Blame src/tpmtool.c

Packit Service 4684c1
/*
Packit Service 4684c1
 * Copyright (C) 2010-2012 Free Software Foundation, Inc.
Packit Service 4684c1
 *
Packit Service 4684c1
 * Author: Nikos Mavrogiannopoulos
Packit Service 4684c1
 *
Packit Service 4684c1
 * This file is part of GnuTLS.
Packit Service 4684c1
 *
Packit Service 4684c1
 * GnuTLS is free software: you can redistribute it and/or modify it
Packit Service 4684c1
 * under the terms of the GNU General Public License as published by
Packit Service 4684c1
 * the Free Software Foundation, either version 3 of the License, or
Packit Service 4684c1
 * (at your option) any later version.
Packit Service 4684c1
 *
Packit Service 4684c1
 * GnuTLS is distributed in the hope that it will be useful, but
Packit Service 4684c1
 * WITHOUT ANY WARRANTY; without even the implied warranty of
Packit Service 4684c1
 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU
Packit Service 4684c1
 * General Public License for more details.
Packit Service 4684c1
 *
Packit Service 4684c1
 * You should have received a copy of the GNU General Public License
Packit Service 4684c1
 * along with this program.  If not, see
Packit Service 4684c1
 * <https://www.gnu.org/licenses/>.
Packit Service 4684c1
 */
Packit Service 4684c1
Packit Service 4684c1
#include <config.h>
Packit Service 4684c1
Packit Service 4684c1
#include <gnutls/gnutls.h>
Packit Service 4684c1
#include <gnutls/x509.h>
Packit Service 4684c1
#include <gnutls/openpgp.h>
Packit Service 4684c1
#include <gnutls/pkcs12.h>
Packit Service 4684c1
#include <gnutls/tpm.h>
Packit Service 4684c1
#include <gnutls/abstract.h>
Packit Service 4684c1
Packit Service 4684c1
#include <stdio.h>
Packit Service 4684c1
#include <stdlib.h>
Packit Service 4684c1
#include <string.h>
Packit Service 4684c1
#include <ctype.h>
Packit Service 4684c1
#include <time.h>
Packit Service 4684c1
#include <unistd.h>
Packit Service 4684c1
#include <errno.h>
Packit Service 4684c1
#include <sys/types.h>
Packit Service 4684c1
#include <sys/stat.h>
Packit Service 4684c1
#include <fcntl.h>
Packit Service 4684c1
Packit Service 4684c1
/* Gnulib portability files. */
Packit Service 4684c1
#include <read-file.h>
Packit Service 4684c1
Packit Service 4684c1
#include "certtool-common.h"
Packit Service 4684c1
#include "tpmtool-args.h"
Packit Service 4684c1
#include "common.h"
Packit Service 4684c1
Packit Service 4684c1
static void cmd_parser(int argc, char **argv);
Packit Service 4684c1
static void tpm_generate(FILE * outfile, unsigned int key_type,
Packit Service 4684c1
			 unsigned int bits, unsigned int flags,
Packit Service 4684c1
			 unsigned int srk_well_known);
Packit Service 4684c1
static void tpm_pubkey(const char *url, FILE * outfile,
Packit Service 4684c1
		       unsigned int srk_well_known);
Packit Service 4684c1
static void tpm_delete(const char *url, FILE * outfile,
Packit Service 4684c1
		       unsigned int srk_well_known);
Packit Service 4684c1
static void tpm_test_sign(const char *url, FILE * outfile);
Packit Service 4684c1
static void tpm_list(FILE * outfile);
Packit Service 4684c1
Packit Service 4684c1
static gnutls_x509_crt_fmt_t incert_format, outcert_format;
Packit Service 4684c1
static gnutls_tpmkey_fmt_t inkey_format, outkey_format;
Packit Service 4684c1
Packit Service 4684c1
static FILE *outfile;
Packit Service 4684c1
static const char *outfile_name = NULL;
Packit Service 4684c1
static FILE *infile;
Packit Service 4684c1
int batch = 0;
Packit Service 4684c1
int ask_pass = 0;
Packit Service 4684c1
Packit Service 4684c1
void app_exit(int val)
Packit Service 4684c1
{
Packit Service 4684c1
	if (val != 0) {
Packit Service 4684c1
		if (outfile_name != NULL) {
Packit Service 4684c1
			remove(outfile_name);
Packit Service 4684c1
		}
Packit Service 4684c1
	}
Packit Service 4684c1
	exit(val);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void tls_log_func(int level, const char *str)
Packit Service 4684c1
{
Packit Service 4684c1
	fprintf(stderr, "|<%d>| %s", level, str);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
Packit Service 4684c1
int main(int argc, char **argv)
Packit Service 4684c1
{
Packit Service 4684c1
	cmd_parser(argc, argv);
Packit Service 4684c1
Packit Service 4684c1
	return 0;
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void cmd_parser(int argc, char **argv)
Packit Service 4684c1
{
Packit Service 4684c1
	int ret, debug = 0;
Packit Service 4684c1
	unsigned int key_type = GNUTLS_PK_UNKNOWN;
Packit Service 4684c1
	unsigned int bits = 0;
Packit Service 4684c1
	unsigned int genflags = 0;
Packit Service 4684c1
	/* Note that the default sec-param is legacy because several TPMs
Packit Service 4684c1
	 * cannot handle larger keys.
Packit Service 4684c1
	 */
Packit Service 4684c1
	const char *sec_param = "legacy";
Packit Service 4684c1
Packit Service 4684c1
	optionProcess(&tpmtoolOptions, argc, argv);
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(DEBUG))
Packit Service 4684c1
		debug = OPT_VALUE_DEBUG;
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(INDER)) {
Packit Service 4684c1
		incert_format = GNUTLS_X509_FMT_DER;
Packit Service 4684c1
		inkey_format = GNUTLS_TPMKEY_FMT_DER;
Packit Service 4684c1
	} else {
Packit Service 4684c1
		incert_format = GNUTLS_X509_FMT_PEM;
Packit Service 4684c1
		inkey_format = GNUTLS_TPMKEY_FMT_CTK_PEM;
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(OUTDER)) {
Packit Service 4684c1
		outcert_format = GNUTLS_X509_FMT_DER;
Packit Service 4684c1
		outkey_format = GNUTLS_TPMKEY_FMT_DER;
Packit Service 4684c1
	} else {
Packit Service 4684c1
		outcert_format = GNUTLS_X509_FMT_PEM;
Packit Service 4684c1
		outkey_format = GNUTLS_TPMKEY_FMT_CTK_PEM;
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(REGISTER))
Packit Service 4684c1
		genflags |= GNUTLS_TPM_REGISTER_KEY;
Packit Service 4684c1
	if (!HAVE_OPT(LEGACY))
Packit Service 4684c1
		genflags |= GNUTLS_TPM_KEY_SIGNING;
Packit Service 4684c1
	if (HAVE_OPT(USER))
Packit Service 4684c1
		genflags |= GNUTLS_TPM_KEY_USER;
Packit Service 4684c1
Packit Service 4684c1
	gnutls_global_set_log_function(tls_log_func);
Packit Service 4684c1
	gnutls_global_set_log_level(debug);
Packit Service 4684c1
	if (debug > 1)
Packit Service 4684c1
		printf("Setting log level to %d\n", debug);
Packit Service 4684c1
Packit Service 4684c1
	if ((ret = gnutls_global_init()) < 0) {
Packit Service 4684c1
		fprintf(stderr, "global_init: %s\n", gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(OUTFILE)) {
Packit Service 4684c1
		outfile = safe_open_rw(OPT_ARG(OUTFILE), 0);
Packit Service 4684c1
		if (outfile == NULL) {
Packit Service 4684c1
			fprintf(stderr, "%s\n", OPT_ARG(OUTFILE));
Packit Service 4684c1
			exit(1);
Packit Service 4684c1
		}
Packit Service 4684c1
		outfile_name = OPT_ARG(OUTFILE);
Packit Service 4684c1
	} else
Packit Service 4684c1
		outfile = stdout;
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(INFILE)) {
Packit Service 4684c1
		infile = fopen(OPT_ARG(INFILE), "rb");
Packit Service 4684c1
		if (infile == NULL) {
Packit Service 4684c1
			fprintf(stderr, "%s\n", OPT_ARG(INFILE));
Packit Service 4684c1
			exit(1);
Packit Service 4684c1
		}
Packit Service 4684c1
	} else
Packit Service 4684c1
		infile = stdin;
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(SEC_PARAM))
Packit Service 4684c1
		sec_param = OPT_ARG(SEC_PARAM);
Packit Service 4684c1
	if (HAVE_OPT(BITS))
Packit Service 4684c1
		bits = OPT_VALUE_BITS;
Packit Service 4684c1
Packit Service 4684c1
Packit Service 4684c1
	if (HAVE_OPT(GENERATE_RSA)) {
Packit Service 4684c1
		key_type = GNUTLS_PK_RSA;
Packit Service 4684c1
		bits = get_bits(key_type, bits, sec_param, 0);
Packit Service 4684c1
		tpm_generate(outfile, key_type, bits, genflags, HAVE_OPT(SRK_WELL_KNOWN));
Packit Service 4684c1
	} else if (HAVE_OPT(PUBKEY)) {
Packit Service 4684c1
		tpm_pubkey(OPT_ARG(PUBKEY), outfile, HAVE_OPT(SRK_WELL_KNOWN));
Packit Service 4684c1
	} else if (HAVE_OPT(DELETE)) {
Packit Service 4684c1
		tpm_delete(OPT_ARG(DELETE), outfile, HAVE_OPT(SRK_WELL_KNOWN));
Packit Service 4684c1
	} else if (HAVE_OPT(LIST)) {
Packit Service 4684c1
		tpm_list(outfile);
Packit Service 4684c1
	} else if (HAVE_OPT(TEST_SIGN)) {
Packit Service 4684c1
		tpm_test_sign(OPT_ARG(TEST_SIGN), outfile);
Packit Service 4684c1
	} else {
Packit Service 4684c1
		USAGE(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	fclose(outfile);
Packit Service 4684c1
Packit Service 4684c1
	gnutls_global_deinit();
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
#define TEST_DATA "Test data to sign"
Packit Service 4684c1
Packit Service 4684c1
static void
Packit Service 4684c1
tpm_test_sign(const char *url, FILE * out)
Packit Service 4684c1
{
Packit Service 4684c1
	gnutls_privkey_t privkey;
Packit Service 4684c1
	gnutls_pubkey_t pubkey;
Packit Service 4684c1
	int ret;
Packit Service 4684c1
	gnutls_datum_t data, sig = {NULL, 0};
Packit Service 4684c1
	int pk;
Packit Service 4684c1
Packit Service 4684c1
	pkcs11_common(NULL);
Packit Service 4684c1
Packit Service 4684c1
	data.data = (void*)TEST_DATA;
Packit Service 4684c1
	data.size = sizeof(TEST_DATA)-1;
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_privkey_init(&privkey);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "Error in %s:%d: %s\n", __func__,
Packit Service 4684c1
			__LINE__, gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_pubkey_init(&pubkey);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "Error in %s:%d: %s\n", __func__,
Packit Service 4684c1
			__LINE__, gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_privkey_import_url(privkey, url, 0);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "Cannot import private key: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_pubkey_import_tpm_url(pubkey, url, NULL, 0);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "Cannot import public key: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_privkey_sign_data(privkey, GNUTLS_DIG_SHA1, 0, &data, &sig);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "Cannot sign data: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	pk = gnutls_pubkey_get_pk_algorithm(pubkey, NULL);
Packit Service 4684c1
Packit Service 4684c1
	fprintf(stderr, "Verifying against private key parameters... ");
Packit Service 4684c1
	ret = gnutls_pubkey_verify_data2(pubkey, gnutls_pk_to_sign(pk, GNUTLS_DIG_SHA1),
Packit Service 4684c1
		0, &data, &sig);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "Cannot verify signed data: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	fprintf(stderr, "ok\n");
Packit Service 4684c1
Packit Service 4684c1
	gnutls_free(sig.data);
Packit Service 4684c1
	gnutls_pubkey_deinit(pubkey);
Packit Service 4684c1
	gnutls_privkey_deinit(privkey);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void tpm_generate(FILE * out, unsigned int key_type,
Packit Service 4684c1
			 unsigned int bits, unsigned int flags,
Packit Service 4684c1
			 unsigned int srk_well_known)
Packit Service 4684c1
{
Packit Service 4684c1
	int ret;
Packit Service 4684c1
	char *srk_pass = NULL, *key_pass = NULL;
Packit Service 4684c1
	gnutls_datum_t privkey, pubkey;
Packit Service 4684c1
Packit Service 4684c1
	if (!srk_well_known) {
Packit Service 4684c1
		srk_pass = getpass("Enter SRK password: ");
Packit Service 4684c1
		if (srk_pass != NULL)
Packit Service 4684c1
			srk_pass = strdup(srk_pass);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	if (!(flags & GNUTLS_TPM_REGISTER_KEY)) {
Packit Service 4684c1
		key_pass = getpass("Enter key password: ");
Packit Service 4684c1
		if (key_pass != NULL)
Packit Service 4684c1
			key_pass = strdup(key_pass);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	ret =
Packit Service 4684c1
	    gnutls_tpm_privkey_generate(key_type, bits, srk_pass, key_pass,
Packit Service 4684c1
					outkey_format, outcert_format,
Packit Service 4684c1
					&privkey, &pubkey, flags);
Packit Service 4684c1
Packit Service 4684c1
	free(key_pass);
Packit Service 4684c1
	free(srk_pass);
Packit Service 4684c1
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "gnutls_tpm_privkey_generate: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
Packit Service 4684c1
	fwrite(privkey.data, 1, privkey.size, out);
Packit Service 4684c1
	fputs("\n", out);
Packit Service 4684c1
Packit Service 4684c1
	gnutls_free(privkey.data);
Packit Service 4684c1
	gnutls_free(pubkey.data);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void tpm_delete(const char *url, FILE * out,
Packit Service 4684c1
		       unsigned int srk_well_known)
Packit Service 4684c1
{
Packit Service 4684c1
	int ret;
Packit Service 4684c1
	char *srk_pass = NULL;
Packit Service 4684c1
Packit Service 4684c1
	if (!srk_well_known)
Packit Service 4684c1
		srk_pass = getpass("Enter SRK password: ");
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_tpm_privkey_delete(url, srk_pass);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "gnutls_tpm_privkey_delete: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	fprintf(out, "Key %s deleted\n", url);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void tpm_list(FILE * out)
Packit Service 4684c1
{
Packit Service 4684c1
	int ret;
Packit Service 4684c1
	gnutls_tpm_key_list_t list;
Packit Service 4684c1
	unsigned int i;
Packit Service 4684c1
	char *url;
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_tpm_get_registered(&list);
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "gnutls_tpm_get_registered: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	fprintf(out, "Available keys:\n");
Packit Service 4684c1
	for (i = 0;; i++) {
Packit Service 4684c1
		ret = gnutls_tpm_key_list_get_url(list, i, &url, 0);
Packit Service 4684c1
		if (ret == GNUTLS_E_REQUESTED_DATA_NOT_AVAILABLE)
Packit Service 4684c1
			break;
Packit Service 4684c1
		else if (ret < 0) {
Packit Service 4684c1
			fprintf(stderr, "gnutls_tpm_key_list_get_url: %s\n",
Packit Service 4684c1
				gnutls_strerror(ret));
Packit Service 4684c1
			gnutls_tpm_key_list_deinit(list);
Packit Service 4684c1
			exit(1);
Packit Service 4684c1
		}
Packit Service 4684c1
Packit Service 4684c1
		fprintf(out, "\t%u: %s\n", i, url);
Packit Service 4684c1
		gnutls_free(url);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	gnutls_tpm_key_list_deinit(list);
Packit Service 4684c1
	fputs("\n", out);
Packit Service 4684c1
}
Packit Service 4684c1
Packit Service 4684c1
static void tpm_pubkey(const char *url, FILE * out, unsigned int srk_well_known)
Packit Service 4684c1
{
Packit Service 4684c1
	int ret;
Packit Service 4684c1
	char *srk_pass = NULL;
Packit Service 4684c1
	gnutls_pubkey_t pubkey;
Packit Service 4684c1
Packit Service 4684c1
	if (!srk_well_known) {
Packit Service 4684c1
		srk_pass = getpass("Enter SRK password: ");
Packit Service 4684c1
		if (srk_pass != NULL)
Packit Service 4684c1
			srk_pass = strdup(srk_pass);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	gnutls_pubkey_init(&pubkey);
Packit Service 4684c1
Packit Service 4684c1
	ret = gnutls_pubkey_import_tpm_url(pubkey, url, srk_pass, 0);
Packit Service 4684c1
Packit Service 4684c1
	free(srk_pass);
Packit Service 4684c1
Packit Service 4684c1
	if (ret < 0) {
Packit Service 4684c1
		fprintf(stderr, "gnutls_pubkey_import_tpm_url: %s\n",
Packit Service 4684c1
			gnutls_strerror(ret));
Packit Service 4684c1
		exit(1);
Packit Service 4684c1
	}
Packit Service 4684c1
Packit Service 4684c1
	print_pubkey_info(pubkey, out, GNUTLS_CRT_PRINT_FULL, GNUTLS_X509_FMT_PEM, 1);
Packit Service 4684c1
Packit Service 4684c1
	gnutls_pubkey_deinit(pubkey);
Packit Service 4684c1
}