|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* Copyright (c) 2013, Red Hat Inc.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Redistribution and use in source and binary forms, with or without
|
|
Packit Service |
3749ba |
* modification, are permitted provided that the following conditions
|
|
Packit Service |
3749ba |
* are met:
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* * Redistributions of source code must retain the above
|
|
Packit Service |
3749ba |
* copyright notice, this list of conditions and the
|
|
Packit Service |
3749ba |
* following disclaimer.
|
|
Packit Service |
3749ba |
* * Redistributions in binary form must reproduce the
|
|
Packit Service |
3749ba |
* above copyright notice, this list of conditions and
|
|
Packit Service |
3749ba |
* the following disclaimer in the documentation and/or
|
|
Packit Service |
3749ba |
* other materials provided with the distribution.
|
|
Packit Service |
3749ba |
* * The names of contributors to this software may not be
|
|
Packit Service |
3749ba |
* used to endorse or promote products derived from this
|
|
Packit Service |
3749ba |
* software without specific prior written permission.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS
|
|
Packit Service |
3749ba |
* "AS IS" AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT
|
|
Packit Service |
3749ba |
* LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS
|
|
Packit Service |
3749ba |
* FOR A PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE
|
|
Packit Service |
3749ba |
* COPYRIGHT OWNER OR CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT,
|
|
Packit Service |
3749ba |
* INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING,
|
|
Packit Service |
3749ba |
* BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS
|
|
Packit Service |
3749ba |
* OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
|
|
Packit Service |
3749ba |
* AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
|
|
Packit Service |
3749ba |
* OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF
|
|
Packit Service |
3749ba |
* THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH
|
|
Packit Service |
3749ba |
* DAMAGE.
|
|
Packit Service |
3749ba |
*
|
|
Packit Service |
3749ba |
* Author: Stef Walter <stefw@redhat.com>
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "config.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "attrs.h"
|
|
Packit Service |
3749ba |
#include "compat.h"
|
|
Packit Service |
3749ba |
#include "debug.h"
|
|
Packit Service |
3749ba |
#include "extract.h"
|
|
Packit Service |
3749ba |
#include "message.h"
|
|
Packit Service |
3749ba |
#include "oid.h"
|
|
Packit Service |
3749ba |
#include "path.h"
|
|
Packit Service |
3749ba |
#include "pkcs11x.h"
|
|
Packit Service |
3749ba |
#include "save.h"
|
|
Packit Service |
3749ba |
#include "tool.h"
|
|
Packit Service |
3749ba |
#include "digest.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include "p11-kit/iter.h"
|
|
Packit Service |
3749ba |
#include "p11-kit/pkcs11.h"
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
#include <assert.h>
|
|
Packit Service |
3749ba |
#include <ctype.h>
|
|
Packit Service |
3749ba |
#include <errno.h>
|
|
Packit Service |
3749ba |
#include <getopt.h>
|
|
Packit Service |
3749ba |
#include <stdint.h>
|
|
Packit Service |
3749ba |
#include <stdio.h>
|
|
Packit Service |
3749ba |
#include <stdlib.h>
|
|
Packit Service |
3749ba |
#include <string.h>
|
|
Packit Service |
3749ba |
#include <unistd.h>
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static bool
|
|
Packit Service |
3749ba |
format_argument (const char *optarg,
|
|
Packit Service |
3749ba |
p11_extract_func *func)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
int i;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* Certain formats do not support expressive trust information.
|
|
Packit Service |
3749ba |
* So the caller should limit the supported purposes when asking
|
|
Packit Service |
3749ba |
* for trust information.
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static const struct {
|
|
Packit Service |
3749ba |
const char *format;
|
|
Packit Service |
3749ba |
p11_extract_func func;
|
|
Packit Service |
3749ba |
} formats[] = {
|
|
Packit Service |
3749ba |
{ "x509-file", p11_extract_x509_file, },
|
|
Packit Service |
3749ba |
{ "x509-directory", p11_extract_x509_directory, },
|
|
Packit Service |
3749ba |
{ "pem-bundle", p11_extract_pem_bundle, },
|
|
Packit Service |
3749ba |
{ "pem-directory", p11_extract_pem_directory },
|
|
Packit Service |
3749ba |
{ "pem-directory-hash", p11_extract_pem_directory_hash },
|
|
Packit Service |
3749ba |
{ "java-cacerts", p11_extract_jks_cacerts },
|
|
Packit Service |
3749ba |
{ "edk2-cacerts", p11_extract_edk2_cacerts },
|
|
Packit Service |
3749ba |
{ "openssl-bundle", p11_extract_openssl_bundle },
|
|
Packit Service |
3749ba |
{ "openssl-directory", p11_extract_openssl_directory },
|
|
Packit Service |
3749ba |
{ NULL },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (*func != NULL) {
|
|
Packit Service |
3749ba |
p11_message ("a format was already specified");
|
|
Packit Service |
3749ba |
return false;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0; formats[i].format != NULL; i++) {
|
|
Packit Service |
3749ba |
if (strcmp (optarg, formats[i].format) == 0) {
|
|
Packit Service |
3749ba |
*func = formats[i].func;
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (*func == NULL) {
|
|
Packit Service |
3749ba |
p11_message ("unsupported or unrecognized format: %s", optarg);
|
|
Packit Service |
3749ba |
return false;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return true;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static bool
|
|
Packit Service |
3749ba |
validate_filter_and_format (p11_enumerate *ex,
|
|
Packit Service |
3749ba |
p11_extract_func func)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
int i;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* These are the extract functions that contain purpose information.
|
|
Packit Service |
3749ba |
* If we're being asked to export anchors, and the extract function does
|
|
Packit Service |
3749ba |
* not support, and the caller has not specified a purpose, then add a
|
|
Packit Service |
3749ba |
* default purpose to limit to.
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
static p11_extract_func supports_trust_policy[] = {
|
|
Packit Service |
3749ba |
p11_extract_openssl_bundle,
|
|
Packit Service |
3749ba |
p11_extract_openssl_directory,
|
|
Packit Service |
3749ba |
NULL
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
for (i = 0; supports_trust_policy[i] != NULL; i++) {
|
|
Packit Service |
3749ba |
if (func == supports_trust_policy[i])
|
|
Packit Service |
3749ba |
return true;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if ((ex->flags & P11_ENUMERATE_ANCHORS) &&
|
|
Packit Service |
3749ba |
(ex->flags & P11_ENUMERATE_BLACKLIST)) {
|
|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* If we're extracting *both* anchors and blacklist, then we must have
|
|
Packit Service |
3749ba |
* a format that can represent the different types of information.
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_message ("format does not support trust policy");
|
|
Packit Service |
3749ba |
return false;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
} else if (ex->flags & P11_ENUMERATE_ANCHORS) {
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* If we're extracting anchors, then we must have either limited the
|
|
Packit Service |
3749ba |
* purposes, or have a format that can represent multiple purposes.
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!ex->limit_to_purposes) {
|
|
Packit Service |
3749ba |
p11_message ("format requires a purpose, specify it with --purpose; defaulting to 'server-auth'");
|
|
Packit Service |
3749ba |
p11_enumerate_opt_purpose (ex, "server-auth");
|
|
Packit Service |
3749ba |
} else if (p11_dict_size (ex->limit_to_purposes) > 1) {
|
|
Packit Service |
3749ba |
p11_message ("format does not support multiple purposes, defaulting to 'server-auth'");
|
|
Packit Service |
3749ba |
p11_enumerate_opt_purpose (ex, "server-auth");
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
return true;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
int
|
|
Packit Service |
3749ba |
p11_trust_extract (int argc,
|
|
Packit Service |
3749ba |
char **argv)
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
p11_extract_func format = NULL;
|
|
Packit Service |
3749ba |
p11_enumerate ex;
|
|
Packit Service |
3749ba |
int opt = 0;
|
|
Packit Service |
3749ba |
int ret;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
enum {
|
|
Packit Service |
3749ba |
opt_overwrite = 'f',
|
|
Packit Service |
3749ba |
opt_verbose = 'v',
|
|
Packit Service |
3749ba |
opt_quiet = 'q',
|
|
Packit Service |
3749ba |
opt_help = 'h',
|
|
Packit Service |
3749ba |
opt_filter = 1000,
|
|
Packit Service |
3749ba |
opt_purpose,
|
|
Packit Service |
3749ba |
opt_format,
|
|
Packit Service |
3749ba |
opt_comment,
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
struct option options[] = {
|
|
Packit Service |
3749ba |
{ "filter", required_argument, NULL, opt_filter },
|
|
Packit Service |
3749ba |
{ "format", required_argument, NULL, opt_format },
|
|
Packit Service |
3749ba |
{ "purpose", required_argument, NULL, opt_purpose },
|
|
Packit Service |
3749ba |
{ "overwrite", no_argument, NULL, opt_overwrite },
|
|
Packit Service |
3749ba |
{ "comment", no_argument, NULL, opt_comment },
|
|
Packit Service |
3749ba |
{ "verbose", no_argument, NULL, opt_verbose },
|
|
Packit Service |
3749ba |
{ "quiet", no_argument, NULL, opt_quiet },
|
|
Packit Service |
3749ba |
{ "help", no_argument, NULL, opt_help },
|
|
Packit Service |
3749ba |
{ 0 },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_tool_desc usages[] = {
|
|
Packit Service |
3749ba |
{ 0, "usage: trust extract --format=<output> <destination>" },
|
|
Packit Service |
3749ba |
{ opt_filter,
|
|
Packit Service |
3749ba |
"filter of what to export\n"
|
|
Packit Service |
3749ba |
" ca-anchors certificate anchors\n"
|
|
Packit Service |
3749ba |
" blacklist blacklisted certificates\n"
|
|
Packit Service |
3749ba |
" trust-policy anchors and blacklist\n"
|
|
Packit Service |
3749ba |
" certificates all certificates\n"
|
|
Packit Service |
3749ba |
" pkcs11:object=xx a PKCS#11 URI",
|
|
Packit Service |
3749ba |
"what",
|
|
Packit Service |
3749ba |
},
|
|
Packit Service |
3749ba |
{ opt_format,
|
|
Packit Service |
3749ba |
"format to extract to\n"
|
|
Packit Service |
3749ba |
" x509-file DER X.509 certificate file\n"
|
|
Packit Service |
3749ba |
" x509-directory directory of X.509 certificates\n"
|
|
Packit Service |
3749ba |
" pem-bundle file containing multiple PEM blocks\n"
|
|
Packit Service |
3749ba |
" pem-directory directory of PEM files\n"
|
|
Packit Service |
3749ba |
" pem-directory-hash directory of PEM files with hash links\n"
|
|
Packit Service |
3749ba |
" openssl-bundle OpenSSL specific PEM bundle\n"
|
|
Packit Service |
3749ba |
" openssl-directory directory of OpenSSL specific files\n"
|
|
Packit Service |
3749ba |
" java-cacerts java keystore cacerts file\n"
|
|
Packit Service |
3749ba |
" edk2-cacerts cacerts file for EDK2 HTTPS config",
|
|
Packit Service |
3749ba |
"type"
|
|
Packit Service |
3749ba |
},
|
|
Packit Service |
3749ba |
{ opt_purpose,
|
|
Packit Service |
3749ba |
"limit to certificates usable for the purpose\n"
|
|
Packit Service |
3749ba |
" server-auth for authenticating servers\n"
|
|
Packit Service |
3749ba |
" client-auth for authenticating clients\n"
|
|
Packit Service |
3749ba |
" email for email protection\n"
|
|
Packit Service |
3749ba |
" code-signing for authenticating signed code\n"
|
|
Packit Service |
3749ba |
" 1.2.3.4.5... an arbitrary object id",
|
|
Packit Service |
3749ba |
"usage"
|
|
Packit Service |
3749ba |
},
|
|
Packit Service |
3749ba |
{ opt_overwrite, "overwrite output file or directory" },
|
|
Packit Service |
3749ba |
{ opt_comment, "add comments to bundles if possible" },
|
|
Packit Service |
3749ba |
{ opt_verbose, "show verbose debug output", },
|
|
Packit Service |
3749ba |
{ opt_quiet, "suppress command output", },
|
|
Packit Service |
3749ba |
{ 0 },
|
|
Packit Service |
3749ba |
};
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_init (&ex);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
while ((opt = p11_tool_getopt (argc, argv, options)) != -1) {
|
|
Packit Service |
3749ba |
switch (opt) {
|
|
Packit Service |
3749ba |
case opt_verbose:
|
|
Packit Service |
3749ba |
case opt_quiet:
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
case opt_overwrite:
|
|
Packit Service |
3749ba |
ex.flags |= P11_SAVE_OVERWRITE;
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case opt_comment:
|
|
Packit Service |
3749ba |
ex.flags |= P11_EXTRACT_COMMENT;
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case opt_filter:
|
|
Packit Service |
3749ba |
if (!p11_enumerate_opt_filter (&ex, optarg))
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case opt_purpose:
|
|
Packit Service |
3749ba |
if (!p11_enumerate_opt_purpose (&ex, optarg))
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case opt_format:
|
|
Packit Service |
3749ba |
if (!format_argument (optarg, &format))
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
case 'h':
|
|
Packit Service |
3749ba |
p11_tool_usage (usages, options);
|
|
Packit Service |
3749ba |
exit (0);
|
|
Packit Service |
3749ba |
case '?':
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
default:
|
|
Packit Service |
3749ba |
assert_not_reached ();
|
|
Packit Service |
3749ba |
break;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
argc -= optind;
|
|
Packit Service |
3749ba |
argv += optind;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (argc != 1) {
|
|
Packit Service |
3749ba |
p11_message ("specify one destination file or directory");
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!format) {
|
|
Packit Service |
3749ba |
p11_message ("no output format specified");
|
|
Packit Service |
3749ba |
exit (2);
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!validate_filter_and_format (&ex, format))
|
|
Packit Service |
3749ba |
exit (1);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (!p11_enumerate_ready (&ex, "ca-anchors"))
|
|
Packit Service |
3749ba |
exit (1);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
ex.flags |= P11_ENUMERATE_CORRELATE;
|
|
Packit Service |
3749ba |
ret = (format) (&ex, argv[0]) ? 0 : 1;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
p11_enumerate_cleanup (&ex);
|
|
Packit Service |
3749ba |
return ret;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
int
|
|
Packit Service |
3749ba |
p11_trust_extract_compat (int argc,
|
|
Packit Service |
3749ba |
char *argv[])
|
|
Packit Service |
3749ba |
{
|
|
Packit Service |
3749ba |
char *path = NULL;
|
|
Packit Service |
3749ba |
int error;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
argv[argc] = NULL;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/*
|
|
Packit Service |
3749ba |
* For compatibility with people who deployed p11-kit 0.18.x
|
|
Packit Service |
3749ba |
* before trust stuff was put into its own branch.
|
|
Packit Service |
3749ba |
*/
|
|
Packit Service |
3749ba |
path = p11_path_build (PRIVATEDIR, "p11-kit-extract-trust", NULL);
|
|
Packit Service |
3749ba |
return_val_if_fail (path != NULL, 1);
|
|
Packit Service |
3749ba |
execv (path, argv);
|
|
Packit Service |
3749ba |
error = errno;
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
if (error == ENOENT) {
|
|
Packit Service |
3749ba |
free (path);
|
|
Packit Service |
3749ba |
path = p11_path_build (PRIVATEDIR, "trust-extract-compat", NULL);
|
|
Packit Service |
3749ba |
return_val_if_fail (path != NULL, 1);
|
|
Packit Service |
3749ba |
execv (path, argv);
|
|
Packit Service |
3749ba |
error = errno;
|
|
Packit Service |
3749ba |
}
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
/* At this point we have no command */
|
|
Packit Service |
3749ba |
p11_message_err (error, "could not run %s command", path);
|
|
Packit Service |
3749ba |
|
|
Packit Service |
3749ba |
free (path);
|
|
Packit Service |
3749ba |
return 2;
|
|
Packit Service |
3749ba |
}
|