|
Packit Service |
4684c1 |
/*
|
|
Packit Service |
4684c1 |
* Copyright (C) 2010-2014 Free Software Foundation, Inc.
|
|
Packit Service |
4684c1 |
* Copyright (C) 2013-2014 Nikos Mavrogiannopoulos
|
|
Packit Service |
4684c1 |
*
|
|
Packit Service |
4684c1 |
* Author: Nikos Mavrogiannopoulos
|
|
Packit Service |
4684c1 |
*
|
|
Packit Service |
4684c1 |
* This file is part of GnuTLS.
|
|
Packit Service |
4684c1 |
*
|
|
Packit Service |
4684c1 |
* GnuTLS is free software: you can redistribute it and/or modify it
|
|
Packit Service |
4684c1 |
* under the terms of the GNU General Public License as published by
|
|
Packit Service |
4684c1 |
* the Free Software Foundation, either version 3 of the License, or
|
|
Packit Service |
4684c1 |
* (at your option) any later version.
|
|
Packit Service |
4684c1 |
*
|
|
Packit Service |
4684c1 |
* GnuTLS is distributed in the hope that it will be useful, but
|
|
Packit Service |
4684c1 |
* WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
Packit Service |
4684c1 |
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
|
Packit Service |
4684c1 |
* General Public License for more details.
|
|
Packit Service |
4684c1 |
*
|
|
Packit Service |
4684c1 |
* You should have received a copy of the GNU General Public License
|
|
Packit Service |
4684c1 |
* along with this program. If not, see
|
|
Packit Service |
4684c1 |
* <https://www.gnu.org/licenses/>.
|
|
Packit Service |
4684c1 |
*/
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
#include <config.h>
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
#include <gnutls/gnutls.h>
|
|
Packit Service |
4684c1 |
#include <gnutls/x509.h>
|
|
Packit Service |
4684c1 |
#include <gnutls/openpgp.h>
|
|
Packit Service |
4684c1 |
#include <gnutls/pkcs12.h>
|
|
Packit Service |
4684c1 |
#include <gnutls/pkcs11.h>
|
|
Packit Service |
4684c1 |
#include <gnutls/abstract.h>
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
#include <stdio.h>
|
|
Packit Service |
4684c1 |
#include <stdlib.h>
|
|
Packit Service |
4684c1 |
#include <string.h>
|
|
Packit Service |
4684c1 |
#include <ctype.h>
|
|
Packit Service |
4684c1 |
#include <time.h>
|
|
Packit Service |
4684c1 |
#include <unistd.h>
|
|
Packit Service |
4684c1 |
#include <errno.h>
|
|
Packit Service |
4684c1 |
#include <sys/types.h>
|
|
Packit Service |
4684c1 |
#include <sys/stat.h>
|
|
Packit Service |
4684c1 |
#include <fcntl.h>
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
/* Gnulib portability files. */
|
|
Packit Service |
4684c1 |
#include <read-file.h>
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
#include "p11tool-args.h"
|
|
Packit Service |
4684c1 |
#include "p11tool.h"
|
|
Packit Service |
4684c1 |
#include "certtool-common.h"
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
static void cmd_parser(int argc, char **argv);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
static FILE *outfile;
|
|
Packit Service |
4684c1 |
static const char *outfile_name = NULL;
|
|
Packit Service |
4684c1 |
int batch = 0;
|
|
Packit Service |
4684c1 |
int ask_pass = 0;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
void app_exit(int val)
|
|
Packit Service |
4684c1 |
{
|
|
Packit Service |
4684c1 |
if (val != 0) {
|
|
Packit Service |
4684c1 |
if (outfile_name)
|
|
Packit Service |
4684c1 |
(void)remove(outfile_name);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
exit(val);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
static void tls_log_func(int level, const char *str)
|
|
Packit Service |
4684c1 |
{
|
|
Packit Service |
4684c1 |
fprintf(stderr, "|<%d>| %s", level, str);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
int main(int argc, char **argv)
|
|
Packit Service |
4684c1 |
{
|
|
Packit Service |
4684c1 |
cmd_parser(argc, argv);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
return 0;
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
static
|
|
Packit Service |
4684c1 |
unsigned opt_to_flags(common_info_st *cinfo, unsigned *key_usage)
|
|
Packit Service |
4684c1 |
{
|
|
Packit Service |
4684c1 |
unsigned flags = 0;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
*key_usage = 0;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(MARK_PRIVATE)) {
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(MARK_PRIVATE)) {
|
|
Packit Service |
4684c1 |
flags |= GNUTLS_PKCS11_OBJ_FLAG_MARK_PRIVATE;
|
|
Packit Service |
4684c1 |
} else {
|
|
Packit Service |
4684c1 |
flags |= GNUTLS_PKCS11_OBJ_FLAG_MARK_NOT_PRIVATE;
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
} else { /* if not given mark as private the private objects, and public the public ones */
|
|
Packit Service |
4684c1 |
if (cinfo->privkey)
|
|
Packit Service |
4684c1 |
flags |= GNUTLS_PKCS11_OBJ_FLAG_MARK_PRIVATE;
|
|
Packit Service |
4684c1 |
else if (cinfo->pubkey || cinfo->cert)
|
|
Packit Service |
4684c1 |
flags |= GNUTLS_PKCS11_OBJ_FLAG_MARK_NOT_PRIVATE;
|
|
Packit Service |
4684c1 |
/* else set the defaults of the token */
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(MARK_DISTRUSTED)) {
|
|
Packit Service |
4684c1 |
flags |=
|
|
Packit Service |
4684c1 |
GNUTLS_PKCS11_OBJ_FLAG_MARK_DISTRUSTED;
|
|
Packit Service |
4684c1 |
} else {
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(MARK_TRUSTED))
|
|
Packit Service |
4684c1 |
flags |=
|
|
Packit Service |
4684c1 |
GNUTLS_PKCS11_OBJ_FLAG_MARK_TRUSTED;
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(MARK_SIGN))
|
|
Packit Service |
4684c1 |
*key_usage |= GNUTLS_KEY_DIGITAL_SIGNATURE;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(MARK_DECRYPT))
|
|
Packit Service |
4684c1 |
*key_usage |= GNUTLS_KEY_DECIPHER_ONLY;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(MARK_CA))
|
|
Packit Service |
4684c1 |
flags |=
|
|
Packit Service |
4684c1 |
GNUTLS_PKCS11_OBJ_FLAG_MARK_CA;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(MARK_WRAP))
|
|
Packit Service |
4684c1 |
flags |= GNUTLS_PKCS11_OBJ_FLAG_MARK_KEY_WRAP;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(LOGIN))
|
|
Packit Service |
4684c1 |
flags |= GNUTLS_PKCS11_OBJ_FLAG_LOGIN;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(SO_LOGIN))
|
|
Packit Service |
4684c1 |
flags |= GNUTLS_PKCS11_OBJ_FLAG_LOGIN_SO;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
return flags;
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
static void cmd_parser(int argc, char **argv)
|
|
Packit Service |
4684c1 |
{
|
|
Packit Service |
4684c1 |
int ret, debug = 0;
|
|
Packit Service |
4684c1 |
common_info_st cinfo;
|
|
Packit Service |
4684c1 |
unsigned int pkcs11_type = -1, key_type = GNUTLS_PK_UNKNOWN;
|
|
Packit Service |
4684c1 |
const char *url = NULL;
|
|
Packit Service |
4684c1 |
unsigned int detailed_url = 0, optct;
|
|
Packit Service |
4684c1 |
unsigned int bits = 0;
|
|
Packit Service |
4684c1 |
const char *label = NULL, *sec_param = NULL, *id = NULL;
|
|
Packit Service |
4684c1 |
unsigned flags;
|
|
Packit Service |
4684c1 |
unsigned key_usage;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
optct = optionProcess(&p11toolOptions, argc, argv);
|
|
Packit Service |
4684c1 |
argc += optct;
|
|
Packit Service |
4684c1 |
argv += optct;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (url == NULL && argc > 0)
|
|
Packit Service |
4684c1 |
url = argv[0];
|
|
Packit Service |
4684c1 |
else
|
|
Packit Service |
4684c1 |
url = "pkcs11:";
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(DEBUG))
|
|
Packit Service |
4684c1 |
debug = OPT_VALUE_DEBUG;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
gnutls_global_set_log_function(tls_log_func);
|
|
Packit Service |
4684c1 |
gnutls_global_set_log_level(debug);
|
|
Packit Service |
4684c1 |
if (debug > 1)
|
|
Packit Service |
4684c1 |
printf("Setting log level to %d\n", debug);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if ((ret = gnutls_global_init()) < 0) {
|
|
Packit Service |
4684c1 |
fprintf(stderr, "global_init: %s\n", gnutls_strerror(ret));
|
|
Packit Service |
4684c1 |
app_exit(1);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(PROVIDER)) {
|
|
Packit Service |
4684c1 |
const char *params = NULL;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(PROVIDER_OPTS))
|
|
Packit Service |
4684c1 |
params = OPT_ARG(PROVIDER_OPTS);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
ret = gnutls_pkcs11_init(GNUTLS_PKCS11_FLAG_MANUAL, NULL);
|
|
Packit Service |
4684c1 |
if (ret < 0)
|
|
Packit Service |
4684c1 |
fprintf(stderr, "pkcs11_init: %s\n",
|
|
Packit Service |
4684c1 |
gnutls_strerror(ret));
|
|
Packit Service |
4684c1 |
else {
|
|
Packit Service |
4684c1 |
ret =
|
|
Packit Service |
4684c1 |
gnutls_pkcs11_add_provider(OPT_ARG(PROVIDER),
|
|
Packit Service |
4684c1 |
params);
|
|
Packit Service |
4684c1 |
if (ret < 0) {
|
|
Packit Service |
4684c1 |
fprintf(stderr, "pkcs11_add_provider: %s\n",
|
|
Packit Service |
4684c1 |
gnutls_strerror(ret));
|
|
Packit Service |
4684c1 |
app_exit(1);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
} else {
|
|
Packit Service |
4684c1 |
ret = gnutls_pkcs11_init(GNUTLS_PKCS11_FLAG_AUTO, NULL);
|
|
Packit Service |
4684c1 |
if (ret < 0)
|
|
Packit Service |
4684c1 |
fprintf(stderr, "pkcs11_init: %s\n",
|
|
Packit Service |
4684c1 |
gnutls_strerror(ret));
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(OUTFILE)) {
|
|
Packit Service |
4684c1 |
outfile = safe_open_rw(OPT_ARG(OUTFILE), 0);
|
|
Packit Service |
4684c1 |
if (outfile == NULL) {
|
|
Packit Service |
4684c1 |
fprintf(stderr, "cannot open %s\n", OPT_ARG(OUTFILE));
|
|
Packit Service |
4684c1 |
app_exit(1);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
outfile_name = OPT_ARG(OUTFILE);
|
|
Packit Service |
4684c1 |
} else
|
|
Packit Service |
4684c1 |
outfile = stdout;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
memset(&cinfo, 0, sizeof(cinfo));
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(HASH)) {
|
|
Packit Service |
4684c1 |
cinfo.hash = hash_to_id(OPT_ARG(HASH));
|
|
Packit Service |
4684c1 |
if (cinfo.hash == GNUTLS_DIG_UNKNOWN) {
|
|
Packit Service |
4684c1 |
fprintf(stderr, "invalid hash: %s\n", OPT_ARG(HASH));
|
|
Packit Service |
4684c1 |
app_exit(1);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(SIGN_PARAMS))
|
|
Packit Service |
4684c1 |
sign_params_to_flags(&cinfo, OPT_ARG(SIGN_PARAMS));
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(SECRET_KEY))
|
|
Packit Service |
4684c1 |
cinfo.secret_key = OPT_ARG(SECRET_KEY);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(LOAD_PRIVKEY))
|
|
Packit Service |
4684c1 |
cinfo.privkey = OPT_ARG(LOAD_PRIVKEY);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(PKCS8))
|
|
Packit Service |
4684c1 |
cinfo.pkcs8 = 1;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(BATCH)) {
|
|
Packit Service |
4684c1 |
batch = cinfo.batch = 1;
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(ONLY_URLS)) {
|
|
Packit Service |
4684c1 |
cinfo.only_urls = 1;
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(INDER) || ENABLED_OPT(INRAW))
|
|
Packit Service |
4684c1 |
cinfo.incert_format = GNUTLS_X509_FMT_DER;
|
|
Packit Service |
4684c1 |
else
|
|
Packit Service |
4684c1 |
cinfo.incert_format = GNUTLS_X509_FMT_PEM;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(OUTDER) || HAVE_OPT(OUTRAW))
|
|
Packit Service |
4684c1 |
cinfo.outcert_format = GNUTLS_X509_FMT_DER;
|
|
Packit Service |
4684c1 |
else
|
|
Packit Service |
4684c1 |
cinfo.outcert_format = GNUTLS_X509_FMT_PEM;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(SET_PIN))
|
|
Packit Service |
4684c1 |
cinfo.pin = OPT_ARG(SET_PIN);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(SET_SO_PIN))
|
|
Packit Service |
4684c1 |
cinfo.so_pin = OPT_ARG(SET_SO_PIN);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(LOAD_CERTIFICATE))
|
|
Packit Service |
4684c1 |
cinfo.cert = OPT_ARG(LOAD_CERTIFICATE);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(LOAD_PUBKEY))
|
|
Packit Service |
4684c1 |
cinfo.pubkey = OPT_ARG(LOAD_PUBKEY);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (ENABLED_OPT(DETAILED_URL))
|
|
Packit Service |
4684c1 |
detailed_url = 1;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(LABEL)) {
|
|
Packit Service |
4684c1 |
label = OPT_ARG(LABEL);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(ID)) {
|
|
Packit Service |
4684c1 |
id = OPT_ARG(ID);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(BITS)) {
|
|
Packit Service |
4684c1 |
bits = OPT_VALUE_BITS;
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(CURVE)) {
|
|
Packit Service |
4684c1 |
gnutls_ecc_curve_t curve = str_to_curve(OPT_ARG(CURVE));
|
|
Packit Service |
4684c1 |
bits = GNUTLS_CURVE_TO_BITS(curve);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(SEC_PARAM)) {
|
|
Packit Service |
4684c1 |
sec_param = OPT_ARG(SEC_PARAM);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
flags = opt_to_flags(&cinfo, &key_usage);
|
|
Packit Service |
4684c1 |
cinfo.key_usage = key_usage;
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
/* handle actions
|
|
Packit Service |
4684c1 |
*/
|
|
Packit Service |
4684c1 |
if (HAVE_OPT(LIST_TOKENS)) {
|
|
Packit Service |
4684c1 |
pkcs11_token_list(outfile, detailed_url, &cinfo, 0);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(LIST_TOKEN_URLS)) {
|
|
Packit Service |
4684c1 |
pkcs11_token_list(outfile, detailed_url, &cinfo, 1);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(LIST_MECHANISMS)) {
|
|
Packit Service |
4684c1 |
pkcs11_mechanism_list(outfile, url, flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(GENERATE_RANDOM)) {
|
|
Packit Service |
4684c1 |
pkcs11_get_random(outfile, url, OPT_VALUE_GENERATE_RANDOM,
|
|
Packit Service |
4684c1 |
&cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(INFO)) {
|
|
Packit Service |
4684c1 |
pkcs11_type = PKCS11_TYPE_INFO;
|
|
Packit Service |
4684c1 |
pkcs11_list(outfile, url, pkcs11_type,
|
|
Packit Service |
4684c1 |
flags, detailed_url, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(LIST_ALL)) {
|
|
Packit Service |
4684c1 |
pkcs11_type = PKCS11_TYPE_ALL;
|
|
Packit Service |
4684c1 |
pkcs11_list(outfile, url, pkcs11_type,
|
|
Packit Service |
4684c1 |
flags, detailed_url, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(LIST_ALL_CERTS)) {
|
|
Packit Service |
4684c1 |
pkcs11_type = PKCS11_TYPE_CRT_ALL;
|
|
Packit Service |
4684c1 |
pkcs11_list(outfile, url, pkcs11_type,
|
|
Packit Service |
4684c1 |
flags, detailed_url, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(LIST_CERTS)) {
|
|
Packit Service |
4684c1 |
pkcs11_type = PKCS11_TYPE_PK;
|
|
Packit Service |
4684c1 |
pkcs11_list(outfile, url, pkcs11_type,
|
|
Packit Service |
4684c1 |
flags, detailed_url, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(LIST_ALL_PRIVKEYS)) {
|
|
Packit Service |
4684c1 |
pkcs11_type = PKCS11_TYPE_PRIVKEY;
|
|
Packit Service |
4684c1 |
pkcs11_list(outfile, url, pkcs11_type,
|
|
Packit Service |
4684c1 |
flags, detailed_url, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(LIST_ALL_TRUSTED)) {
|
|
Packit Service |
4684c1 |
pkcs11_type = PKCS11_TYPE_TRUSTED;
|
|
Packit Service |
4684c1 |
pkcs11_list(outfile, url, pkcs11_type,
|
|
Packit Service |
4684c1 |
flags, detailed_url, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(EXPORT)) {
|
|
Packit Service |
4684c1 |
pkcs11_export(outfile, url, flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(EXPORT_STAPLED)) {
|
|
Packit Service |
4684c1 |
pkcs11_export(outfile, url, flags|GNUTLS_PKCS11_OBJ_FLAG_OVERWRITE_TRUSTMOD_EXT, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(EXPORT_CHAIN)) {
|
|
Packit Service |
4684c1 |
pkcs11_export_chain(outfile, url, flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(WRITE)) {
|
|
Packit Service |
4684c1 |
pkcs11_write(outfile, url, label, id,
|
|
Packit Service |
4684c1 |
flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(TEST_SIGN)) {
|
|
Packit Service |
4684c1 |
pkcs11_test_sign(outfile, url, flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(INITIALIZE)) {
|
|
Packit Service |
4684c1 |
pkcs11_init(outfile, url, label, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(INITIALIZE_PIN)) {
|
|
Packit Service |
4684c1 |
pkcs11_set_token_pin(outfile, url, &cinfo, 0);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(INITIALIZE_SO_PIN)) {
|
|
Packit Service |
4684c1 |
pkcs11_set_token_pin(outfile, url, &cinfo, 1);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(DELETE)) {
|
|
Packit Service |
4684c1 |
pkcs11_delete(outfile, url, flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(GENERATE_PRIVKEY)) {
|
|
Packit Service |
4684c1 |
key_type = figure_key_type(OPT_ARG(GENERATE_PRIVKEY));
|
|
Packit Service |
4684c1 |
if (key_type == GNUTLS_PK_UNKNOWN)
|
|
Packit Service |
4684c1 |
app_exit(1);
|
|
Packit Service |
4684c1 |
pkcs11_generate(outfile, url, key_type,
|
|
Packit Service |
4684c1 |
get_bits(key_type, bits, sec_param, 0),
|
|
Packit Service |
4684c1 |
label, id, detailed_url,
|
|
Packit Service |
4684c1 |
flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(GENERATE_ECC)) {
|
|
Packit Service |
4684c1 |
key_type = GNUTLS_PK_EC;
|
|
Packit Service |
4684c1 |
pkcs11_generate(outfile, url, key_type,
|
|
Packit Service |
4684c1 |
get_bits(key_type, bits, sec_param, 0),
|
|
Packit Service |
4684c1 |
label, id, detailed_url,
|
|
Packit Service |
4684c1 |
flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(GENERATE_RSA)) {
|
|
Packit Service |
4684c1 |
key_type = GNUTLS_PK_RSA;
|
|
Packit Service |
4684c1 |
pkcs11_generate(outfile, url, key_type,
|
|
Packit Service |
4684c1 |
get_bits(key_type, bits, sec_param, 0),
|
|
Packit Service |
4684c1 |
label, id, detailed_url,
|
|
Packit Service |
4684c1 |
flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(GENERATE_DSA)) {
|
|
Packit Service |
4684c1 |
key_type = GNUTLS_PK_DSA;
|
|
Packit Service |
4684c1 |
pkcs11_generate(outfile, url, key_type,
|
|
Packit Service |
4684c1 |
get_bits(key_type, bits, sec_param, 0),
|
|
Packit Service |
4684c1 |
label, id, detailed_url,
|
|
Packit Service |
4684c1 |
flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(EXPORT_PUBKEY)) {
|
|
Packit Service |
4684c1 |
pkcs11_export_pubkey(outfile, url, detailed_url, flags, &cinfo);
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(SET_ID)) {
|
|
Packit Service |
4684c1 |
pkcs11_set_id(outfile, url, detailed_url, flags, &cinfo, OPT_ARG(SET_ID));
|
|
Packit Service |
4684c1 |
} else if (HAVE_OPT(SET_LABEL)) {
|
|
Packit Service |
4684c1 |
pkcs11_set_label(outfile, url, detailed_url, flags, &cinfo, OPT_ARG(SET_LABEL));
|
|
Packit Service |
4684c1 |
} else {
|
|
Packit Service |
4684c1 |
USAGE(1);
|
|
Packit Service |
4684c1 |
}
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
fclose(outfile);
|
|
Packit Service |
4684c1 |
|
|
Packit Service |
4684c1 |
#ifdef ENABLE_PKCS11
|
|
Packit Service |
4684c1 |
gnutls_pkcs11_deinit();
|
|
Packit Service |
4684c1 |
#endif
|
|
Packit Service |
4684c1 |
gnutls_global_deinit();
|
|
Packit Service |
4684c1 |
}
|