)
  2283. {
  2284. LogMsg = fDelta?
  2285. MSG_E_DELTA_CRL_PUBLICATION_HOST_NAME :
  2286. MSG_E_BASE_CRL_PUBLICATION_HOST_NAME;
  2287. }
  2288. else
  2289. {
  2290. pwszHostName = L"";
  2291. }
  2292. apwsz[cpwsz++] = pwszHostName;
  2293. apwsz[cpwsz++] = NULL != pwszError? L"\n" : L"";
  2294. apwsz[cpwsz++] = NULL != pwszError? pwszError : L"";
  2295. CSASSERT(ARRAYSIZE(apwsz) >= cpwsz);
  2296. if (CERTLOG_ERROR <= g_dwLogLevel)
  2297. {
  2298. hr = LogEvent(EVENTLOG_ERROR_TYPE, LogMsg, cpwsz, apwsz);
  2299. _PrintIfError(hr, "LogEvent");
  2300. }
  2301. //error:
  2302. if (NULL != pwszMessageText && awchr != pwszMessageText)
  2303. {
  2304. LocalFree(const_cast<WCHAR *>(pwszMessageText));
  2305. }
  2306. }
  2307. HRESULT
  2308. crlWriteCRLToURL(
  2309. IN BOOL fDelta,
  2310. IN BOOL iKey,
  2311. IN WCHAR const *pwszURL,
  2312. IN BYTE const *pbCRL,
  2313. IN DWORD cbCRL,
  2314. OUT DWORD *pPublishFlags)
  2315. {
  2316. HRESULT hr;
  2317. WCHAR const *pwsz2;
  2318. WCHAR *pwszDup = NULL;
  2319. WCHAR *pwszT;
  2320. WCHAR awcPrefix[6]; // file:/ftp:/http:/ldap: and trailing '\0'
  2321. DWORD ErrorFlags;
  2322. WCHAR *pwszError = NULL;
  2323. *pPublishFlags = 0;
  2324. ErrorFlags = CPF_BADURL_ERROR;
  2325. hr = crlParseURLPrefix(
  2326. pwszURL,
  2327. ARRAYSIZE(awcPrefix),
  2328. awcPrefix,
  2329. &pwsz2);
  2330. _JumpIfError(hr, error, "crlParseURLPrefix");
  2331. DBGPRINT((
  2332. DBG_SS_CERTSRV,
  2333. "crlWriteCRLToURL: \"%ws\" %ws\n",
  2334. awcPrefix,
  2335. pwsz2));
  2336. if (0 == LSTRCMPIS(awcPrefix, L"file:"))
  2337. {
  2338. ErrorFlags = CPF_FILE_ERROR;
  2339. // tricky
  2340. hr = CRLWriteToLockedFile(pbCRL, cbCRL, FALSE, pwsz2);
  2341. _JumpIfError(hr, error, "CRLWriteToLockedFile");
  2342. }
  2343. else if (0 == LSTRCMPIS(awcPrefix, L"ftp:"))
  2344. {
  2345. ErrorFlags = CPF_FTP_ERROR;
  2346. hr = HRESULT_FROM_WIN32(ERROR_BAD_PATHNAME);
  2347. _JumpError(hr, error, "Publish to ftp:");
  2348. }
  2349. else if (0 == LSTRCMPIS(awcPrefix, L"http:"))
  2350. {
  2351. ErrorFlags = CPF_HTTP_ERROR;
  2352. hr = HRESULT_FROM_WIN32(ERROR_BAD_PATHNAME);
  2353. _JumpError(hr, error, "Publish to http:");
  2354. }
  2355. else if (0 == LSTRCMPIS(awcPrefix, L"ldap:"))
  2356. {
  2357. ErrorFlags = CPF_LDAP_ERROR;
  2358. while (L'/' == *pwsz2)
  2359. {
  2360. pwsz2++;
  2361. }
  2362. hr = myDupString(pwsz2, &pwszDup);
  2363. _JumpIfError(hr, error, "myDupString");
  2364. pwszT = wcschr(pwszDup, L'?');
  2365. if (NULL != pwszT)
  2366. {
  2367. *pwszT = L'\0';
  2368. }
  2369. hr = WriteCRLToDSAttribute(pwszDup, fDelta, pbCRL, cbCRL, &pwszError);
  2370. _JumpIfError(hr, error, "WriteCRLToDSAttribute");
  2371. }
  2372. else
  2373. {
  2374. ErrorFlags = CPF_BADURL_ERROR;
  2375. hr = HRESULT_FROM_WIN32(ERROR_BAD_PATHNAME);
  2376. _JumpError(hr, error, "Publish to unknown URL type");
  2377. }
  2378. CSASSERT(S_OK == hr);
  2379. error:
  2380. if (S_OK != hr)
  2381. {
  2382. *pPublishFlags = ErrorFlags;
  2383. crlLogError(
  2384. fDelta,
  2385. CPF_LDAP_ERROR == ErrorFlags,
  2386. iKey,
  2387. pwszURL,
  2388. pwszError,
  2389. hr);
  2390. }
  2391. if (NULL != pwszError)
  2392. {
  2393. LocalFree(pwszError);
  2394. }
  2395. if (NULL != pwszDup)
  2396. {
  2397. LocalFree(pwszDup);
  2398. }
  2399. return(hr);
  2400. }
  2401. HRESULT
  2402. crlWriteCRLToURLList(
  2403. IN BOOL fDelta,
  2404. IN DWORD iKey,
  2405. IN WCHAR const * const *papwszURLs,
  2406. IN BYTE const *pbCRL,
  2407. IN DWORD cbCRL,
  2408. IN OUT DWORD *pCRLPublishFlags,
  2409. OUT WCHAR **ppwszCRLError)
  2410. {
  2411. HRESULT hr = S_OK;
  2412. HRESULT hr2;
  2413. DWORD PublishFlags;
  2414. *ppwszCRLError = NULL;
  2415. // publish this CRL in multiple places
  2416. if (NULL != papwszURLs)
  2417. {
  2418. WCHAR const * const *ppwsz;
  2419. for (ppwsz = papwszURLs; NULL != *ppwsz; ppwsz++)
  2420. {
  2421. PublishFlags = 0;
  2422. hr2 = crlWriteCRLToURL(
  2423. fDelta,
  2424. iKey,
  2425. *ppwsz,
  2426. pbCRL,
  2427. cbCRL,
  2428. &PublishFlags);
  2429. *pCRLPublishFlags |= PublishFlags;
  2430. if (S_OK != hr2)
  2431. {
  2432. if (S_OK == hr)
  2433. {
  2434. hr = hr2; // Save first error
  2435. }
  2436. _PrintError(hr2, "crlWriteCRLToURL");
  2437. hr2 = myAppendString(*ppwsz, L"\n", ppwszCRLError);
  2438. _PrintIfError(hr2, "myAppendString");
  2439. if (S_OK == hr)
  2440. {
  2441. hr = hr2; // Save first error
  2442. }
  2443. }
  2444. }
  2445. }
  2446. //error:
  2447. return(hr);
  2448. }
  2449. HRESULT
  2450. crlWriteCRLToCAStore(
  2451. IN BOOL fDelta,
  2452. IN DWORD iKey,
  2453. IN BYTE const *pbCRL,
  2454. IN DWORD cbCRL,
  2455. IN CERT_CONTEXT const *pccCA)
  2456. {
  2457. HRESULT hr;
  2458. HCERTSTORE hStore = NULL;
  2459. CRL_CONTEXT const *pCRLStore = NULL;
  2460. CRL_CONTEXT const *pCRLNew = NULL;
  2461. BOOL fFound = FALSE;
  2462. hStore = CertOpenStore(
  2463. CERT_STORE_PROV_SYSTEM_REGISTRY_W,
  2464. X509_ASN_ENCODING,
  2465. NULL, // hProv
  2466. CERT_SYSTEM_STORE_LOCAL_MACHINE,
  2467. wszCA_CERTSTORE);
  2468. if (NULL == hStore)
  2469. {
  2470. hr = myHLastError();
  2471. _JumpError(hr, error, "CertOpenStore");
  2472. }
  2473. for (;;)
  2474. {
  2475. DWORD dwCryptFlags;
  2476. BOOL fIsDeltaCRL;
  2477. CRL_CONTEXT const *pCRL;
  2478. dwCryptFlags = CERT_STORE_SIGNATURE_FLAG;
  2479. pCRLStore = CertGetCRLFromStore(
  2480. hStore,
  2481. pccCA,
  2482. pCRLStore,
  2483. &dwCryptFlags);
  2484. if (NULL == pCRLStore)
  2485. {
  2486. break;
  2487. }
  2488. // delete this CRL from the store ONLY if the CRL signature matches
  2489. // this CA context's public key
  2490. if (0 != dwCryptFlags)
  2491. {
  2492. continue; // no match -- skip
  2493. }
  2494. hr = myIsDeltaCRL(pCRLStore, &fIsDeltaCRL);
  2495. _JumpIfError(hr, error, "myIsDeltaCRL");
  2496. if (fIsDeltaCRL)
  2497. {
  2498. if (!fDelta)
  2499. {
  2500. continue; // no match -- skip Delta CRLs
  2501. }
  2502. }
  2503. else
  2504. {
  2505. if (fDelta)
  2506. {
  2507. continue; // no match -- skip Base CRLs
  2508. }
  2509. }
  2510. // See if it has already been published
  2511. if (cbCRL == pCRLStore->cbCrlEncoded &&
  2512. 0 == memcmp(pbCRL, pCRLStore->pbCrlEncoded, cbCRL))
  2513. {
  2514. fFound = TRUE;
  2515. continue; // exact match -- already published
  2516. }
  2517. pCRL = CertDuplicateCRLContext(pCRLStore);
  2518. if (!CertDeleteCRLFromStore(pCRL))
  2519. {
  2520. hr = myHLastError();
  2521. _JumpError(hr, error, "CertDeleteCRLFromStore");
  2522. }
  2523. }
  2524. if (!fFound)
  2525. {
  2526. pCRLNew = CertCreateCRLContext(X509_ASN_ENCODING, pbCRL, cbCRL);
  2527. if (NULL == pCRLNew)
  2528. {
  2529. hr = myHLastError();
  2530. _JumpError(hr, error, "CertCreateCRLContext");
  2531. }
  2532. if (!CertAddCRLContextToStore(
  2533. hStore,
  2534. pCRLNew,
  2535. CERT_STORE_ADD_ALWAYS,
  2536. NULL))
  2537. {
  2538. hr = myHLastError();
  2539. _JumpError(hr, error, "CertAddCRLContextToStore");
  2540. }
  2541. }
  2542. hr = S_OK;
  2543. error:
  2544. if (S_OK != hr)
  2545. {
  2546. crlLogError(fDelta, FALSE, iKey, g_pwszIntermediateCAStore, NULL, hr);
  2547. }
  2548. if (NULL != pCRLNew)
  2549. {
  2550. CertFreeCRLContext(pCRLNew);
  2551. }
  2552. if (NULL != pCRLStore)
  2553. {
  2554. CertFreeCRLContext(pCRLStore);
  2555. }
  2556. if (NULL != hStore)
  2557. {
  2558. CertCloseStore(hStore, CERT_CLOSE_STORE_CHECK_FLAG);
  2559. }
  2560. return(hr);
  2561. }
  2562. HRESULT
  2563. crlPublishGeneratedCRL(
  2564. IN DWORD RowId,
  2565. IN FILETIME const *pftCurrent,
  2566. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  2567. IN BOOL fDelta,
  2568. IN DWORD iKey,
  2569. IN BYTE const *pbCRL,
  2570. IN DWORD cbCRL,
  2571. IN CACTX const *pCAContext,
  2572. OUT BOOL *pfRetryNeeded,
  2573. OUT HRESULT *phrCRLPublish)
  2574. {
  2575. HRESULT hr;
  2576. HRESULT hrCRLPublish;
  2577. DWORD CRLPublishFlags;
  2578. WCHAR *pwszCRLError = NULL;
  2579. *pfRetryNeeded = FALSE;
  2580. hrCRLPublish = S_OK;
  2581. CRLPublishFlags = 0;
  2582. // first verify CRL signature with the CA Cert public key (catch bad CSPs)
  2583. if (!CryptVerifyCertificateSignature(
  2584. NULL,
  2585. X509_ASN_ENCODING,
  2586. pbCRL,
  2587. cbCRL,
  2588. &pCAContext->pccCA->pCertInfo->SubjectPublicKeyInfo))
  2589. {
  2590. hr = myHLastError();
  2591. _PrintError(hr, "CryptVerifyCertificateSignature");
  2592. hrCRLPublish = hr; // save first error
  2593. CRLPublishFlags |= CPF_SIGNATURE_ERROR;
  2594. }
  2595. else
  2596. {
  2597. hr = crlWriteCRLToCAStore(
  2598. fDelta,
  2599. iKey,
  2600. pbCRL,
  2601. cbCRL,
  2602. pCAContext->pccCA);
  2603. if (S_OK != hr)
  2604. {
  2605. _PrintError(hr, "crlWriteCRLToCAStore");
  2606. hrCRLPublish = hr;
  2607. CRLPublishFlags |= CPF_CASTORE_ERROR;
  2608. }
  2609. hr = crlWriteCRLToURLList(
  2610. fDelta,
  2611. iKey,
  2612. fDelta?
  2613. pCAContext->papwszDeltaCRLFiles :
  2614. pCAContext->papwszCRLFiles,
  2615. pbCRL,
  2616. cbCRL,
  2617. &CRLPublishFlags,
  2618. &pwszCRLError);
  2619. if (S_OK != hr)
  2620. {
  2621. _PrintError(hr, "crlWriteCRLToURLList");
  2622. if (S_OK == hrCRLPublish)
  2623. {
  2624. hrCRLPublish = hr; // save first error
  2625. }
  2626. }
  2627. }
  2628. if (S_OK != hrCRLPublish)
  2629. {
  2630. *pfRetryNeeded = TRUE;
  2631. }
  2632. hr = crlUpdateCRLPublishStateInDB(
  2633. RowId,
  2634. pftCurrent,
  2635. hrCRLPublish,
  2636. CRLPublishFlags,
  2637. pwszUserName,
  2638. pwszCRLError);
  2639. _JumpIfError(hr, error, "crlUpdateCRLPublishStateInDB");
  2640. error:
  2641. *phrCRLPublish = hrCRLPublish;
  2642. if (NULL != pwszCRLError)
  2643. {
  2644. LocalFree(pwszCRLError);
  2645. }
  2646. return(hr);
  2647. }
  2648. HRESULT
  2649. crlSignAndSaveCRL(
  2650. IN DWORD CRLNumber,
  2651. IN DWORD CRLNumberBaseMin, // 0 implies Base CRL; else Delta CRL
  2652. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  2653. IN BOOL fShadowDelta, // empty delta CRL with new MinBaseCRL
  2654. IN CACTX const *pCAContext,
  2655. IN DWORD cCRL,
  2656. IN CRL_ENTRY *aCRL,
  2657. IN FILETIME const *pftCurrent,
  2658. IN FILETIME const *pftThisUpdate, // includes skew
  2659. OPTIONAL IN FILETIME const *pftNextUpdate, // includes skew & overlap
  2660. IN FILETIME const *pftThisPublish,
  2661. OPTIONAL IN FILETIME const *pftNextPublish,
  2662. OPTIONAL IN FILETIME const *pftQuery,
  2663. IN FILETIME const *pftPropagationComplete,
  2664. OUT BOOL *pfRetryNeeded,
  2665. OUT HRESULT *phrCRLPublish)
  2666. {
  2667. HRESULT hr;
  2668. CRL_INFO CRLInfo;
  2669. DWORD i;
  2670. DWORD cb;
  2671. DWORD cbCRL;
  2672. BYTE *pbCrlEncoded = NULL;
  2673. BYTE *pbCRL = NULL;
  2674. #define CCRLEXT 6
  2675. CERT_EXTENSION aext[CCRLEXT];
  2676. BYTE *apbFree[CCRLEXT];
  2677. DWORD cpbFree = 0;
  2678. DWORD RowId;
  2679. *pfRetryNeeded = FALSE;
  2680. *phrCRLPublish = S_OK;
  2681. ZeroMemory(&CRLInfo, sizeof(CRLInfo));
  2682. CRLInfo.dwVersion = CRL_V2;
  2683. CRLInfo.SignatureAlgorithm.pszObjId = pCAContext->pszObjIdSignatureAlgorithm;
  2684. CRLInfo.Issuer.pbData = pCAContext->pccCA->pCertInfo->Subject.pbData;
  2685. CRLInfo.Issuer.cbData = pCAContext->pccCA->pCertInfo->Subject.cbData;
  2686. CRLInfo.ThisUpdate = *pftThisUpdate;
  2687. if (NULL != pftNextUpdate)
  2688. {
  2689. CRLInfo.NextUpdate = *pftNextUpdate;
  2690. }
  2691. CRLInfo.cCRLEntry = cCRL;
  2692. CRLInfo.rgCRLEntry = aCRL;
  2693. CRLInfo.cExtension = 0;
  2694. CRLInfo.rgExtension = aext;
  2695. ZeroMemory(aext, sizeof(aext));
  2696. if (NULL != pCAContext->KeyAuthority2CRL.pbData)
  2697. {
  2698. aext[CRLInfo.cExtension].pszObjId = szOID_AUTHORITY_KEY_IDENTIFIER2;
  2699. if (EDITF_ENABLEAKICRITICAL & g_CRLEditFlags)
  2700. {
  2701. aext[CRLInfo.cExtension].fCritical = TRUE;
  2702. }
  2703. aext[CRLInfo.cExtension].Value = pCAContext->KeyAuthority2CRL;
  2704. CRLInfo.cExtension++;
  2705. }
  2706. if (!myEncodeObject(
  2707. X509_ASN_ENCODING,
  2708. X509_INTEGER,
  2709. &pCAContext->NameId,
  2710. 0,
  2711. CERTLIB_USE_LOCALALLOC,
  2712. &aext[CRLInfo.cExtension].Value.pbData,
  2713. &aext[CRLInfo.cExtension].Value.cbData))
  2714. {
  2715. hr = myHLastError();
  2716. _JumpError(hr, error, "myEncodeObject");
  2717. }
  2718. aext[CRLInfo.cExtension].pszObjId = szOID_CERTSRV_CA_VERSION;
  2719. apbFree[cpbFree++] = aext[CRLInfo.cExtension].Value.pbData,
  2720. CRLInfo.cExtension++;
  2721. if (!myEncodeObject(
  2722. X509_ASN_ENCODING,
  2723. X509_INTEGER,
  2724. &CRLNumber,
  2725. 0,
  2726. CERTLIB_USE_LOCALALLOC,
  2727. &aext[CRLInfo.cExtension].Value.pbData,
  2728. &aext[CRLInfo.cExtension].Value.cbData))
  2729. {
  2730. hr = myHLastError();
  2731. _JumpError(hr, error, "myEncodeObject");
  2732. }
  2733. aext[CRLInfo.cExtension].pszObjId = szOID_CRL_NUMBER;
  2734. apbFree[cpbFree++] = aext[CRLInfo.cExtension].Value.pbData;
  2735. if ((CRLF_CRLNUMBER_CRITICAL & g_dwCRLFlags) && 0 == CRLNumberBaseMin)
  2736. {
  2737. aext[CRLInfo.cExtension].fCritical = TRUE;
  2738. }
  2739. CRLInfo.cExtension++;
  2740. // NextPublish is the earliest the client should look for a newer CRL.
  2741. if (NULL != pftNextPublish)
  2742. {
  2743. if (!myEncodeObject(
  2744. X509_ASN_ENCODING,
  2745. X509_CHOICE_OF_TIME,
  2746. pftNextPublish,
  2747. 0,
  2748. CERTLIB_USE_LOCALALLOC,
  2749. &aext[CRLInfo.cExtension].Value.pbData,
  2750. &aext[CRLInfo.cExtension].Value.cbData))
  2751. {
  2752. hr = myHLastError();
  2753. _JumpError(hr, error, "myEncodeObject");
  2754. }
  2755. aext[CRLInfo.cExtension].pszObjId = szOID_CRL_NEXT_PUBLISH;
  2756. apbFree[cpbFree++] = aext[CRLInfo.cExtension].Value.pbData,
  2757. CRLInfo.cExtension++;
  2758. }
  2759. if (0 != CRLNumberBaseMin) // if Delta CRL
  2760. {
  2761. if (!myEncodeObject(
  2762. X509_ASN_ENCODING,
  2763. X509_INTEGER,
  2764. &CRLNumberBaseMin,
  2765. 0,
  2766. CERTLIB_USE_LOCALALLOC,
  2767. &aext[CRLInfo.cExtension].Value.pbData,
  2768. &aext[CRLInfo.cExtension].Value.cbData))
  2769. {
  2770. hr = myHLastError();
  2771. _JumpError(hr, error, "myEncodeObject");
  2772. }
  2773. aext[CRLInfo.cExtension].pszObjId = szOID_DELTA_CRL_INDICATOR;
  2774. aext[CRLInfo.cExtension].fCritical = TRUE;
  2775. apbFree[cpbFree++] = aext[CRLInfo.cExtension].Value.pbData,
  2776. CRLInfo.cExtension++;
  2777. // Add a CDP to base and delta CRLs to make it easier to manually
  2778. // publish an off-line CA's CRLs to the correct DS location.
  2779. if (NULL != pCAContext->CDPCRLDelta.pbData)
  2780. {
  2781. aext[CRLInfo.cExtension].pszObjId = szOID_CRL_SELF_CDP;
  2782. aext[CRLInfo.cExtension].Value = pCAContext->CDPCRLDelta;
  2783. CRLInfo.cExtension++;
  2784. }
  2785. }
  2786. else
  2787. {
  2788. // else if Base CRL (and if delta CRLs are enabled)
  2789. if (!g_fDeltaCRLPublishDisabled &&
  2790. NULL != pCAContext->CDPCRLFreshest.pbData)
  2791. {
  2792. aext[CRLInfo.cExtension].pszObjId = szOID_FRESHEST_CRL;
  2793. aext[CRLInfo.cExtension].Value = pCAContext->CDPCRLFreshest;
  2794. CRLInfo.cExtension++;
  2795. }
  2796. // Add a CDP to base and delta CRLs to make it easier to manually
  2797. // publish an off-line CA's CRLs to the correct DS location.
  2798. if (NULL != pCAContext->CDPCRLBase.pbData)
  2799. {
  2800. aext[CRLInfo.cExtension].pszObjId = szOID_CRL_SELF_CDP;
  2801. aext[CRLInfo.cExtension].Value = pCAContext->CDPCRLBase;
  2802. CRLInfo.cExtension++;
  2803. }
  2804. }
  2805. CSASSERT(ARRAYSIZE(aext) >= CRLInfo.cExtension);
  2806. if (!myEncodeObject(
  2807. X509_ASN_ENCODING,
  2808. X509_CERT_CRL_TO_BE_SIGNED,
  2809. &CRLInfo,
  2810. 0,
  2811. CERTLIB_USE_LOCALALLOC,
  2812. &pbCrlEncoded, // pbEncoded
  2813. &cb))
  2814. {
  2815. hr = myHLastError();
  2816. _JumpError(hr, error, "myEncodeObject");
  2817. }
  2818. hr = myEncodeSignedContent(
  2819. pCAContext->hProvCA,
  2820. X509_ASN_ENCODING,
  2821. pCAContext->pszObjIdSignatureAlgorithm,
  2822. pbCrlEncoded,
  2823. cb,
  2824. CERTLIB_USE_LOCALALLOC,
  2825. &pbCRL,
  2826. &cbCRL); // use LocalAlloc*
  2827. _JumpIfError(hr, error, "myEncodeSignedContent");
  2828. hr = crlWriteCRLToDB(
  2829. CRLNumber, // CRLNumber
  2830. CRLNumberBaseMin, // CRLMinBase: 0 implies Base CRL
  2831. pwszUserName,
  2832. fShadowDelta,
  2833. pCAContext->NameId, // CRLNameId
  2834. cCRL, // CRLCount
  2835. &CRLInfo.ThisUpdate, // pftThisUpdate
  2836. pftNextUpdate,
  2837. pftThisPublish, // pftThisPublish
  2838. pftNextPublish, // pftNextPublish
  2839. pftQuery,
  2840. pftPropagationComplete,
  2841. pbCRL, // pbCRL
  2842. cbCRL, // cbCRL
  2843. &RowId);
  2844. _JumpIfError(hr, error, "crlWriteCRLToDB");
  2845. hr = crlPublishGeneratedCRL(
  2846. RowId,
  2847. pftCurrent,
  2848. pwszUserName,
  2849. 0 != CRLNumberBaseMin, // fDelta
  2850. pCAContext->iKey,
  2851. pbCRL, // pbCRL
  2852. cbCRL, // cbCRL
  2853. pCAContext,
  2854. pfRetryNeeded,
  2855. phrCRLPublish);
  2856. _JumpIfError(hr, error, "crlPublishGeneratedCRL");
  2857. error:
  2858. CSASSERT(ARRAYSIZE(aext) >= CRLInfo.cExtension);
  2859. CSASSERT(ARRAYSIZE(apbFree) >= cpbFree);
  2860. for (i = 0; i < cpbFree; i++)
  2861. {
  2862. CSASSERT(NULL != apbFree[i]);
  2863. LocalFree(apbFree[i]);
  2864. }
  2865. if (NULL != pbCrlEncoded)
  2866. {
  2867. LocalFree(pbCrlEncoded);
  2868. }
  2869. if (NULL != pbCRL)
  2870. {
  2871. LocalFree(pbCRL);
  2872. }
  2873. return(myHError(hr));
  2874. }
  2875. ///////////////////////////////////////////////////
  2876. // crlPublishCRLFromCAContext is called to build and save one CRL.
  2877. //
  2878. HRESULT
  2879. crlPublishCRLFromCAContext(
  2880. IN DWORD CRLNumber,
  2881. IN DWORD CRLNumberBaseMin, // 0 implies Base CRL; else Delta CRL
  2882. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  2883. IN BOOL fShadowDelta, // empty delta CRL with new MinBaseCRL
  2884. IN CACTX const *pCAContext,
  2885. IN FILETIME const *pftCurrent,
  2886. IN FILETIME ftThisUpdate, // clamped by CA cert
  2887. IN OUT FILETIME *pftNextUpdate, // clamped by CA cert
  2888. OPTIONAL OUT BOOL *pfClamped,
  2889. OPTIONAL IN FILETIME const *pftQuery,
  2890. IN FILETIME const *pftThisPublish,
  2891. IN FILETIME const *pftNextPublish,
  2892. IN FILETIME const *pftLastPublishBase,
  2893. IN FILETIME const *pftPropagationComplete,
  2894. OUT BOOL *pfRetryNeeded,
  2895. OUT HRESULT *phrPublish)
  2896. {
  2897. HRESULT hr;
  2898. DWORD cCRL = 0;
  2899. CRL_ENTRY *aCRL = NULL;
  2900. VOID *pvBlockSerial = NULL;
  2901. CERT_INFO const *pCertInfo = pCAContext->pccCA->pCertInfo;
  2902. *pfRetryNeeded = FALSE;
  2903. *phrPublish = S_OK;
  2904. hr = S_OK;
  2905. __try
  2906. {
  2907. if (!fShadowDelta)
  2908. {
  2909. hr = crlBuildCRLArray(
  2910. 0 != CRLNumberBaseMin, // fDelta
  2911. pftQuery,
  2912. pftThisPublish,
  2913. pftLastPublishBase,
  2914. pCAContext->iKey,
  2915. &cCRL,
  2916. &aCRL,
  2917. &pvBlockSerial);
  2918. _JumpIfError(hr, error, "crlBuildCRLArray");
  2919. }
  2920. // Ensure it is not before the CA certificate's start date.
  2921. if (0 > CompareFileTime(&ftThisUpdate, &pCertInfo->NotBefore))
  2922. {
  2923. // clamp
  2924. ftThisUpdate = pCertInfo->NotBefore;
  2925. }
  2926. // Ensure it is not after the CA certificate's end date.
  2927. if (NULL != pfClamped)
  2928. {
  2929. //init to FALSE
  2930. *pfClamped = FALSE;
  2931. }
  2932. if (0 == (CRLF_PUBLISH_EXPIRED_CERT_CRLS & g_dwCRLFlags) &&
  2933. 0 < CompareFileTime(pftNextUpdate, &pCertInfo->NotAfter))
  2934. {
  2935. // clamp
  2936. *pftNextUpdate = pCertInfo->NotAfter;
  2937. if (NULL != pfClamped)
  2938. {
  2939. *pfClamped = TRUE;
  2940. }
  2941. if (pCAContext->iKey < g_pCAContextCurrent->iKey)
  2942. {
  2943. pftNextUpdate = NULL;
  2944. pftNextPublish = NULL;
  2945. }
  2946. }
  2947. #ifdef DBG_CERTSRV_DEBUG_PRINT
  2948. {
  2949. WCHAR *pwszNow = NULL;
  2950. WCHAR *pwszQuery = NULL;
  2951. WCHAR *pwszThisUpdate = NULL;
  2952. WCHAR *pwszNextUpdate = NULL;
  2953. WCHAR const *pwszCRLType = 0 == CRLNumberBaseMin? L"Base" : L"Delta";
  2954. myGMTFileTimeToWszLocalTime(pftThisPublish, TRUE, &pwszNow);
  2955. if (NULL != pftQuery)
  2956. {
  2957. myGMTFileTimeToWszLocalTime(pftQuery, TRUE, &pwszQuery);
  2958. }
  2959. myGMTFileTimeToWszLocalTime(&ftThisUpdate, TRUE, &pwszThisUpdate);
  2960. if (NULL != pftNextUpdate)
  2961. {
  2962. myGMTFileTimeToWszLocalTime(pftNextUpdate, TRUE, &pwszNextUpdate);
  2963. }
  2964. DBGPRINT((
  2965. DBG_SS_ERROR | DBG_SS_CERTSRV,
  2966. "crlPublishCRLFromCAContext(tid=%d, CA Version=%u.%u): %ws CRL %u,%hs %u\n"
  2967. " %ws CRL Publishing now(%ws)\n"
  2968. " %ws CRL Query(%ws)\n"
  2969. " %ws CRL ThisUpdate(%ws)\n"
  2970. " %ws CRL NextUpdate(%ws)\n",
  2971. GetCurrentThreadId(),
  2972. pCAContext->iCert,
  2973. pCAContext->iKey,
  2974. pwszCRLType,
  2975. CRLNumber,
  2976. 0 == CRLNumberBaseMin? "" : " Min Base",
  2977. CRLNumberBaseMin,
  2978. pwszCRLType,
  2979. pwszNow,
  2980. pwszCRLType,
  2981. NULL != pftQuery? pwszQuery : L"None",
  2982. pwszCRLType,
  2983. pwszThisUpdate,
  2984. pwszCRLType,
  2985. pwszNextUpdate));
  2986. if (NULL != pwszNow)
  2987. {
  2988. LocalFree(pwszNow);
  2989. }
  2990. if (NULL != pwszQuery)
  2991. {
  2992. LocalFree(pwszQuery);
  2993. }
  2994. if (NULL != pwszThisUpdate)
  2995. {
  2996. LocalFree(pwszThisUpdate);
  2997. }
  2998. if (NULL != pwszNextUpdate)
  2999. {
  3000. LocalFree(pwszNextUpdate);
  3001. }
  3002. }
  3003. #endif //DBG_CERTSRV_DEBUG_PRINT
  3004. hr = CertSrvTestServerState();
  3005. _JumpIfError(hr, error, "CertSrvTestServerState");
  3006. hr = crlSignAndSaveCRL(
  3007. CRLNumber,
  3008. CRLNumberBaseMin,
  3009. pwszUserName,
  3010. fShadowDelta,
  3011. pCAContext,
  3012. cCRL,
  3013. aCRL,
  3014. pftCurrent,
  3015. &ftThisUpdate,
  3016. pftNextUpdate,
  3017. pftThisPublish, // - no skew or overlap
  3018. pftNextPublish, // no skew
  3019. pftQuery,
  3020. pftPropagationComplete,
  3021. pfRetryNeeded,
  3022. phrPublish);
  3023. _JumpIfError(hr, error, "crlSignAndSaveCRL");
  3024. CONSOLEPRINT4((
  3025. DBG_SS_CERTSRV,
  3026. "Published %hs CRL #%u for key %u.%u\n",
  3027. 0 == CRLNumberBaseMin? "Base" : "Delta",
  3028. CRLNumber,
  3029. pCAContext->iCert,
  3030. pCAContext->iKey));
  3031. CSASSERT(S_OK == hr);
  3032. }
  3033. __except(hr = myHEXCEPTIONCODE(), EXCEPTION_EXECUTE_HANDLER)
  3034. {
  3035. }
  3036. error:
  3037. crlFreeCRLArray(pvBlockSerial, aCRL);
  3038. CSASSERT(S_OK == hr || FAILED(hr));
  3039. return(hr);
  3040. }
  3041. DWORD g_aColCRLNumber[] = {
  3042. #define ICOL_CRLNUMBER 0
  3043. DTI_CRLTABLE | DTL_NUMBER,
  3044. };
  3045. HRESULT
  3046. crlGetNextCRLNumber(
  3047. OUT DWORD *pdwCRLNumber)
  3048. {
  3049. HRESULT hr;
  3050. CERTVIEWRESTRICTION acvr[1];
  3051. CERTVIEWRESTRICTION *pcvr;
  3052. IEnumCERTDBRESULTROW *pView = NULL;
  3053. DWORD Zero = 0;
  3054. CERTDBRESULTROW aResult[1];
  3055. CERTDBRESULTROW *pResult;
  3056. DWORD celtFetched;
  3057. BOOL fResultActive = FALSE;
  3058. *pdwCRLNumber = 1;
  3059. // Set up restrictions as follows:
  3060. pcvr = acvr;
  3061. // CRLNumber > 0 (indexed column)
  3062. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_NUMBER;
  3063. pcvr->SeekOperator = CVR_SEEK_GT;
  3064. pcvr->SortOrder = CVR_SORT_DESCEND; // highest CRL Number first
  3065. pcvr->pbValue = (BYTE *) &Zero;
  3066. pcvr->cbValue = sizeof(Zero);
  3067. pcvr++;
  3068. CSASSERT(ARRAYSIZE(acvr) == SAFE_SUBTRACT_POINTERS(pcvr, acvr));
  3069. celtFetched = 0;
  3070. hr = g_pCertDB->OpenView(
  3071. ARRAYSIZE(acvr),
  3072. acvr,
  3073. ARRAYSIZE(g_aColCRLNumber),
  3074. g_aColCRLNumber,
  3075. 0, // no worker thread
  3076. &pView);
  3077. _JumpIfError(hr, error, "OpenView");
  3078. hr = pView->Next(NULL, ARRAYSIZE(aResult), aResult, &celtFetched);
  3079. if (S_FALSE == hr)
  3080. {
  3081. if (0 == celtFetched)
  3082. {
  3083. hr = S_OK;
  3084. goto error;
  3085. }
  3086. }
  3087. _JumpIfError(hr, error, "Next");
  3088. fResultActive = TRUE;
  3089. CSASSERT(ARRAYSIZE(aResult) == celtFetched);
  3090. pResult = &aResult[0];
  3091. CSASSERT(ARRAYSIZE(g_aColCRLNumber) == pResult->ccol);
  3092. CSASSERT(NULL != pResult->acol[ICOL_CRLNUMBER].pbValue);
  3093. CSASSERT(PROPTYPE_LONG == (PROPTYPE_MASK & pResult->acol[ICOL_CRLNUMBER].Type));
  3094. CSASSERT(sizeof(*pdwCRLNumber) == pResult->acol[ICOL_CRLNUMBER].cbValue);
  3095. *pdwCRLNumber = 1 + *(DWORD *) pResult->acol[ICOL_CRLNUMBER].pbValue;
  3096. hr = S_OK;
  3097. error:
  3098. if (NULL != pView)
  3099. {
  3100. if (fResultActive)
  3101. {
  3102. pView->ReleaseResultRow(celtFetched, aResult);
  3103. }
  3104. pView->Release();
  3105. }
  3106. DBGPRINT((
  3107. DBG_SS_CERTSRVI,
  3108. "crlGetNextCRLNumber -> %u\n",
  3109. *pdwCRLNumber));
  3110. return(hr);
  3111. }
  3112. #undef ICOL_CRLNUMBER
  3113. //+--------------------------------------------------------------------------
  3114. // crlGetBaseCRLInfo -- get database column data for the most recent Base CRL
  3115. //
  3116. //---------------------------------------------------------------------------
  3117. DWORD g_aColBaseCRLInfo[] = {
  3118. #define ICOLBI_CRLNUMBER 0
  3119. DTI_CRLTABLE | DTL_NUMBER,
  3120. #define ICOLBI_CRLTHISUPDATE 1
  3121. DTI_CRLTABLE | DTL_THISUPDATEDATE,
  3122. #define ICOLBI_CRLNEXTUPDATE 2
  3123. DTI_CRLTABLE | DTL_NEXTUPDATEDATE,
  3124. #define ICOLBI_CRLNAMEID 3
  3125. DTI_CRLTABLE | DTL_NAMEID,
  3126. };
  3127. HRESULT
  3128. crlGetBaseCRLInfo(
  3129. IN FILETIME const *pftCurrent,
  3130. IN BOOL fOldestUnexpiredBase, // else newest propagated CRL
  3131. OUT DWORD *pdwRowId,
  3132. OUT DWORD *pdwCRLNumber,
  3133. OUT FILETIME *pftThisUpdate)
  3134. {
  3135. HRESULT hr;
  3136. CERTVIEWRESTRICTION acvr[2];
  3137. CERTVIEWRESTRICTION *pcvr;
  3138. IEnumCERTDBRESULTROW *pView = NULL;
  3139. DWORD Zero = 0;
  3140. CERTDBRESULTROW aResult[1];
  3141. CERTDBRESULTROW *pResult;
  3142. DWORD celtFetched;
  3143. BOOL fResultActive = FALSE;
  3144. BOOL fSaveCRLInfo;
  3145. DWORD RowId = 0;
  3146. DWORD CRLNumber;
  3147. FILETIME ftThisUpdate;
  3148. FILETIME ftNextUpdate;
  3149. FILETIME ftNextUpdateT;
  3150. *pdwRowId = 0;
  3151. *pdwCRLNumber = 0;
  3152. CRLNumber = 0;
  3153. pftThisUpdate->dwHighDateTime = 0;
  3154. pftThisUpdate->dwLowDateTime = 0;
  3155. if (CRLF_DELTA_USE_OLDEST_UNEXPIRED_BASE & g_dwCRLFlags)
  3156. {
  3157. fOldestUnexpiredBase = TRUE;
  3158. }
  3159. // Set up restrictions as follows:
  3160. pcvr = acvr;
  3161. if (fOldestUnexpiredBase)
  3162. {
  3163. // NextUpdate >= now
  3164. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_NEXTUPDATEDATE;
  3165. pcvr->SeekOperator = CVR_SEEK_GE;
  3166. }
  3167. else // else newest propagated CRL
  3168. {
  3169. // PropagationComplete < now
  3170. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_PROPAGATIONCOMPLETEDATE;
  3171. pcvr->SeekOperator = CVR_SEEK_LT;
  3172. }
  3173. pcvr->SortOrder = CVR_SORT_DESCEND; // Newest CRL first
  3174. pcvr->pbValue = (BYTE *) pftCurrent;
  3175. pcvr->cbValue = sizeof(*pftCurrent);
  3176. pcvr++;
  3177. // CRL Minimum Base == 0 (to eliminate delta CRLs)
  3178. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_MINBASE;
  3179. pcvr->SeekOperator = CVR_SEEK_EQ;
  3180. pcvr->SortOrder = CVR_SORT_NONE;
  3181. pcvr->pbValue = (BYTE *) &Zero;
  3182. pcvr->cbValue = sizeof(Zero);
  3183. pcvr++;
  3184. CSASSERT(ARRAYSIZE(acvr) == SAFE_SUBTRACT_POINTERS(pcvr, acvr));
  3185. celtFetched = 0;
  3186. ZeroMemory(&ftThisUpdate, sizeof(ftThisUpdate));
  3187. ZeroMemory(&ftNextUpdate, sizeof(ftNextUpdate));
  3188. hr = g_pCertDB->OpenView(
  3189. ARRAYSIZE(acvr),
  3190. acvr,
  3191. ARRAYSIZE(g_aColBaseCRLInfo),
  3192. g_aColBaseCRLInfo,
  3193. 0, // no worker thread
  3194. &pView);
  3195. _JumpIfError(hr, error, "OpenView");
  3196. while (0 == RowId || fOldestUnexpiredBase)
  3197. {
  3198. hr = pView->Next(NULL, ARRAYSIZE(aResult), aResult, &celtFetched);
  3199. if (S_FALSE == hr)
  3200. {
  3201. CSASSERT(0 == celtFetched);
  3202. if (0 != RowId)
  3203. {
  3204. break;
  3205. }
  3206. hr = HRESULT_FROM_WIN32(ERROR_FILE_NOT_FOUND);
  3207. }
  3208. _JumpIfError(hr, error, "Next: no matching base CRL");
  3209. fResultActive = TRUE;
  3210. CSASSERT(ARRAYSIZE(aResult) == celtFetched);
  3211. pResult = &aResult[0];
  3212. CSASSERT(ARRAYSIZE(g_aColBaseCRLInfo) == pResult->ccol);
  3213. CSASSERT(NULL != pResult->acol[ICOLBI_CRLNUMBER].pbValue);
  3214. CSASSERT(PROPTYPE_LONG == (PROPTYPE_MASK & pResult->acol[ICOLBI_CRLNUMBER].Type));
  3215. CSASSERT(sizeof(DWORD) == pResult->acol[ICOLBI_CRLNUMBER].cbValue);
  3216. CSASSERT(NULL != pResult->acol[ICOLBI_CRLTHISUPDATE].pbValue);
  3217. CSASSERT(PROPTYPE_DATE == (PROPTYPE_MASK & pResult->acol[ICOLBI_CRLTHISUPDATE].Type));
  3218. CSASSERT(sizeof(FILETIME) == pResult->acol[ICOLBI_CRLTHISUPDATE].cbValue);
  3219. if (NULL != pResult->acol[ICOLBI_CRLNEXTUPDATE].pbValue)
  3220. {
  3221. CSASSERT(PROPTYPE_DATE == (PROPTYPE_MASK & pResult->acol[ICOLBI_CRLNEXTUPDATE].Type));
  3222. CSASSERT(sizeof(FILETIME) == pResult->acol[ICOLBI_CRLNEXTUPDATE].cbValue);
  3223. ftNextUpdateT = *(FILETIME *) pResult->acol[ICOLBI_CRLNEXTUPDATE].pbValue;
  3224. }
  3225. else
  3226. {
  3227. ftNextUpdateT.dwHighDateTime = MAXDWORD;
  3228. ftNextUpdateT.dwLowDateTime = MAXDWORD;
  3229. }
  3230. DBGPRINT((DBG_SS_CERTSRVI, "Query:RowId: %u\n", pResult->rowid));
  3231. DBGPRINT((DBG_SS_CERTSRVI, "Query:CRLNumber: %u\n", *(DWORD *) pResult->acol[ICOLBI_CRLNUMBER].pbValue));
  3232. DBGPRINT((DBG_SS_CERTSRVI, "Query:NameId: 0x%x\n", *(DWORD *) pResult->acol[ICOLBI_CRLNAMEID].pbValue));
  3233. DBGPRINTTIME(NULL, "Query:ThisUpdate", DPT_DATE, *(FILETIME *) pResult->acol[ICOLBI_CRLTHISUPDATE].pbValue);
  3234. DBGPRINTTIME(NULL, "Query:NextUpdate", DPT_DATE, ftNextUpdateT);
  3235. if (0 == RowId)
  3236. {
  3237. // save first matching row info
  3238. fSaveCRLInfo = TRUE;
  3239. }
  3240. else
  3241. {
  3242. // save row info, if looking for
  3243. // oldest unexpired base & this CRL expires before the saved CRL
  3244. // +1 if first > second -- saved > this
  3245. CSASSERT(fOldestUnexpiredBase);
  3246. fSaveCRLInfo = 0 < CompareFileTime(&ftNextUpdate, &ftNextUpdateT);
  3247. }
  3248. if (fSaveCRLInfo)
  3249. {
  3250. CRLNumber = *(DWORD *) pResult->acol[ICOLBI_CRLNUMBER].pbValue;
  3251. ftThisUpdate = *(FILETIME *) pResult->acol[ICOLBI_CRLTHISUPDATE].pbValue;
  3252. ftNextUpdate = ftNextUpdateT;
  3253. RowId = pResult->rowid;
  3254. DBGPRINT((
  3255. DBG_SS_CERTSRVI,
  3256. "Query: SAVED RowId=%u CRLNumber=%u\n",
  3257. pResult->rowid,
  3258. CRLNumber));
  3259. DBGPRINTTIME(NULL, "ftThisUpdate", DPT_DATE, ftThisUpdate);
  3260. }
  3261. pView->ReleaseResultRow(celtFetched, aResult);
  3262. fResultActive = FALSE;
  3263. }
  3264. *pdwRowId = RowId;
  3265. *pdwCRLNumber = CRLNumber;
  3266. *pftThisUpdate = ftThisUpdate;
  3267. DBGPRINTTIME(NULL, "*pftThisUpdate", DPT_DATE, *pftThisUpdate);
  3268. DBGPRINTTIME(NULL, "ftNextUpdate", DPT_DATE, ftNextUpdate);
  3269. hr = S_OK;
  3270. error:
  3271. if (NULL != pView)
  3272. {
  3273. if (fResultActive)
  3274. {
  3275. pView->ReleaseResultRow(celtFetched, aResult);
  3276. }
  3277. pView->Release();
  3278. }
  3279. DBGPRINT((
  3280. DBG_SS_CERTSRV,
  3281. "crlGetBaseCRLInfo -> RowId=%u, CRL=%u\n",
  3282. *pdwRowId,
  3283. *pdwCRLNumber));
  3284. return(hr);
  3285. }
  3286. #undef ICOLBI_CRLNUMBER
  3287. #undef ICOLBI_CRLTHISUPDATE
  3288. #undef ICOLBI_CRLNEXTUPDATE
  3289. #undef ICOLBI_CRLNAMEID
  3290. DWORD g_aColRepublishCRLInfo[] = {
  3291. #define ICOLRI_CRLNUMBER 0
  3292. DTI_CRLTABLE | DTL_NUMBER,
  3293. #define ICOLRI_CRLNAMEID 1
  3294. DTI_CRLTABLE | DTL_NAMEID,
  3295. #define ICOLRI_CRLPUBLISHFLAGS 2
  3296. DTI_CRLTABLE | DTL_PUBLISHFLAGS,
  3297. #define ICOLRI_CRLTHISUPDATE 3
  3298. DTI_CRLTABLE | DTL_THISUPDATEDATE,
  3299. #define ICOLRI_CRLNEXTUPDATE 4
  3300. DTI_CRLTABLE | DTL_NEXTUPDATEDATE,
  3301. #define ICOLRI_CRLRAWCRL 5
  3302. DTI_CRLTABLE | DTL_RAWCRL,
  3303. };
  3304. HRESULT
  3305. crlGetRowIdAndCRL(
  3306. IN BOOL fDelta,
  3307. IN CACTX *pCAContext,
  3308. OUT DWORD *pdwRowId,
  3309. OUT DWORD *pcbCRL,
  3310. OPTIONAL OUT BYTE **ppbCRL,
  3311. OPTIONAL OUT DWORD *pdwCRLPublishFlags)
  3312. {
  3313. HRESULT hr;
  3314. CERTVIEWRESTRICTION acvr[4];
  3315. CERTVIEWRESTRICTION *pcvr;
  3316. IEnumCERTDBRESULTROW *pView = NULL;
  3317. DWORD Zero = 0;
  3318. DWORD NameIdMin;
  3319. DWORD NameIdMax;
  3320. CERTDBRESULTROW aResult[1];
  3321. CERTDBRESULTROW *pResult;
  3322. DWORD celtFetched;
  3323. BOOL fResultActive = FALSE;
  3324. FILETIME ftCurrent;
  3325. DWORD RowId = 0;
  3326. BYTE *pbCRL = NULL;
  3327. DWORD cbCRL;
  3328. *pdwRowId = 0;
  3329. *pcbCRL = 0;
  3330. if (NULL != ppbCRL)
  3331. {
  3332. *ppbCRL = NULL;
  3333. }
  3334. if (NULL != pdwCRLPublishFlags)
  3335. {
  3336. *pdwCRLPublishFlags = 0;
  3337. }
  3338. GetSystemTimeAsFileTime(&ftCurrent);
  3339. DBGPRINT((
  3340. DBG_SS_CERTSRVI,
  3341. "crlGetRowIdAndCRL(%ws, NameId=%x)\n",
  3342. fDelta? L"Delta" : L"Base",
  3343. pCAContext->NameId));
  3344. // Set up restrictions as follows:
  3345. pcvr = acvr;
  3346. // RowId > 0
  3347. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_ROWID;
  3348. pcvr->SeekOperator = CVR_SEEK_GE;
  3349. pcvr->SortOrder = CVR_SORT_DESCEND; // Newest CRL first
  3350. pcvr->pbValue = (BYTE *) &Zero;
  3351. pcvr->cbValue = sizeof(Zero);
  3352. pcvr++;
  3353. if (fDelta)
  3354. {
  3355. // CRL Minimum Base > 0 (to eliminate base CRLs)
  3356. pcvr->SeekOperator = CVR_SEEK_GT;
  3357. }
  3358. else
  3359. {
  3360. // CRL Minimum Base == 0 (to eliminate delta CRLs)
  3361. pcvr->SeekOperator = CVR_SEEK_EQ;
  3362. }
  3363. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_MINBASE;
  3364. pcvr->SortOrder = CVR_SORT_NONE;
  3365. pcvr->pbValue = (BYTE *) &Zero;
  3366. pcvr->cbValue = sizeof(Zero);
  3367. pcvr++;
  3368. // NameId >= MAKECANAMEID(iCert == 0, pCAContext->iKey)
  3369. NameIdMin = MAKECANAMEID(0, pCAContext->iKey);
  3370. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_NAMEID;
  3371. pcvr->SeekOperator = CVR_SEEK_GE;
  3372. pcvr->SortOrder = CVR_SORT_NONE;
  3373. pcvr->pbValue = (BYTE *) &NameIdMin;
  3374. pcvr->cbValue = sizeof(NameIdMin);
  3375. pcvr++;
  3376. // NameId <= MAKECANAMEID(iCert == _16BITMASK, pCAContext->iKey)
  3377. NameIdMax = MAKECANAMEID(_16BITMASK, pCAContext->iKey);
  3378. pcvr->ColumnIndex = DTI_CRLTABLE | DTL_NAMEID;
  3379. pcvr->SeekOperator = CVR_SEEK_LE;
  3380. pcvr->SortOrder = CVR_SORT_NONE;
  3381. pcvr->pbValue = (BYTE *) &NameIdMax;
  3382. pcvr->cbValue = sizeof(NameIdMax);
  3383. pcvr++;
  3384. CSASSERT(ARRAYSIZE(acvr) == SAFE_SUBTRACT_POINTERS(pcvr, acvr));
  3385. celtFetched = 0;
  3386. cbCRL = 0;
  3387. hr = g_pCertDB->OpenView(
  3388. ARRAYSIZE(acvr),
  3389. acvr,
  3390. ((NULL != ppbCRL) ?
  3391. (DWORD) ARRAYSIZE(g_aColRepublishCRLInfo) :
  3392. (DWORD) ARRAYSIZE(g_aColRepublishCRLInfo) - 1 ), // explicitly describe expected return value
  3393. g_aColRepublishCRLInfo,
  3394. 0, // no worker thread
  3395. &pView);
  3396. _JumpIfError(hr, error, "OpenView");
  3397. while (0 == RowId)
  3398. {
  3399. hr = pView->Next(NULL, ARRAYSIZE(aResult), aResult, &celtFetched);
  3400. if (S_FALSE == hr)
  3401. {
  3402. CSASSERT(0 == celtFetched);
  3403. hr = HRESULT_FROM_WIN32(ERROR_FILE_NOT_FOUND);
  3404. }
  3405. _JumpIfErrorStr2(
  3406. hr,
  3407. error,
  3408. "Next: no matching CRL",
  3409. fDelta? L"delta" : L"base",
  3410. fDelta? hr : S_OK);
  3411. fResultActive = TRUE;
  3412. CSASSERT(ARRAYSIZE(aResult) == celtFetched);
  3413. pResult = &aResult[0];
  3414. CSASSERT(ARRAYSIZE(g_aColRepublishCRLInfo) == pResult->ccol);
  3415. // verify CRLNumber data & schema
  3416. CSASSERT(NULL != pResult->acol[ICOLRI_CRLNUMBER].pbValue);
  3417. CSASSERT(
  3418. PROPTYPE_LONG ==
  3419. (PROPTYPE_MASK & pResult->acol[ICOLRI_CRLNUMBER].Type));
  3420. CSASSERT(sizeof(DWORD) == pResult->acol[ICOLRI_CRLNUMBER].cbValue);
  3421. // verify ThisUpdate data & schema
  3422. CSASSERT(NULL != pResult->acol[ICOLRI_CRLTHISUPDATE].pbValue);
  3423. CSASSERT(
  3424. PROPTYPE_DATE ==
  3425. (PROPTYPE_MASK & pResult->acol[ICOLRI_CRLTHISUPDATE].Type));
  3426. CSASSERT(
  3427. sizeof(FILETIME) ==
  3428. pResult->acol[ICOLRI_CRLTHISUPDATE].cbValue);
  3429. // verify NextUpdate data & schema
  3430. if (NULL != pResult->acol[ICOLRI_CRLNEXTUPDATE].pbValue)
  3431. {
  3432. CSASSERT(
  3433. PROPTYPE_DATE ==
  3434. (PROPTYPE_MASK & pResult->acol[ICOLRI_CRLNEXTUPDATE].Type));
  3435. CSASSERT(
  3436. sizeof(FILETIME) ==
  3437. pResult->acol[ICOLRI_CRLNEXTUPDATE].cbValue);
  3438. }
  3439. // verify RawCRL data & schema
  3440. if (NULL != ppbCRL)
  3441. {
  3442. CSASSERT(NULL != pResult->acol[ICOLRI_CRLRAWCRL].pbValue);
  3443. CSASSERT(PROPTYPE_BINARY == (PROPTYPE_MASK & pResult->acol[ICOLRI_CRLRAWCRL].Type));
  3444. }
  3445. // DBGPRINT query results
  3446. DBGPRINT((DBG_SS_CERTSRVI, "Query:RowId: %u\n", pResult->rowid));
  3447. DBGPRINT((
  3448. DBG_SS_CERTSRVI,
  3449. "Query:CRLNumber: %u\n",
  3450. *(DWORD *) pResult->acol[ICOLRI_CRLNUMBER].pbValue));
  3451. DBGPRINT((
  3452. DBG_SS_CERTSRVI,
  3453. "Query:NameId: 0x%x\n",
  3454. *(DWORD *) pResult->acol[ICOLRI_CRLNAMEID].pbValue));
  3455. DBGPRINTTIME(
  3456. NULL,
  3457. "Query:ThisUpdate",
  3458. DPT_DATE,
  3459. *(FILETIME *) pResult->acol[ICOLRI_CRLTHISUPDATE].pbValue);
  3460. if (NULL != pResult->acol[ICOLRI_CRLNEXTUPDATE].pbValue)
  3461. {
  3462. DBGPRINTTIME(
  3463. NULL,
  3464. "Query:NextUpdate",
  3465. DPT_DATE,
  3466. *(FILETIME *) pResult->acol[ICOLRI_CRLNEXTUPDATE].pbValue);
  3467. }
  3468. if (NULL != ppbCRL)
  3469. {
  3470. DBGPRINT((
  3471. DBG_SS_CERTSRVI,
  3472. "Query:RawCRL: cb=%x\n",
  3473. pResult->acol[ICOLRI_CRLRAWCRL].cbValue));
  3474. }
  3475. if (NULL != pResult->acol[ICOLRI_CRLPUBLISHFLAGS].pbValue)
  3476. {
  3477. DBGPRINT((
  3478. DBG_SS_CERTSRVI,
  3479. "Query:PublishFlags: f=%x\n",
  3480. *(DWORD *) pResult->acol[ICOLRI_CRLPUBLISHFLAGS].pbValue));
  3481. }
  3482. if (0 < CompareFileTime(
  3483. (FILETIME *) pResult->acol[ICOLRI_CRLTHISUPDATE].pbValue,
  3484. &ftCurrent))
  3485. {
  3486. _PrintError(E_INVALIDARG, "ThisUpdate in future");
  3487. }
  3488. if (NULL != pResult->acol[ICOLRI_CRLNEXTUPDATE].pbValue &&
  3489. 0 > CompareFileTime(
  3490. (FILETIME *) pResult->acol[ICOLRI_CRLNEXTUPDATE].pbValue,
  3491. &ftCurrent))
  3492. {
  3493. hr = E_INVALIDARG;
  3494. _JumpError(hr, error, "NextUpdate in past");
  3495. }
  3496. CSASSERT(0 != pResult->rowid);
  3497. CSASSERT(NULL == pbCRL);
  3498. RowId = pResult->rowid;
  3499. if (NULL != ppbCRL)
  3500. {
  3501. cbCRL = pResult->acol[ICOLRI_CRLRAWCRL].cbValue;
  3502. pbCRL = (BYTE *) LocalAlloc(LMEM_FIXED, cbCRL);
  3503. if (NULL == pbCRL)
  3504. {
  3505. hr = E_OUTOFMEMORY;
  3506. _JumpError(hr, error, "LocalAlloc");
  3507. }
  3508. CopyMemory(
  3509. pbCRL,
  3510. pResult->acol[ICOLRI_CRLRAWCRL].pbValue,
  3511. cbCRL);
  3512. }
  3513. if (NULL != pdwCRLPublishFlags &&
  3514. NULL != pResult->acol[ICOLRI_CRLPUBLISHFLAGS].pbValue)
  3515. {
  3516. *pdwCRLPublishFlags =
  3517. *(DWORD *) pResult->acol[ICOLRI_CRLPUBLISHFLAGS].pbValue;
  3518. }
  3519. DBGPRINT((DBG_SS_CERTSRVI, "Query:RowId: SAVED %u\n", pResult->rowid));
  3520. pView->ReleaseResultRow(celtFetched, aResult);
  3521. fResultActive = FALSE;
  3522. }
  3523. *pdwRowId = RowId;
  3524. if (NULL != ppbCRL)
  3525. {
  3526. *pcbCRL = cbCRL;
  3527. *ppbCRL = pbCRL;
  3528. pbCRL = NULL;
  3529. }
  3530. hr = S_OK;
  3531. error:
  3532. if (NULL != pbCRL)
  3533. {
  3534. LocalFree(pbCRL);
  3535. }
  3536. if (NULL != pView)
  3537. {
  3538. if (fResultActive)
  3539. {
  3540. pView->ReleaseResultRow(celtFetched, aResult);
  3541. }
  3542. pView->Release();
  3543. }
  3544. DBGPRINT((
  3545. DBG_SS_CERTSRVI,
  3546. "crlGetRowIdAndCRL(%ws) -> RowId=%u, cbCRL=%x, hr=%x\n",
  3547. fDelta? L"Delta" : L"Base",
  3548. *pdwRowId,
  3549. *pcbCRL,
  3550. hr));
  3551. return(hr);
  3552. }
  3553. #undef ICOLRI_CRLNUMBER
  3554. #undef ICOLRI_CRLNAMEID
  3555. #undef ICOLRI_CRLRAWCRL
  3556. #undef ICOLRI_CRLPUBLISHFLAGS
  3557. #undef ICOLRI_CRLTHISUPDATEDATE
  3558. #undef ICOLRI_CRLNEXTUPDATEDATE
  3559. HRESULT
  3560. crlRepublishCRLFromCAContext(
  3561. IN FILETIME const *pftCurrent,
  3562. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  3563. IN BOOL fDelta,
  3564. IN CACTX *pCAContext,
  3565. OUT BOOL *pfRetryNeeded,
  3566. OUT HRESULT *phrPublish)
  3567. {
  3568. HRESULT hr;
  3569. DWORD cbCRL;
  3570. BYTE *pbCRL = NULL;
  3571. DWORD RowId;
  3572. *pfRetryNeeded = FALSE;
  3573. *phrPublish = S_OK;
  3574. hr = crlGetRowIdAndCRL(fDelta, pCAContext, &RowId, &cbCRL, &pbCRL, NULL);
  3575. _JumpIfError(hr, error, "crlGetRowIdAndCRL");
  3576. hr = crlPublishGeneratedCRL(
  3577. RowId,
  3578. pftCurrent,
  3579. pwszUserName,
  3580. fDelta,
  3581. pCAContext->iKey,
  3582. pbCRL,
  3583. cbCRL,
  3584. pCAContext,
  3585. pfRetryNeeded,
  3586. phrPublish);
  3587. _JumpIfError(hr, error, "crlPublishGeneratedCRL");
  3588. error:
  3589. if (NULL != pbCRL)
  3590. {
  3591. LocalFree(pbCRL);
  3592. }
  3593. return(hr);
  3594. }
  3595. HRESULT
  3596. crlRepublishExistingCRLs(
  3597. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  3598. IN BOOL fDeltaOnly,
  3599. IN BOOL fShadowDelta,
  3600. IN FILETIME const *pftCurrent,
  3601. OUT BOOL *pfRetryNeeded,
  3602. OUT HRESULT *phrPublish)
  3603. {
  3604. HRESULT hr;
  3605. HRESULT hrPublish;
  3606. BOOL fRetryNeeded;
  3607. DWORD i;
  3608. *pfRetryNeeded = FALSE;
  3609. *phrPublish = S_OK;
  3610. // Walk global CA Context array from the back, and republish CRLs for
  3611. // each unique CA key. This causes the most current CRL to be published
  3612. // first, and the most current CA Cert context to be used to publish a CRL
  3613. // that covers multiple CA Certs due to key reuse.
  3614. for (i = g_cCACerts; i > 0; i--)
  3615. {
  3616. CACTX *pCAContext = &g_aCAContext[i - 1];
  3617. hr = PKCSVerifyCAState(pCAContext);
  3618. _PrintIfError(hr, "PKCSVerifyCAState");
  3619. if (CTXF_SKIPCRL & pCAContext->Flags)
  3620. {
  3621. continue;
  3622. }
  3623. if (!fDeltaOnly)
  3624. {
  3625. // Publish the most recent existing Base CRL
  3626. hr = CertSrvTestServerState();
  3627. _JumpIfError(hr, error, "CertSrvTestServerState");
  3628. hr = crlRepublishCRLFromCAContext(
  3629. pftCurrent,
  3630. pwszUserName,
  3631. FALSE, // fDelta
  3632. pCAContext,
  3633. &fRetryNeeded,
  3634. &hrPublish);
  3635. _JumpIfError(hr, error, "crlRepublishCRLFromCAContext");
  3636. if (fRetryNeeded)
  3637. {
  3638. *pfRetryNeeded = TRUE;
  3639. }
  3640. if (S_OK == *phrPublish)
  3641. {
  3642. *phrPublish = hrPublish;
  3643. }
  3644. }
  3645. if (!g_fDeltaCRLPublishDisabled || fShadowDelta)
  3646. {
  3647. // Publish the most recent existing Delta CRL
  3648. hr = CertSrvTestServerState();
  3649. _JumpIfError(hr, error, "CertSrvTestServerState");
  3650. hr = crlRepublishCRLFromCAContext(
  3651. pftCurrent,
  3652. pwszUserName,
  3653. TRUE, // fDelta
  3654. pCAContext,
  3655. &fRetryNeeded,
  3656. &hrPublish);
  3657. _JumpIfError(hr, error, "crlRepublishCRLFromCAContext");
  3658. if (fRetryNeeded)
  3659. {
  3660. *pfRetryNeeded = TRUE;
  3661. }
  3662. if (S_OK == *phrPublish)
  3663. {
  3664. *phrPublish = hrPublish;
  3665. }
  3666. }
  3667. }
  3668. hr = S_OK;
  3669. error:
  3670. return(hr);
  3671. }
  3672. HRESULT
  3673. crlComputeCRLTimes(
  3674. IN BOOL DBGPARMREFERENCED(fDelta),
  3675. IN CSCRLPERIOD const *pccp,
  3676. IN FILETIME const *pftCurrent,
  3677. OUT FILETIME *pftThisUpdate, // ftCurrent - clock skew
  3678. IN OUT FILETIME *pftNextUpdate, // ftCurrent + period + overlap + skew
  3679. OUT FILETIME *pftNextPublish, // ftCurrent + CRL period
  3680. OUT FILETIME *pftPropagationComplete) // ftCurrent + overlap
  3681. {
  3682. HRESULT hr;
  3683. LONGLONG lldelta;
  3684. if (0 == pftNextUpdate->dwHighDateTime &&
  3685. 0 == pftNextUpdate->dwLowDateTime)
  3686. {
  3687. // Calculate expiration date for this CRL:
  3688. // ftCurrent + CRL period
  3689. DBGPRINTTIME(&fDelta, "*pftCurrent", DPT_DATE, *pftCurrent);
  3690. *pftNextUpdate = *pftCurrent;
  3691. DBGPRINT((
  3692. DBG_SS_CERTSRVI,
  3693. "+ count=%d, enum=%d\n",
  3694. pccp->lCRLPeriodCount,
  3695. pccp->enumCRLPeriod));
  3696. myMakeExprDateTime(
  3697. pftNextUpdate,
  3698. pccp->lCRLPeriodCount,
  3699. pccp->enumCRLPeriod);
  3700. DBGPRINTTIME(&fDelta, "*pftNextUpdate", DPT_DATE, *pftNextUpdate);
  3701. }
  3702. if (0 > CompareFileTime(pftNextUpdate, pftCurrent))
  3703. {
  3704. hr = E_INVALIDARG;
  3705. _JumpError(hr, error, "*pftNextUpdate in past");
  3706. }
  3707. *pftThisUpdate = *pftCurrent;
  3708. *pftNextPublish = *pftNextUpdate; // unmodified expiration time
  3709. // Subtract clock skew from the current time for ftThisUpdate time.
  3710. lldelta = g_dwClockSkewMinutes * CVT_MINUTES;
  3711. myAddToFileTime(pftThisUpdate, -lldelta * CVT_BASE);
  3712. // Add clock skew to ftNextUpdate,
  3713. // Add propogation overlap to ftNextUpdate.
  3714. lldelta += pccp->dwCRLOverlapMinutes * CVT_MINUTES;
  3715. myAddToFileTime(pftNextUpdate, lldelta * CVT_BASE);
  3716. *pftPropagationComplete = *pftCurrent;
  3717. lldelta = pccp->dwCRLOverlapMinutes * CVT_MINUTES;
  3718. myAddToFileTime(pftPropagationComplete, lldelta * CVT_BASE);
  3719. DBGPRINTTIME(&fDelta, "*pftCurrent", DPT_DATE, *pftCurrent);
  3720. DBGPRINTTIME(&fDelta, "*pftThisUpdate", DPT_DATE, *pftThisUpdate);
  3721. DBGPRINTTIME(&fDelta, "*pftNextUpdate", DPT_DATE, *pftNextUpdate);
  3722. DBGPRINTTIME(&fDelta, "*pftNextPublish", DPT_DATE, *pftNextPublish);
  3723. DBGPRINTTIME(&fDelta, "*pftPropagationComplete", DPT_DATE, *pftPropagationComplete);
  3724. hr = S_OK;
  3725. error:
  3726. return(hr);
  3727. }
  3728. // crlGenerateAndPublishCRLs
  3729. //
  3730. // The algorithm for computing base and delta CRL overlap periods is:
  3731. // Base:
  3732. // If Base registry overlap period specified:
  3733. // {
  3734. // Start with Base registry setting rounded down to nearest minute
  3735. // multiple
  3736. // }
  3737. // else
  3738. // {
  3739. // Start with 10% of Base CRL period (1/10 period) rounded down to
  3740. // nearest minute multiple
  3741. // Maximum 12 hours
  3742. // }
  3743. // Minimum 1.5 times clock skew (usually 1.5 * 10 minutes)
  3744. // Maximum 100% of Base CRL period
  3745. //
  3746. // Delta:
  3747. // If Delta registry overlap period specified:
  3748. // {
  3749. // Start with Delta registry setting rounded down to nearest minute
  3750. // multiple
  3751. // }
  3752. // else
  3753. // {
  3754. // Start with 100% of Delta CRL period (full period) rounded down to
  3755. // nearest minute multiple
  3756. // Maximum 12 hours
  3757. // }
  3758. // Minimum 1.5 times clock skew (usually 1.5 * 10 minutes)
  3759. // Maximum 100% of Delta CRL period
  3760. HRESULT
  3761. crlGenerateAndPublishCRLs(
  3762. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  3763. IN BOOL fDeltaOnly, // else base (and delta, if enabled)
  3764. IN BOOL fShadowDelta, // empty delta CRL with new MinBaseCRL
  3765. IN FILETIME const *pftCurrent,
  3766. IN FILETIME ftNextUpdateBase,
  3767. OUT DWORD *pdwRowIdBase,
  3768. OUT FILETIME *pftQueryDeltaDelete,
  3769. OUT BOOL *pfRetryNeeded,
  3770. OUT HRESULT *phrPublish)
  3771. {
  3772. HRESULT hr;
  3773. HRESULT hrPublish;
  3774. HKEY hkeyBase = NULL;
  3775. HKEY hkeyCA = NULL;
  3776. BOOL fClamped = FALSE;
  3777. DWORD CRLNumber;
  3778. DWORD CRLNumberDelta;
  3779. DWORD CRLNumberBaseMin = 0;
  3780. DWORD i;
  3781. BOOL fRetryNeeded;
  3782. FILETIME ftNextUpdateDelta;
  3783. FILETIME ftThisUpdate;
  3784. FILETIME ftQueryDelta;
  3785. FILETIME *pftQueryDelta = &ftQueryDelta;
  3786. FILETIME ftLastPublishBase;
  3787. FILETIME ftNextPublishBase;
  3788. FILETIME ftNextUpdateBaseClamped = ftNextUpdateBase; // if clamped
  3789. FILETIME ftNextPublishDelta;
  3790. FILETIME ftPropagationCompleteBase;
  3791. FILETIME ftPropagationCompleteDelta;
  3792. CSCRLPERIOD ccpBase;
  3793. CSCRLPERIOD ccpDelta;
  3794. *pfRetryNeeded = FALSE;
  3795. pftQueryDeltaDelete->dwHighDateTime = 0;
  3796. pftQueryDeltaDelete->dwLowDateTime = 0;
  3797. *phrPublish = S_OK;
  3798. hr = crlGetNextCRLNumber(&CRLNumber);
  3799. _JumpIfError(hr, error, "crlGetNextCRLNumber");
  3800. hr = crlGetRegCRLPublishParams(
  3801. g_wszSanitizedName,
  3802. &ccpBase,
  3803. &ccpDelta);
  3804. _JumpIfError(hr, error, "crlGetRegCRLPublishParams");
  3805. // in manual publish case, 0 implies use default publish period
  3806. CRLNumberDelta = CRLNumber;
  3807. if (fDeltaOnly)
  3808. {
  3809. ftNextUpdateDelta = ftNextUpdateBase;
  3810. ZeroMemory(&ftNextUpdateBase, sizeof(ftNextUpdateBase));
  3811. }
  3812. else
  3813. {
  3814. // son of RFC 2459: Trevor says don't do this (yet):
  3815. // CRLNumberDelta++;
  3816. ZeroMemory(&ftNextUpdateDelta, sizeof(ftNextUpdateDelta));
  3817. }
  3818. hr = crlComputeCRLTimes(
  3819. FALSE, // fDelta
  3820. &ccpBase, // IN
  3821. pftCurrent, // IN
  3822. &ftThisUpdate, // OUT includes skew
  3823. &ftNextUpdateBase, // INOUT includes overlap, skew
  3824. &ftNextPublishBase, // OUT unmodified expire time
  3825. &ftPropagationCompleteBase); // OUT includes overlap
  3826. _JumpIfError(hr, error, "crlComputeCRLTimes");
  3827. hr = crlComputeCRLTimes(
  3828. TRUE, // fDelta
  3829. fShadowDelta? &ccpBase : &ccpDelta, // IN
  3830. pftCurrent, // IN
  3831. &ftThisUpdate, // OUT includes skew
  3832. &ftNextUpdateDelta, // INOUT includes overlap, skew
  3833. &ftNextPublishDelta, // OUT unmodified expire time
  3834. &ftPropagationCompleteDelta); // OUT includes overlap
  3835. _JumpIfError(hr, error, "crlComputeCRLTimes");
  3836. // Set ftLastPublishBase to *pftCurrent minus lifetime of this base CRL,
  3837. // which is an educated guess for the ftThisPublish value for the last
  3838. // CRL issued.
  3839. ftLastPublishBase = *pftCurrent;
  3840. myAddToFileTime(
  3841. &ftLastPublishBase,
  3842. -mySubtractFileTimes(&ftNextPublishBase, pftCurrent));
  3843. // Clamp delta CRL to not end after base CRL.
  3844. if (0 < CompareFileTime(&ftNextPublishDelta, &ftNextPublishBase))
  3845. {
  3846. ftNextPublishDelta = ftNextPublishBase;
  3847. DBGPRINTTIME(NULL, "ftNextPublishDelta", DPT_DATE, ftNextPublishDelta);
  3848. }
  3849. if (0 < CompareFileTime(&ftNextUpdateDelta, &ftNextUpdateBase))
  3850. {
  3851. ftNextUpdateDelta = ftNextUpdateBase;
  3852. DBGPRINTTIME(NULL, "ftNextUpdateDelta", DPT_DATE, ftNextUpdateDelta);
  3853. }
  3854. if (0 < CompareFileTime(&ftPropagationCompleteDelta, &ftPropagationCompleteBase))
  3855. {
  3856. ftPropagationCompleteDelta = ftPropagationCompleteBase;
  3857. DBGPRINTTIME(NULL, "ftPropagationCompleteDelta", DPT_DATE, ftPropagationCompleteDelta);
  3858. }
  3859. if (!g_fDeltaCRLPublishDisabled || fShadowDelta)
  3860. {
  3861. hr = crlGetBaseCRLInfo(
  3862. pftCurrent,
  3863. FALSE, // try newest propagated CRL
  3864. pdwRowIdBase,
  3865. &CRLNumberBaseMin,
  3866. &ftQueryDelta);
  3867. _PrintIfError(hr, "crlGetBaseCRLInfo");
  3868. if (S_OK != hr)
  3869. {
  3870. hr = crlGetBaseCRLInfo(
  3871. pftCurrent,
  3872. TRUE, // try oldest unexpired CRL
  3873. pdwRowIdBase,
  3874. &CRLNumberBaseMin,
  3875. &ftQueryDelta);
  3876. _PrintIfError(hr, "crlGetBaseCRLInfo");
  3877. if (S_OK != hr)
  3878. {
  3879. CRLNumberBaseMin = 1;
  3880. if (!fDeltaOnly && 1 == CRLNumber)
  3881. {
  3882. ftQueryDelta = *pftCurrent; // empty CRL
  3883. }
  3884. else
  3885. {
  3886. pftQueryDelta = NULL; // full CRL
  3887. }
  3888. }
  3889. }
  3890. if (S_OK == hr)
  3891. {
  3892. // Delete old CRLs that expired at least one base CRL period prior
  3893. // to the "minimum" base crl ThisUpdate date found in the database.
  3894. *pftQueryDeltaDelete = ftQueryDelta;
  3895. myAddToFileTime(
  3896. pftQueryDeltaDelete,
  3897. -mySubtractFileTimes(&ftNextUpdateBase, &ftThisUpdate));
  3898. }
  3899. if (fShadowDelta)
  3900. {
  3901. CRLNumberBaseMin = CRLNumber;
  3902. }
  3903. CSASSERT(0 != CRLNumberBaseMin);
  3904. }
  3905. // Walk global CA Context array from the back, and generate a CRL for
  3906. // each unique CA key. This causes the most current CRL to be built
  3907. // first, and the most current CA Cert to be used to build a CRL that
  3908. // covers multiple CA Certs due to key reuse.
  3909. for (i = g_cCACerts; i > 0; i--)
  3910. {
  3911. CACTX *pCAContext = &g_aCAContext[i - 1];
  3912. hr = PKCSVerifyCAState(pCAContext);
  3913. _PrintIfError(hr, "PKCSVerifyCAState");
  3914. if (CTXF_SKIPCRL & pCAContext->Flags)
  3915. {
  3916. continue;
  3917. }
  3918. if (!fDeltaOnly)
  3919. {
  3920. // Publish a new Base CRL
  3921. // make a local copy in case clamped
  3922. FILETIME ftNextUpdateBaseTemp = ftNextUpdateBase;
  3923. fClamped = FALSE;
  3924. hr = CertSrvTestServerState();
  3925. _JumpIfError(hr, error, "CertSrvTestServerState");
  3926. hr = crlPublishCRLFromCAContext(
  3927. CRLNumber,
  3928. 0, // CRLNumberBaseMin
  3929. pwszUserName,
  3930. FALSE, // fShadowDelta
  3931. pCAContext,
  3932. pftCurrent,
  3933. ftThisUpdate,
  3934. &ftNextUpdateBaseTemp,
  3935. &fClamped,
  3936. NULL,
  3937. pftCurrent,
  3938. &ftNextPublishBase,
  3939. &ftLastPublishBase,
  3940. &ftPropagationCompleteBase,
  3941. &fRetryNeeded,
  3942. &hrPublish);
  3943. _JumpIfError(hr, error, "crlPublishCRLFromCAContext");
  3944. if (fRetryNeeded)
  3945. {
  3946. *pfRetryNeeded = TRUE;
  3947. }
  3948. if (S_OK == *phrPublish)
  3949. {
  3950. *phrPublish = hrPublish;
  3951. }
  3952. {
  3953. CertSrv::CAuditEvent event(SE_AUDITID_CERTSRV_AUTOPUBLISHCRL, g_dwAuditFilter);
  3954. hr = event.AddData(true); // %1 base crl?
  3955. _JumpIfError(hr, error, "CAuditEvent::AddData");
  3956. hr = event.AddData(CRLNumber); // %2 CRL#
  3957. _JumpIfError(hr, error, "CAuditEvent::AddData");
  3958. hr = event.AddData(pCAContext->pwszKeyContainerName); // %3 key container
  3959. _JumpIfError(hr, error, "CAuditEvent::AddData");
  3960. hr = event.AddData(ftNextPublishBase); // %4 next publish
  3961. _JumpIfError(hr, error, "CAuditEvent::AddData");
  3962. hr = event.AddData((LPCWSTR*)pCAContext->papwszCRLFiles); //%5 URLs
  3963. _JumpIfError(hr, error, "CAuditEvent::AddData");
  3964. hr = event.Report();
  3965. _JumpIfError(hr, error, "CAuditEvent::Report");
  3966. }
  3967. if (i == g_cCACerts && fClamped)
  3968. {
  3969. // new next publish clamps with CA expiration, only update
  3970. // the current crl with new one for later reg save
  3971. ftNextUpdateBaseClamped = ftNextUpdateBaseTemp;
  3972. }
  3973. }
  3974. if (!g_fDeltaCRLPublishDisabled || fShadowDelta)
  3975. {
  3976. // Publish a new Delta CRL
  3977. FILETIME ftNextUpdateDeltaTemp = ftNextUpdateDelta;
  3978. hr = CertSrvTestServerState();
  3979. _JumpIfError(hr, error, "CertSrvTestServerState");
  3980. hr = crlPublishCRLFromCAContext(
  3981. CRLNumberDelta,
  3982. CRLNumberBaseMin,
  3983. pwszUserName,
  3984. fShadowDelta,
  3985. pCAContext,
  3986. pftCurrent,
  3987. ftThisUpdate,
  3988. &ftNextUpdateDeltaTemp,
  3989. NULL,
  3990. pftQueryDelta,
  3991. pftCurrent,
  3992. &ftNextPublishDelta,
  3993. &ftLastPublishBase, // Base!
  3994. &ftPropagationCompleteDelta,
  3995. &fRetryNeeded,
  3996. &hrPublish);
  3997. _JumpIfError(hr, error, "crlPublishCRLFromCAContext");
  3998. if (fRetryNeeded)
  3999. {
  4000. *pfRetryNeeded = TRUE;
  4001. }
  4002. if (S_OK == *phrPublish)
  4003. {
  4004. *phrPublish = hrPublish;
  4005. }
  4006. {
  4007. CertSrv::CAuditEvent event(SE_AUDITID_CERTSRV_AUTOPUBLISHCRL, g_dwAuditFilter);
  4008. hr = event.AddData(false); // %1 base crl?
  4009. _JumpIfError(hr, error, "CAuditEvent::AddData");
  4010. hr = event.AddData(CRLNumberDelta); // %2 CRL#
  4011. _JumpIfError(hr, error, "CAuditEvent::AddData");
  4012. hr = event.AddData(pCAContext->pwszKeyContainerName); // %3 key container
  4013. _JumpIfError(hr, error, "CAuditEvent::AddData");
  4014. hr = event.AddData(ftNextPublishDelta); // %4 next publish
  4015. _JumpIfError(hr, error, "CAuditEvent::AddData");
  4016. hr = event.AddData((LPCWSTR*)pCAContext->papwszDeltaCRLFiles); // %5 URLs
  4017. _JumpIfError(hr, error, "CAuditEvent::AddData");
  4018. hr = event.Report();
  4019. _JumpIfError(hr, error, "CAuditEvent::Report");
  4020. }
  4021. }
  4022. }
  4023. // update the registry and global variables
  4024. if (!fDeltaOnly)
  4025. {
  4026. if (!fClamped)
  4027. {
  4028. g_ftCRLNextPublish = ftNextPublishBase;
  4029. }
  4030. else
  4031. {
  4032. g_ftCRLNextPublish = ftNextUpdateBaseClamped;
  4033. }
  4034. hr = crlSetRegCRLNextPublish(
  4035. FALSE,
  4036. g_wszSanitizedName,
  4037. wszREGCRLNEXTPUBLISH,
  4038. &g_ftCRLNextPublish);
  4039. _JumpIfError(hr, error, "crlSetRegCRLNextPublish");
  4040. }
  4041. g_ftDeltaCRLNextPublish = ftNextPublishDelta;
  4042. if (!g_fDeltaCRLPublishDisabled)
  4043. {
  4044. hr = crlSetRegCRLNextPublish(
  4045. TRUE,
  4046. g_wszSanitizedName,
  4047. wszREGCRLDELTANEXTPUBLISH,
  4048. &g_ftDeltaCRLNextPublish);
  4049. _JumpIfError(hr, error, "crlSetRegCRLNextPublish");
  4050. }
  4051. hr = S_OK;
  4052. error:
  4053. if (NULL != hkeyCA)
  4054. {
  4055. RegCloseKey(hkeyCA);
  4056. }
  4057. if (NULL != hkeyBase)
  4058. {
  4059. RegCloseKey(hkeyBase);
  4060. }
  4061. return(hr);
  4062. }
  4063. ///////////////////////////////////////////////////
  4064. // CRLPublishCRLs is called to publish a set of CRLs.
  4065. //
  4066. // if fRebuildCRL is TRUE, the CRLs are rebuilt from the database.
  4067. // otherwise, the exit module is re-notified of the CRLs.
  4068. // For consistency, if the exit module returns ERROR_RETRY, this
  4069. // function will write the retry bit into the registry which will
  4070. // trigger the Wakeup function, which then recalculates when the
  4071. // next publish should happen.
  4072. //
  4073. // pfRetryNeeded is an OUT param that notifies the autopublish routine if
  4074. // a retry is immediately necessary following a rebuilt CRL. In this
  4075. // case the registry would not be changed and the registry trigger
  4076. // would not fire.
  4077. //
  4078. // (Current_time - skew) is used as ThisUpdate
  4079. // (ftNextUpdate+skew+Overlap) is used as NextUpdate
  4080. // (ftNextUpdate) is next wakeup/publish time
  4081. //
  4082. // There are registry values to specify the overlap.
  4083. // HLKLM\SYSTEM\CurrentControlSet\Services\CertSvc\Configuration\<CA Name>:
  4084. // CRLOverlapPeriod REG_SZ = Hours (or Minutes)
  4085. // CRLOverlapUnits REG_DWORD = 0 (0) -- DISABLED
  4086. //
  4087. // If the above registry values are set and valid, the registry overlap period
  4088. // is calculated as:
  4089. // max(Registry CRL Overlap Period, 1.5 * Registry clock skew minutes)
  4090. //
  4091. // If they are not present or invalid, the overlap period is calculated as:
  4092. // max(
  4093. // min(Registry CRL Period / 10, 12 hours),
  4094. // 1.5 * Registry clock skew minutes) +
  4095. // Registry clock skew minutes
  4096. //
  4097. // ThisUpdate is calculated as:
  4098. // max(Current Time - Registry clock skew minutes, CA cert NotBefore date)
  4099. //
  4100. // NextUpdate is calculated as:
  4101. // min(
  4102. // Current Time +
  4103. // Registry CRL period +
  4104. // calculated overlap period +
  4105. // Registry clock skew minutes,
  4106. // CA cert NotAfter date)
  4107. //
  4108. // The Next CRL publication time is calculated as:
  4109. // Current Time + Registry CRL period
  4110. //
  4111. // This function sets g_hCRLManualPublishEvent. Automatic publishing
  4112. // is personally responsible for clearing this event if it calls us.
  4113. HRESULT
  4114. CRLPublishCRLs(
  4115. IN BOOL fRebuildCRL, // else republish only
  4116. IN BOOL fForceRepublish, // else check registry retry count
  4117. OPTIONAL IN WCHAR const *pwszUserName, // else timer thread
  4118. IN BOOL fDeltaOnly, // else base (and delta, if enabled)
  4119. IN BOOL fShadowDelta, // empty delta CRL with new MinBaseCRL
  4120. IN FILETIME ftNextUpdateBase,
  4121. OUT BOOL *pfRetryNeeded,
  4122. OUT HRESULT *phrPublish)
  4123. {
  4124. HRESULT hr;
  4125. BOOL fRetryNeeded = FALSE;
  4126. BOOL fExitNotify = FALSE;
  4127. BOOL fCoInitialized = FALSE;
  4128. DWORD RowIdBase = 0;
  4129. FILETIME ftQueryDeltaDelete = { 0, 0 };
  4130. DWORD dwPreviousAttempts;
  4131. DWORD dwCurrentAttempts;
  4132. static BOOL s_fSkipRetry = FALSE;
  4133. *pfRetryNeeded = FALSE;
  4134. *phrPublish = S_OK;
  4135. if (fDeltaOnly && g_fDeltaCRLPublishDisabled && !fShadowDelta)
  4136. {
  4137. hr = HRESULT_FROM_WIN32(ERROR_RESOURCE_DISABLED);
  4138. _JumpError(hr, error, "g_fDeltaCRLPublishDisabled");
  4139. }
  4140. // retrieve initial retry value (optional registry value)
  4141. hr = myGetCertRegDWValue(
  4142. g_wszSanitizedName,
  4143. NULL,
  4144. NULL,
  4145. wszREGCRLATTEMPTREPUBLISH,
  4146. &dwPreviousAttempts);
  4147. if (HRESULT_FROM_WIN32(ERROR_FILE_NOT_FOUND) == hr)
  4148. {
  4149. dwPreviousAttempts = 0; // assume no previous failed publish attempts
  4150. hr = S_OK;
  4151. }
  4152. _JumpIfErrorStr(
  4153. hr,
  4154. error,
  4155. "myGetCertRegDWValue",
  4156. wszREGCRLATTEMPTREPUBLISH);
  4157. dwCurrentAttempts = dwPreviousAttempts;
  4158. DBGPRINT((
  4159. DBG_SS_CERTSRV,
  4160. "CRLPublishCRLs(fRebuildCRL=%u, fForceRepublish=%u, User=%ws)\n",
  4161. fRebuildCRL,
  4162. fForceRepublish,
  4163. pwszUserName));
  4164. DBGPRINT((
  4165. DBG_SS_CERTSRV,
  4166. "CRLPublishCRLs(fDeltaOnly=%u, fShadowDelta=%u, dwPreviousAttempts=%u)\n",
  4167. fDeltaOnly,
  4168. fShadowDelta,
  4169. dwPreviousAttempts));
  4170. if (0 != dwPreviousAttempts && NULL == pwszUserName && s_fSkipRetry)
  4171. {
  4172. fRetryNeeded = TRUE;
  4173. }
  4174. else
  4175. {
  4176. FILETIME ftCurrent;
  4177. GetSystemTimeAsFileTime(&ftCurrent);
  4178. // generate CRLs if necessary
  4179. if (fRebuildCRL)
  4180. {
  4181. hr = crlGenerateAndPublishCRLs(
  4182. pwszUserName,
  4183. fDeltaOnly,
  4184. fShadowDelta,
  4185. &ftCurrent,
  4186. ftNextUpdateBase,
  4187. &RowIdBase,
  4188. &ftQueryDeltaDelete,
  4189. &fRetryNeeded,
  4190. phrPublish);
  4191. _JumpIfError(hr, error, "crlGenerateAndPublishCRLs");
  4192. fExitNotify = TRUE;
  4193. dwCurrentAttempts = 1;
  4194. }
  4195. else
  4196. if (fForceRepublish ||
  4197. (0 < dwPreviousAttempts &&
  4198. CERTSRV_CRLPUB_RETRY_COUNT_DEFAULT > dwPreviousAttempts))
  4199. {
  4200. // If the timer thread is auto-republishing due to previously
  4201. // failed publish attempts, retry base CRLs, too, because we
  4202. // can't tell if the retry is due to a base or delta CRL error.
  4203. if (NULL == pwszUserName)
  4204. {
  4205. fDeltaOnly = FALSE;
  4206. }
  4207. hr = crlRepublishExistingCRLs(
  4208. pwszUserName,
  4209. fDeltaOnly,
  4210. fShadowDelta,
  4211. &ftCurrent,
  4212. &fRetryNeeded,
  4213. phrPublish);
  4214. _JumpIfError(hr, error, "crlRepublishCRLs");
  4215. fExitNotify = TRUE;
  4216. dwCurrentAttempts++;
  4217. }
  4218. if (fExitNotify && g_fEnableExit)
  4219. {
  4220. hr = CoInitializeEx(NULL, GetCertsrvComThreadingModel());
  4221. if (S_OK != hr && S_FALSE != hr)
  4222. {
  4223. _JumpError(hr, error, "CoInitializeEx");
  4224. }
  4225. fCoInitialized = TRUE;
  4226. // make sure exit module(s) get notified for publish and republish
  4227. // in case of earlier exit module publish failure.
  4228. hr = ExitNotify(EXITEVENT_CRLISSUED, 0, NULL, MAXDWORD);
  4229. _PrintIfError(hr, "ExitNotify");
  4230. if ((HRESULT) ERROR_RETRY == hr ||
  4231. HRESULT_FROM_WIN32(ERROR_RETRY) == hr)
  4232. {
  4233. fRetryNeeded = TRUE;
  4234. if (S_OK == *phrPublish)
  4235. {
  4236. *phrPublish = HRESULT_FROM_WIN32(ERROR_RETRY);
  4237. }
  4238. }
  4239. CONSOLEPRINT0((DBG_SS_CERTSRV, "Issued CRL Exit Event\n"));
  4240. }
  4241. // If new or existing CRLs successfully published, reset count to 0
  4242. if (fExitNotify && !fRetryNeeded)
  4243. {
  4244. dwCurrentAttempts = 0;
  4245. if (CERTLOG_VERBOSE <= g_dwLogLevel)
  4246. {
  4247. WCHAR *pwszHostName = NULL;
  4248. DWORD LogMsg;
  4249. if (NULL != g_pld)
  4250. {
  4251. myLdapGetDSHostName(g_pld, &pwszHostName);
  4252. }
  4253. LogMsg = fDeltaOnly?
  4254. MSG_DELTA_CRLS_PUBLISHED :
  4255. (g_fDeltaCRLPublishDisabled?
  4256. MSG_BASE_CRLS_PUBLISHED :
  4257. MSG_BASE_AND_DELTA_CRLS_PUBLISHED);
  4258. if (NULL != pwszHostName)
  4259. {
  4260. LogMsg = fDeltaOnly?
  4261. MSG_DELTA_CRLS_PUBLISHED_HOST_NAME :
  4262. (g_fDeltaCRLPublishDisabled?
  4263. MSG_BASE_CRLS_PUBLISHED_HOST_NAME :
  4264. MSG_BASE_AND_DELTA_CRLS_PUBLISHED_HOST_NAME);
  4265. }
  4266. hr = LogEvent(
  4267. EVENTLOG_INFORMATION_TYPE,
  4268. LogMsg,
  4269. (WORD) (NULL == pwszHostName? 0 : 1), // cStrings
  4270. (WCHAR const **) &pwszHostName); // apwszStrings
  4271. _PrintIfError(hr, "LogEvent");
  4272. }
  4273. }
  4274. // If the retry count has changed, update the registry.
  4275. if (dwCurrentAttempts != dwPreviousAttempts)
  4276. {
  4277. DBGPRINT((
  4278. DBG_SS_CERTSRV,
  4279. "CRLPublishCRLs(Attempts: %u --> %u)\n",
  4280. dwPreviousAttempts,
  4281. dwCurrentAttempts));
  4282. hr = mySetCertRegDWValue(
  4283. g_wszSanitizedName,
  4284. NULL,
  4285. NULL,
  4286. wszREGCRLATTEMPTREPUBLISH,
  4287. dwCurrentAttempts);
  4288. _JumpIfErrorStr(
  4289. hr,
  4290. error,
  4291. "mySetCertRegDWValue",
  4292. wszREGCRLATTEMPTREPUBLISH);
  4293. // If we tried unsuccessfully too many times to publish these CRLs,
  4294. // and we're about to give up until a new set is generated, log an
  4295. // event saying so.
  4296. if (fExitNotify &&
  4297. CERTSRV_CRLPUB_RETRY_COUNT_DEFAULT == dwCurrentAttempts &&
  4298. CERTLOG_ERROR <= g_dwLogLevel)
  4299. {
  4300. WCHAR wszAttempts[cwcDWORDSPRINTF];
  4301. WCHAR const *pwsz = wszAttempts;
  4302. wsprintf(wszAttempts, L"%u", dwCurrentAttempts);
  4303. hr = LogEvent(
  4304. EVENTLOG_ERROR_TYPE,
  4305. MSG_E_CRL_PUBLICATION_TOO_MANY_RETRIES,
  4306. 1, // cStrings
  4307. &pwsz); // apwszStrings
  4308. _PrintIfError(hr, "LogEvent");
  4309. }
  4310. }
  4311. if (fRebuildCRL)
  4312. {
  4313. // Delete old CRLs only if new CRLs built & published successfully.
  4314. if (!fRetryNeeded)
  4315. {
  4316. hr = CertSrvTestServerState();
  4317. _JumpIfError(hr, error, "CertSrvTestServerState");
  4318. hr = crlDeleteExpiredCRLs(
  4319. &ftCurrent,
  4320. &ftQueryDeltaDelete,
  4321. RowIdBase);
  4322. _PrintIfError(hr, "crlDeleteExpiredCRLs");
  4323. }
  4324. // Clear force CRL flag only when we build new CRLs.
  4325. hr = SetSetupStatus(g_wszSanitizedName, SETUP_FORCECRL_FLAG, FALSE);
  4326. _PrintIfError(hr, "SetSetupStatus");
  4327. }
  4328. }
  4329. s_fSkipRetry = NULL != pwszUserName;
  4330. if (fRebuildCRL || fRetryNeeded)
  4331. {
  4332. // If we are doing ANYTHING that will affect automatic wakeup, trigger
  4333. // our publish event.
  4334. // NOTE: do this last or else state might not be updated
  4335. SetEvent(g_hCRLManualPublishEvent);
  4336. }
  4337. hr = S_OK;
  4338. error:
  4339. *pfRetryNeeded = fRetryNeeded;
  4340. if (fCoInitialized)
  4341. {
  4342. CoUninitialize();
  4343. }
  4344. return(hr);
  4345. }
  4346. HRESULT
  4347. CRLGetCRL(
  4348. IN DWORD iCertArg,
  4349. IN BOOL fDelta,
  4350. OPTIONAL OUT CRL_CONTEXT const **ppCRL,
  4351. OPTIONAL OUT DWORD *pdwCRLPublishFlags)
  4352. {
  4353. HRESULT hr;
  4354. DWORD State;
  4355. DWORD iCert;
  4356. DWORD iCRL;
  4357. DWORD dwRowId;
  4358. BYTE *pbCRL = NULL;
  4359. DWORD cbCRL;
  4360. if (NULL != ppCRL)
  4361. {
  4362. *ppCRL = NULL;
  4363. }
  4364. hr = PKCSMapCRLIndex(iCertArg, &iCert, &iCRL, &State);
  4365. _JumpIfError(hr, error, "PKCSMapCRLIndex");
  4366. if (MAXDWORD != iCertArg &&
  4367. CA_DISP_VALID != State &&
  4368. CA_DISP_INVALID != State)
  4369. {
  4370. hr = E_INVALIDARG;
  4371. _JumpError(hr, error, "No CRL for this Cert");
  4372. }
  4373. // Now we know iCert is a valid Cert Index:
  4374. hr = crlGetRowIdAndCRL(
  4375. fDelta,
  4376. &g_aCAContext[iCert],
  4377. &dwRowId,
  4378. &cbCRL,
  4379. &pbCRL,
  4380. pdwCRLPublishFlags);
  4381. if (S_OK != hr)
  4382. {
  4383. _PrintError2(
  4384. hr,
  4385. "crlGetRowIdAndCRL",
  4386. fDelta? HRESULT_FROM_WIN32(ERROR_FILE_NOT_FOUND) : S_OK);
  4387. if (MAXDWORD != iCertArg && CA_DISP_INVALID == State)
  4388. {
  4389. hr = E_INVALIDARG;
  4390. _JumpError(hr, error, "No CRL for this expired Cert");
  4391. }
  4392. _JumpError2(
  4393. hr,
  4394. error,
  4395. "crlGetRowIdAndCRL",
  4396. fDelta? HRESULT_FROM_WIN32(ERROR_FILE_NOT_FOUND) : S_OK);
  4397. }
  4398. if (NULL != ppCRL)
  4399. {
  4400. *ppCRL = CertCreateCRLContext(X509_ASN_ENCODING, pbCRL, cbCRL);
  4401. if (NULL == *ppCRL)
  4402. {
  4403. hr = myHLastError();
  4404. _JumpError(hr, error, "CertCreateCRLContext");
  4405. }
  4406. }
  4407. hr = S_OK;
  4408. error:
  4409. if (NULL != pbCRL)
  4410. {
  4411. LocalFree(pbCRL);
  4412. }
  4413. return(hr);
  4414. }