|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* Copyright (c) 2013, Red Hat Inc.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Redistribution and use in source and binary forms, with or without
|
|
Packit Service |
3749ba |
* modification, are permitted provided that the following conditions
|
|
Packit Service |
3749ba |
* are met:
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* * Redistributions of source code must retain the above
|
|
Packit Service |
3749ba |
* copyright notice, this list of conditions and the
|
|
Packit Service |
3749ba |
* following disclaimer.
|
|
Packit Service |
3749ba |
* * Redistributions in binary form must reproduce the
|
|
Packit Service |
3749ba |
* above copyright notice, this list of conditions and
|
|
Packit Service |
3749ba |
* the following disclaimer in the documentation and/or
|
|
Packit Service |
3749ba |
* other materials provided with the distribution.
|
|
Packit Service |
3749ba |
* * The names of contributors to this software may not be
|
|
Packit Service |
3749ba |
* used to endorse or promote products derived from this
|
|
Packit Service |
3749ba |
* software without specific prior written permission.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
Packit Service |
3749ba |
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
Packit Service |
3749ba |
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
|
Packit Service |
3749ba |
* FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
|
Packit Service |
3749ba |
* COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
Packit Service |
3749ba |
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
|
|
Packit Service |
3749ba |
* BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
|
|
Packit Service |
3749ba |
* OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
|
|
Packit Service |
3749ba |
* AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
|
|
Packit Service |
3749ba |
* OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
|
|
Packit Service |
3749ba |
* THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
|
|
Packit Service |
3749ba |
* DAMAGE.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Author: Stef Walter <stefw@redhat.com>
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "config.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#define P11_DEBUG_FLAG P11_DEBUG_TOOL
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "attrs.h"
|
|
Packit Service |
3749ba |
#include "debug.h"
|
|
Packit Service |
3749ba |
#include "dump.h"
|
|
Packit Service |
3749ba |
#include "enumerate.h"
|
|
Packit Service |
3749ba |
#include "message.h"
|
|
Packit Service |
3749ba |
#include "persist.h"
|
|
Packit Service |
3749ba |
#include "tool.h"
|
|
Packit Service |
3749ba |
#include "url.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "p11-kit/iter.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include <assert.h>
|
|
Packit Service |
3749ba |
#include <stdlib.h>
|
|
Packit Service |
3749ba |
#include <string.h>
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static char *
|
|
Packit Service |
3749ba |
format_uri (p11_enumerate *ex,
|
|
Packit Service |
3749ba |
int flags)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
CK_ATTRIBUTE *attr;
|
|
Packit Service |
3749ba |
p11_kit_uri *uri;
|
|
Packit Service |
3749ba |
char *string;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
uri = p11_kit_uri_new ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
memcpy (p11_kit_uri_get_token_info (uri),
|
|
Packit Service |
3749ba |
p11_kit_iter_get_token (ex->iter),
|
|
Packit Service |
3749ba |
sizeof (CK_TOKEN_INFO));
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
attr = p11_attrs_find (ex->attrs, CKA_CLASS);
|
|
Packit Service |
3749ba |
if (attr != NULL)
|
|
Packit Service |
3749ba |
p11_kit_uri_set_attribute (uri, attr);
|
|
Packit Service |
3749ba |
attr = p11_attrs_find (ex->attrs, CKA_ID);
|
|
Packit Service |
3749ba |
if (attr != NULL)
|
|
Packit Service |
3749ba |
p11_kit_uri_set_attribute (uri, attr);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (p11_kit_uri_format (uri, flags, &string) != P11_KIT_URI_OK)
|
|
Packit Service |
3749ba |
string = NULL;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_kit_uri_free (uri);
|
|
Packit Service |
3749ba |
return string;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static bool
|
|
Packit Service |
3749ba |
dump_iterate (p11_enumerate *ex)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
p11_persist *persist;
|
|
Packit Service |
3749ba |
char *string;
|
|
Packit Service |
3749ba |
p11_buffer buf;
|
|
Packit Service |
3749ba |
CK_RV rv;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
persist = p11_persist_new ();
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!p11_buffer_init (&buf, 0))
|
|
Packit Service |
3749ba |
return_val_if_reached (false);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
while ((rv = p11_kit_iter_next (ex->iter)) == CKR_OK) {
|
|
Packit Service |
3749ba |
if (!p11_buffer_reset (&buf, 8192))
|
|
Packit Service |
3749ba |
return_val_if_reached (false);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
string = format_uri (ex, P11_KIT_URI_FOR_OBJECT);
|
|
Packit Service |
3749ba |
if (string) {
|
|
Packit Service |
3749ba |
printf ("# %s\n", string);
|
|
Packit Service |
3749ba |
free (string);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!p11_persist_write (persist, ex->attrs, &buf)) {
|
|
Packit Service |
3749ba |
p11_message ("could not dump object");
|
|
Packit Service |
3749ba |
continue;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
fwrite (buf.data, 1, buf.len, stdout);
|
|
Packit Service |
3749ba |
printf ("\n");
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_persist_free (persist);
|
|
Packit Service |
3749ba |
p11_buffer_uninit (&buf;;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return (rv == CKR_CANCEL);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
int
|
|
Packit Service |
3749ba |
p11_trust_dump (int argc,
|
|
Packit Service |
3749ba |
char **argv)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
p11_enumerate ex;
|
|
Packit Service |
3749ba |
int opt = 0;
|
|
Packit Service |
3749ba |
int ret;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
enum {
|
|
Packit Service |
3749ba |
opt_verbose = 'v',
|
|
Packit Service |
3749ba |
opt_quiet = 'q',
|
|
Packit Service |
3749ba |
opt_help = 'h',
|
|
Packit Service |
3749ba |
opt_filter = 1000,
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
struct option options[] = {
|
|
Packit Service |
3749ba |
{ "filter", required_argument, NULL, opt_filter },
|
|
Packit Service |
3749ba |
{ "verbose", no_argument, NULL, opt_verbose },
|
|
Packit Service |
3749ba |
{ "quiet", no_argument, NULL, opt_quiet },
|
|
Packit Service |
3749ba |
{ "help", no_argument, NULL, opt_help },
|
|
Packit Service |
3749ba |
{ 0 },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_tool_desc usages[] = {
|
|
Packit Service |
3749ba |
{ 0, "usage: trust list --filter=<what>" },
|
|
Packit Service |
3749ba |
{ opt_filter,
|
|
Packit Service |
3749ba |
"filter of what to export\n"
|
|
Packit Service |
3749ba |
" pkcs11:object=xx a PKCS#11 URI\n"
|
|
Packit Service |
3749ba |
" all all objects",
|
|
Packit Service |
3749ba |
"what",
|
|
Packit Service |
3749ba |
},
|
|
Packit Service |
3749ba |
{ opt_verbose, "show verbose debug output", },
|
|
Packit Service |
3749ba |
{ opt_quiet, "suppress command output", },
|
|
Packit Service |
3749ba |
{ 0 },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_init (&ex);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
while ((opt = p11_tool_getopt (argc, argv, options)) != -1) {
|
|
Packit Service |
3749ba |
switch (opt) {
|
|
Packit Service |
3749ba |
case opt_verbose:
|
|
Packit Service |
3749ba |
case opt_quiet:
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
case opt_filter:
|
|
Packit Service |
3749ba |
if (!p11_enumerate_opt_filter (&ex, optarg))
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case 'h':
|
|
Packit Service |
3749ba |
p11_tool_usage (usages, options);
|
|
Packit Service |
3749ba |
exit (0);
|
|
Packit Service |
3749ba |
case '?':
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
default:
|
|
Packit Service |
3749ba |
assert_not_reached ();
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (argc - optind != 0) {
|
|
Packit Service |
3749ba |
p11_message ("extra arguments passed to command");
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!p11_enumerate_ready (&ex, "all"))
|
|
Packit Service |
3749ba |
exit (1);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ret = dump_iterate (&ex) ? 0 : 1;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_cleanup (&ex);
|
|
Packit Service |
3749ba |
return ret;
|
|
Packit Service |
3749ba |
}
|