|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* Copyright (c) 2013, Red Hat Inc.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Redistribution and use in source and binary forms, with or without
|
|
Packit Service |
3749ba |
* modification, are permitted provided that the following conditions
|
|
Packit Service |
3749ba |
* are met:
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* * Redistributions of source code must retain the above
|
|
Packit Service |
3749ba |
* copyright notice, this list of conditions and the
|
|
Packit Service |
3749ba |
* following disclaimer.
|
|
Packit Service |
3749ba |
* * Redistributions in binary form must reproduce the
|
|
Packit Service |
3749ba |
* above copyright notice, this list of conditions and
|
|
Packit Service |
3749ba |
* the following disclaimer in the documentation and/or
|
|
Packit Service |
3749ba |
* other materials provided with the distribution.
|
|
Packit Service |
3749ba |
* * The names of contributors to this software may not be
|
|
Packit Service |
3749ba |
* used to endorse or promote products derived from this
|
|
Packit Service |
3749ba |
* software without specific prior written permission.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
Packit Service |
3749ba |
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
Packit Service |
3749ba |
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
|
Packit Service |
3749ba |
* FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
|
Packit Service |
3749ba |
* COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
Packit Service |
3749ba |
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
|
|
Packit Service |
3749ba |
* BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
|
|
Packit Service |
3749ba |
* OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
|
|
Packit Service |
3749ba |
* AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
|
|
Packit Service |
3749ba |
* OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
|
|
Packit Service |
3749ba |
* THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
|
|
Packit Service |
3749ba |
* DAMAGE.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Author: Stef Walter <stefw@redhat.com>
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "config.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#define P11_DEBUG_FLAG P11_DEBUG_TOOL
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "anchor.h"
|
|
Packit Service |
3749ba |
#include "attrs.h"
|
|
Packit Service |
3749ba |
#include "debug.h"
|
|
Packit Service |
3749ba |
#include "constants.h"
|
|
Packit Service |
3749ba |
#include "extract.h"
|
|
Packit Service |
3749ba |
#include "message.h"
|
|
Packit Service |
3749ba |
#include "parser.h"
|
|
Packit Service |
3749ba |
#include "tool.h"
|
|
Packit Service |
3749ba |
#include "pkcs11x.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "p11-kit/iter.h"
|
|
Packit Service |
3749ba |
#include "p11-kit/p11-kit.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include <assert.h>
|
|
Packit Service |
3749ba |
#include <getopt.h>
|
|
Packit Service |
3749ba |
#include <stdio.h>
|
|
Packit Service |
3749ba |
#include <stdlib.h>
|
|
Packit Service |
3749ba |
#include <string.h>
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static p11_parser *
|
|
Packit Service |
3749ba |
create_arg_file_parser (void)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
p11_parser *parser;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
parser = p11_parser_new (NULL);
|
|
Packit Service |
3749ba |
return_val_if_fail (parser != NULL, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_parser_formats (parser,
|
|
Packit Service |
a29e5c |
p11_parser_format_x509,
|
|
Packit Service |
a29e5c |
p11_parser_format_pem,
|
|
Packit Service |
a29e5c |
NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return parser;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static bool
|
|
Packit Service |
3749ba |
iter_match_anchor (p11_kit_iter *iter,
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attrs)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attr;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
attr = p11_attrs_find_valid (attrs, CKA_CLASS);
|
|
Packit Service |
3749ba |
if (attr == NULL)
|
|
Packit Service |
3749ba |
return false;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (iter, attr, 1);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
attr = p11_attrs_find_valid (attrs, CKA_VALUE);
|
|
Packit Service |
3749ba |
if (attr == NULL)
|
|
Packit Service |
3749ba |
return false;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_add_filter (iter, attr, 1);
|
|
Packit Service |
3749ba |
return true;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static p11_array *
|
|
Packit Service |
3749ba |
uris_or_files_to_iters (int argc,
|
|
Packit Service |
3749ba |
char *argv[],
|
|
Packit Service |
3749ba |
int behavior)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
int flags = P11_KIT_URI_FOR_OBJECT_ON_TOKEN_AND_MODULE;
|
|
Packit Service |
3749ba |
p11_parser *parser = NULL;
|
|
Packit Service |
3749ba |
p11_array *iters;
|
|
Packit Service |
3749ba |
p11_array *parsed;
|
|
Packit Service |
3749ba |
p11_kit_uri *uri;
|
|
Packit Service |
3749ba |
p11_kit_iter *iter;
|
|
Packit Service |
3749ba |
int ret;
|
|
Packit Service |
3749ba |
int i, j;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
iters = p11_array_new ((p11_destroyer)p11_kit_iter_free);
|
|
Packit Service |
3749ba |
return_val_if_fail (iters != NULL, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0; i < argc; i++) {
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* A PKCS#11 URI */
|
|
Packit Service |
3749ba |
if (strncmp (argv[i], "pkcs11:", 7) == 0) {
|
|
Packit Service |
3749ba |
uri = p11_kit_uri_new ();
|
|
Packit Service |
3749ba |
if (p11_kit_uri_parse (argv[i], flags, uri) != P11_KIT_URI_OK) {
|
|
Packit Service |
3749ba |
p11_message ("invalid PKCS#11 uri: %s", argv[i]);
|
|
Packit Service |
3749ba |
p11_kit_uri_free (uri);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
iter = p11_kit_iter_new (uri, behavior);
|
|
Packit Service |
3749ba |
return_val_if_fail (iter != NULL, NULL);
|
|
Packit Service |
3749ba |
p11_kit_uri_free (uri);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!p11_array_push (iters, iter))
|
|
Packit Service |
3749ba |
return_val_if_reached (NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
} else {
|
|
Packit Service |
3749ba |
if (parser == NULL)
|
|
Packit Service |
3749ba |
parser = create_arg_file_parser ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ret = p11_parse_file (parser, argv[i], NULL, P11_PARSE_FLAG_ANCHOR);
|
|
Packit Service |
3749ba |
switch (ret) {
|
|
Packit Service |
3749ba |
case P11_PARSE_SUCCESS:
|
|
Packit Service |
3749ba |
p11_debug ("parsed file: %s", argv[i]);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case P11_PARSE_UNRECOGNIZED:
|
|
Packit Service |
3749ba |
p11_message ("unrecognized file format: %s", argv[i]);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
default:
|
|
Packit Service |
3749ba |
p11_message ("failed to parse file: %s", argv[i]);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (ret != P11_PARSE_SUCCESS)
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
parsed = p11_parser_parsed (parser);
|
|
Packit Service |
3749ba |
for (j = 0; j < parsed->num; j++) {
|
|
Packit Service |
3749ba |
iter = p11_kit_iter_new (NULL, behavior);
|
|
Packit Service |
3749ba |
return_val_if_fail (iter != NULL, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
iter_match_anchor (iter, parsed->elem[j]);
|
|
Packit Service |
3749ba |
if (!p11_array_push (iters, iter))
|
|
Packit Service |
3749ba |
return_val_if_reached (NULL);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (parser)
|
|
Packit Service |
3749ba |
p11_parser_free (parser);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (argc != i) {
|
|
Packit Service |
3749ba |
p11_array_free (iters);
|
|
Packit Service |
3749ba |
return NULL;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return iters;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static p11_array *
|
|
Packit Service |
3749ba |
files_to_attrs (int argc,
|
|
Packit Service |
3749ba |
char *argv[])
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
p11_parser *parser;
|
|
Packit Service |
3749ba |
p11_array *parsed;
|
|
Packit Service |
3749ba |
p11_array *array;
|
|
Packit Service |
3749ba |
int ret = P11_PARSE_SUCCESS;
|
|
Packit Service |
3749ba |
int i, j;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
array = p11_array_new (p11_attrs_free);
|
|
Packit Service |
3749ba |
return_val_if_fail (array != NULL, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
parser = create_arg_file_parser ();
|
|
Packit Service |
3749ba |
return_val_if_fail (parser != NULL, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0; i < argc; i++) {
|
|
Packit Service |
3749ba |
ret = p11_parse_file (parser, argv[i], NULL, P11_PARSE_FLAG_ANCHOR);
|
|
Packit Service |
3749ba |
switch (ret) {
|
|
Packit Service |
3749ba |
case P11_PARSE_SUCCESS:
|
|
Packit Service |
3749ba |
p11_debug ("parsed file: %s", argv[i]);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case P11_PARSE_UNRECOGNIZED:
|
|
Packit Service |
3749ba |
p11_message ("unrecognized file format: %s", argv[i]);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
default:
|
|
Packit Service |
3749ba |
p11_message ("failed to parse file: %s", argv[i]);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (ret != P11_PARSE_SUCCESS)
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
parsed = p11_parser_parsed (parser);
|
|
Packit Service |
3749ba |
for (j = 0; j < parsed->num; j++) {
|
|
Packit Service |
3749ba |
if (!p11_array_push (array, parsed->elem[j]))
|
|
Packit Service |
3749ba |
return_val_if_reached (NULL);
|
|
Packit Service |
3749ba |
parsed->elem[j] = NULL;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_parser_free (parser);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (ret == P11_PARSE_SUCCESS)
|
|
Packit Service |
3749ba |
return array;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_array_free (array);
|
|
Packit Service |
3749ba |
return NULL;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_SESSION_HANDLE
|
|
Packit Service |
3749ba |
session_for_store_on_module (const char *name,
|
|
Packit Service |
3749ba |
CK_FUNCTION_LIST *module,
|
|
Packit Service |
3749ba |
bool *found_read_only)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_SESSION_HANDLE session = 0;
|
|
Packit Service |
3749ba |
CK_SLOT_ID *slots = NULL;
|
|
Packit Service |
3749ba |
CK_TOKEN_INFO info;
|
|
Packit Service |
3749ba |
CK_ULONG count = 0;
|
|
Packit Service |
3749ba |
CK_ULONG i;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_module_initialize (module);
|
|
Packit Service |
3749ba |
if (rv != CKR_OK) {
|
|
Packit Service |
3749ba |
p11_message ("%s: couldn't initialize: %s", name, p11_kit_message ());
|
|
Packit Service |
3749ba |
return 0UL;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = (module->C_GetSlotList) (CK_TRUE, NULL, &count);
|
|
Packit Service |
3749ba |
if (rv == CKR_OK) {
|
|
Packit Service |
3749ba |
slots = calloc (count + 1, sizeof (CK_ULONG));
|
|
Packit Service |
3749ba |
return_val_if_fail (slots != NULL, 0UL);
|
|
Packit Service |
3749ba |
rv = (module->C_GetSlotList) (CK_TRUE, slots, &count);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
if (rv != CKR_OK) {
|
|
Packit Service |
3749ba |
p11_message ("%s: couldn't enumerate slots: %s", name, p11_kit_strerror (rv));
|
|
Packit Service |
3749ba |
free (slots);
|
|
Packit Service |
3749ba |
return 0UL;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0; session == 0 && i < count; i++) {
|
|
Packit Service |
3749ba |
rv = (module->C_GetTokenInfo) (slots[i], &info;;
|
|
Packit Service |
3749ba |
if (rv != CKR_OK) {
|
|
Packit Service |
3749ba |
p11_message ("%s: couldn't get token info: %s", name, p11_kit_strerror (rv));
|
|
Packit Service |
3749ba |
continue;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (info.flags & CKF_WRITE_PROTECTED) {
|
|
Packit Service |
3749ba |
*found_read_only = true;
|
|
Packit Service |
3749ba |
continue;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = (module->C_OpenSession) (slots[i], CKF_SERIAL_SESSION | CKF_RW_SESSION,
|
|
Packit Service |
3749ba |
NULL, NULL, &session);
|
|
Packit Service |
3749ba |
if (rv != CKR_OK) {
|
|
Packit Service |
3749ba |
p11_message ("%s: couldn't open session: %s", name, p11_kit_strerror (rv));
|
|
Packit Service |
3749ba |
session = 0;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_debug ("opened writable session on: %s", name);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
free (slots);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (session == 0UL)
|
|
Packit Service |
3749ba |
p11_kit_module_finalize (module);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return session;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_SESSION_HANDLE
|
|
Packit Service |
3749ba |
session_for_store (CK_FUNCTION_LIST **module)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_SESSION_HANDLE session = 0UL;
|
|
Packit Service |
3749ba |
CK_FUNCTION_LIST **modules;
|
|
Packit Service |
3749ba |
bool found_read_only = false;
|
|
Packit Service |
3749ba |
char *name;
|
|
Packit Service |
3749ba |
int i;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
modules = p11_kit_modules_load (NULL, P11_KIT_MODULE_TRUSTED);
|
|
Packit Service |
3749ba |
if (modules == NULL)
|
|
Packit Service |
3749ba |
return 0;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0; modules[i] != NULL; i++) {
|
|
Packit Service |
3749ba |
if (session == 0UL) {
|
|
Packit Service |
3749ba |
name = p11_kit_module_get_name (modules[i]);
|
|
Packit Service |
3749ba |
session = session_for_store_on_module (name, modules[i],
|
|
Packit Service |
3749ba |
&found_read_only);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (session != 0UL) {
|
|
Packit Service |
3749ba |
*module = modules[i];
|
|
Packit Service |
3749ba |
modules[i] = NULL;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
free (name);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (modules[i])
|
|
Packit Service |
3749ba |
p11_kit_module_release (modules[i]);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (session == 0UL) {
|
|
Packit Service |
3749ba |
if (found_read_only)
|
|
Packit Service |
3749ba |
p11_message ("no configured writable location to store anchors");
|
|
Packit Service |
3749ba |
else
|
|
Packit Service |
3749ba |
p11_message ("no configured location to store anchors");
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
free (modules);
|
|
Packit Service |
3749ba |
return session;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static bool
|
|
Packit Service |
3749ba |
create_anchor (CK_FUNCTION_LIST *module,
|
|
Packit Service |
3749ba |
CK_SESSION_HANDLE session,
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attrs)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_BBOOL truev = CK_TRUE;
|
|
Packit Service |
3749ba |
CK_OBJECT_HANDLE object;
|
|
Packit Service |
3749ba |
char *string;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
CK_ULONG klass;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE basics_certificate[] = {
|
|
Packit Service |
3749ba |
{ CKA_TOKEN, &truev, sizeof (truev) },
|
|
Packit Service |
3749ba |
{ CKA_TRUSTED, &truev, sizeof (truev) },
|
|
Packit Service |
3749ba |
{ CKA_INVALID, },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE basics_extension[] = {
|
|
Packit Service |
3749ba |
{ CKA_TOKEN, &truev, sizeof (truev) },
|
|
Packit Service |
3749ba |
{ CKA_INVALID, },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE basics_empty[] = {
|
|
Packit Service |
3749ba |
{ CKA_INVALID, },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *basics = basics_empty;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (p11_attrs_find_ulong (attrs, CKA_CLASS, &klass)) {
|
|
Packit Service |
3749ba |
switch (klass) {
|
|
Packit Service |
3749ba |
case CKO_CERTIFICATE:
|
|
Packit Service |
3749ba |
basics = basics_certificate;
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case CKO_X_CERTIFICATE_EXTENSION:
|
|
Packit Service |
3749ba |
basics = basics_extension;
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
attrs = p11_attrs_merge (attrs, p11_attrs_dup (basics), true);
|
|
Packit Service |
3749ba |
p11_attrs_remove (attrs, CKA_MODIFIABLE);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (p11_debugging) {
|
|
Packit Service |
3749ba |
string = p11_attrs_to_string (attrs, -1);
|
|
Packit Service |
3749ba |
p11_debug ("storing: %s", string);
|
|
Packit Service |
3749ba |
free (string);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = (module->C_CreateObject) (session, attrs,
|
|
Packit Service |
3749ba |
p11_attrs_count (attrs), &object);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_attrs_free (attrs);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (rv != CKR_OK) {
|
|
Packit Service |
3749ba |
p11_message ("couldn't create object: %s", p11_kit_strerror (rv));
|
|
Packit Service |
3749ba |
return false;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return true;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static bool
|
|
Packit Service |
3749ba |
modify_anchor (CK_FUNCTION_LIST *module,
|
|
Packit Service |
3749ba |
CK_SESSION_HANDLE session,
|
|
Packit Service |
3749ba |
CK_OBJECT_HANDLE object,
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attrs)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_BBOOL truev = CK_TRUE;
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *changes;
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *label;
|
|
Packit Service |
3749ba |
CK_ULONG klass;
|
|
Packit Service |
3749ba |
char *string;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE trusted = { CKA_TRUSTED, &truev, sizeof (truev) };
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
label = p11_attrs_find_valid (attrs, CKA_LABEL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (p11_attrs_find_ulong (attrs, CKA_CLASS, &klass) &&
|
|
Packit Service |
3749ba |
klass == CKO_CERTIFICATE)
|
|
Packit Service |
3749ba |
changes = p11_attrs_build (NULL, &trusted, label, NULL);
|
|
Packit Service |
3749ba |
else
|
|
Packit Service |
3749ba |
changes = p11_attrs_build (NULL, label, NULL);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return_val_if_fail (attrs != NULL, FALSE);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* Don't need the attributes anymore */
|
|
Packit Service |
3749ba |
p11_attrs_free (attrs);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (p11_debugging) {
|
|
Packit Service |
3749ba |
string = p11_attrs_to_string (changes, -1);
|
|
Packit Service |
3749ba |
p11_debug ("setting: %s", string);
|
|
Packit Service |
3749ba |
free (string);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = (module->C_SetAttributeValue) (session, object, changes,
|
|
Packit Service |
3749ba |
p11_attrs_count (changes));
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_attrs_free (changes);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (rv != CKR_OK) {
|
|
Packit Service |
3749ba |
p11_message ("couldn't create object: %s", p11_kit_strerror (rv));
|
|
Packit Service |
3749ba |
return false;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return true;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static CK_OBJECT_HANDLE
|
|
Packit Service |
3749ba |
find_anchor (CK_FUNCTION_LIST *module,
|
|
Packit Service |
3749ba |
CK_SESSION_HANDLE session,
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attrs)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_OBJECT_HANDLE object = 0UL;
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attr;
|
|
Packit Service |
3749ba |
p11_kit_iter *iter;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
attr = p11_attrs_find_valid (attrs, CKA_CLASS);
|
|
Packit Service |
3749ba |
return_val_if_fail (attr != NULL, 0);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
iter = p11_kit_iter_new (NULL, 0);
|
|
Packit Service |
3749ba |
return_val_if_fail (iter != NULL, 0);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (iter_match_anchor (iter, attrs)) {
|
|
Packit Service |
3749ba |
p11_kit_iter_begin_with (iter, module, 0, session);
|
|
Packit Service |
3749ba |
if (p11_kit_iter_next (iter) == CKR_OK)
|
|
Packit Service |
3749ba |
object = p11_kit_iter_get_object (iter);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_free (iter);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return object;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static int
|
|
Packit Service |
3749ba |
anchor_store (int argc,
|
|
Packit Service |
3749ba |
char *argv[],
|
|
Packit Service |
3749ba |
bool *changed,
|
|
Packit Service |
3749ba |
unsigned int *errors)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attrs;
|
|
Packit Service |
3749ba |
CK_FUNCTION_LIST *module = NULL;
|
|
Packit Service |
3749ba |
CK_SESSION_HANDLE session;
|
|
Packit Service |
3749ba |
CK_OBJECT_HANDLE object;
|
|
Packit Service |
3749ba |
p11_array *anchors;
|
|
Packit Service |
3749ba |
int ret;
|
|
Packit Service |
3749ba |
int i;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
anchors = files_to_attrs (argc, argv);
|
|
Packit Service |
3749ba |
if (anchors == NULL)
|
|
Packit Service |
3749ba |
return 1;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (anchors->num == 0) {
|
|
Packit Service |
3749ba |
p11_message ("specify at least one anchor input file");
|
|
Packit Service |
3749ba |
p11_array_free (anchors);
|
|
Packit Service |
3749ba |
return 2;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
session = session_for_store (&module);
|
|
Packit Service |
3749ba |
if (session == 0UL) {
|
|
Packit Service |
3749ba |
p11_array_free (anchors);
|
|
Packit Service |
3749ba |
return 1;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0, ret = 0; i < anchors->num; i++) {
|
|
Packit Service |
3749ba |
attrs = anchors->elem[i];
|
|
Packit Service |
3749ba |
anchors->elem[i] = NULL;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
object = find_anchor (module, session, attrs);
|
|
Packit Service |
3749ba |
if (object == 0) {
|
|
Packit Service |
3749ba |
p11_debug ("don't yet have this anchor");
|
|
Packit Service |
3749ba |
if (create_anchor (module, session, attrs)) {
|
|
Packit Service |
3749ba |
*changed = true;
|
|
Packit Service |
3749ba |
} else {
|
|
Packit Service |
3749ba |
ret = 1;
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
} else {
|
|
Packit Service |
3749ba |
p11_debug ("already have this anchor");
|
|
Packit Service |
3749ba |
if (modify_anchor (module, session, object, attrs)) {
|
|
Packit Service |
3749ba |
*changed = true;
|
|
Packit Service |
3749ba |
} else {
|
|
Packit Service |
3749ba |
ret = 1;
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (ret != 0)
|
|
Packit Service |
3749ba |
*errors = 1;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_array_free (anchors);
|
|
Packit Service |
3749ba |
p11_kit_module_finalize (module);
|
|
Packit Service |
3749ba |
p11_kit_module_release (module);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return ret;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static const char *
|
|
Packit Service |
3749ba |
description_for_object_at_iter (p11_kit_iter *iter)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_OBJECT_CLASS klass;
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE attrs[] = {
|
|
Packit Service |
3749ba |
{ CKA_CLASS, &klass, sizeof (klass) },
|
|
Packit Service |
3749ba |
{ CKA_INVALID },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
const char *desc = "object";
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_load_attributes (iter, attrs, 1);
|
|
Packit Service |
3749ba |
if (rv == CKR_OK)
|
|
Packit Service |
3749ba |
desc = p11_constant_nick (p11_constant_classes, klass);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return desc;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static bool
|
|
Packit Service |
3749ba |
remove_all (p11_kit_iter *iter,
|
|
Packit Service |
3749ba |
bool *changed,
|
|
Packit Service |
3749ba |
unsigned int *errors)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
const char *desc;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
while ((rv = p11_kit_iter_next (iter)) == CKR_OK) {
|
|
Packit Service |
3749ba |
desc = description_for_object_at_iter (iter);
|
|
Packit Service |
3749ba |
p11_debug ("removing %s: %lu", desc, p11_kit_iter_get_object (iter));
|
|
Packit Service |
3749ba |
rv = p11_kit_iter_destroy_object (iter);
|
|
Packit Service |
3749ba |
switch (rv) {
|
|
Packit Service |
3749ba |
case CKR_OK:
|
|
Packit Service |
3749ba |
*changed = true;
|
|
Packit Service |
3749ba |
continue;
|
|
Packit Service |
3749ba |
case CKR_TOKEN_WRITE_PROTECTED:
|
|
Packit Service |
3749ba |
case CKR_SESSION_READ_ONLY:
|
|
Packit Service |
3749ba |
case CKR_ATTRIBUTE_READ_ONLY:
|
|
Packit Service |
3749ba |
p11_message ("couldn't remove read-only %s", desc);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
default:
|
|
Packit Service |
3749ba |
p11_message ("couldn't remove %s: %s", desc,
|
|
Packit Service |
3749ba |
p11_kit_strerror (rv));
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
(*errors)++;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return (rv == CKR_CANCEL) && *errors == 0;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static int
|
|
Packit Service |
3749ba |
anchor_remove (int argc,
|
|
Packit Service |
3749ba |
char *argv[],
|
|
Packit Service |
3749ba |
bool *changed,
|
|
Packit Service |
3749ba |
unsigned int *errors)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_FUNCTION_LIST **modules;
|
|
Packit Service |
3749ba |
p11_array *iters;
|
|
Packit Service |
3749ba |
p11_kit_iter *iter;
|
|
Packit Service |
3749ba |
int ret = 0;
|
|
Packit Service |
3749ba |
int i;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
iters = uris_or_files_to_iters (argc, argv, P11_KIT_ITER_WANT_WRITABLE);
|
|
Packit Service |
3749ba |
return_val_if_fail (iters != NULL, 1);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (iters->num == 0) {
|
|
Packit Service |
3749ba |
p11_message ("at least one file or uri must be specified");
|
|
Packit Service |
3749ba |
p11_array_free (iters);
|
|
Packit Service |
3749ba |
return 2;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
modules = p11_kit_modules_load_and_initialize (P11_KIT_MODULE_TRUSTED);
|
|
Packit Service |
3749ba |
if (modules == NULL)
|
|
Packit Service |
3749ba |
ret = 1;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0; ret == 0 && i < iters->num; i++) {
|
|
Packit Service |
3749ba |
iter = iters->elem[i];
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_iter_begin (iter, modules);
|
|
Packit Service |
3749ba |
if (!remove_all (iter, changed, errors))
|
|
Packit Service |
3749ba |
ret = 1;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_array_free (iters);
|
|
Packit Service |
3749ba |
p11_kit_modules_finalize_and_release (modules);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return ret;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
int
|
|
Packit Service |
3749ba |
p11_trust_anchor (int argc,
|
|
Packit Service |
3749ba |
char **argv)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
bool changed = false;
|
|
Packit Service |
3749ba |
unsigned int errors = 0;
|
|
Packit Service |
3749ba |
int action = 0;
|
|
Packit Service |
3749ba |
int opt;
|
|
Packit Service |
3749ba |
int ret = 0;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
enum {
|
|
Packit Service |
3749ba |
opt_verbose = 'v',
|
|
Packit Service |
3749ba |
opt_quiet = 'q',
|
|
Packit Service |
3749ba |
opt_help = 'h',
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
opt_store = 's',
|
|
Packit Service |
3749ba |
opt_remove = 'r',
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
struct option options[] = {
|
|
Packit Service |
3749ba |
{ "store", no_argument, NULL, opt_store },
|
|
Packit Service |
3749ba |
{ "remove", no_argument, NULL, opt_remove },
|
|
Packit Service |
3749ba |
{ "verbose", no_argument, NULL, opt_verbose },
|
|
Packit Service |
3749ba |
{ "quiet", no_argument, NULL, opt_quiet },
|
|
Packit Service |
3749ba |
{ "help", no_argument, NULL, opt_help },
|
|
Packit Service |
3749ba |
{ 0 },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_tool_desc usages[] = {
|
|
Packit Service |
3749ba |
{ 0, "usage: trust anchor --store <file> ...\n"
|
|
Packit Service |
3749ba |
" trust anchor --remove <file or URI> ..."},
|
|
Packit Service |
3749ba |
{ opt_verbose, "show verbose debug output", },
|
|
Packit Service |
3749ba |
{ opt_quiet, "suppress command output", },
|
|
Packit Service |
3749ba |
{ 0 },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
while ((opt = p11_tool_getopt (argc, argv, options)) != -1) {
|
|
Packit Service |
3749ba |
switch (opt) {
|
|
Packit Service |
3749ba |
case opt_store:
|
|
Packit Service |
3749ba |
case opt_remove:
|
|
Packit Service |
3749ba |
if (action == 0) {
|
|
Packit Service |
3749ba |
action = opt;
|
|
Packit Service |
3749ba |
} else {
|
|
Packit Service |
3749ba |
p11_message ("an action was already specified");
|
|
Packit Service |
3749ba |
return 2;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case opt_verbose:
|
|
Packit Service |
3749ba |
case opt_quiet:
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case opt_help:
|
|
Packit Service |
3749ba |
p11_tool_usage (usages, options);
|
|
Packit Service |
3749ba |
return 0;
|
|
Packit Service |
3749ba |
case '?':
|
|
Packit Service |
3749ba |
p11_tool_usage (usages, options);
|
|
Packit Service |
3749ba |
return 2;
|
|
Packit Service |
3749ba |
default:
|
|
Packit Service |
3749ba |
assert_not_reached ();
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
argc -= optind;
|
|
Packit Service |
3749ba |
argv += optind;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (action == 0)
|
|
Packit Service |
3749ba |
action = opt_store;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* Store is different, and only accepts files */
|
|
Packit Service |
3749ba |
if (action == opt_store)
|
|
Packit Service |
3749ba |
ret = anchor_store (argc, argv, &changed, &errors);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
else if (action == opt_remove)
|
|
Packit Service |
3749ba |
ret = anchor_remove (argc, argv, &changed, &errors);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
else
|
|
Packit Service |
3749ba |
assert_not_reached ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (errors > 0) {
|
|
Packit Service |
3749ba |
if (errors == 1)
|
|
Packit Service |
3749ba |
p11_message ("%u error while processing", errors);
|
|
Packit Service |
3749ba |
else
|
|
Packit Service |
3749ba |
p11_message ("%u errors while processing", errors);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* Extract the compat bundles after modification */
|
|
Packit Service |
3749ba |
if (ret == 0 && changed) {
|
|
Packit Service |
3749ba |
char *args[] = { argv[0], NULL };
|
|
Packit Service |
3749ba |
ret = p11_trust_extract_compat (1, args);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return ret;
|
|
Packit Service |
3749ba |
}
|