2003-08-05 19:11:04 +02:00
|
|
|
|
/* certdump.c - Dump a certificate for debugging
|
2004-02-13 18:06:50 +01:00
|
|
|
|
* Copyright (C) 2001, 2004 Free Software Foundation, Inc.
|
2003-08-05 19:11:04 +02:00
|
|
|
|
*
|
|
|
|
|
* This file is part of GnuPG.
|
|
|
|
|
*
|
|
|
|
|
* GnuPG is free software; you can redistribute it and/or modify
|
|
|
|
|
* it under the terms of the GNU General Public License as published by
|
|
|
|
|
* the Free Software Foundation; either version 2 of the License, or
|
|
|
|
|
* (at your option) any later version.
|
|
|
|
|
*
|
|
|
|
|
* GnuPG is distributed in the hope that it will be useful,
|
|
|
|
|
* but WITHOUT ANY WARRANTY; without even the implied warranty of
|
|
|
|
|
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
|
|
|
|
|
* GNU General Public License for more details.
|
|
|
|
|
*
|
|
|
|
|
* You should have received a copy of the GNU General Public License
|
|
|
|
|
* along with this program; if not, write to the Free Software
|
2006-06-20 19:21:37 +02:00
|
|
|
|
* Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301,
|
|
|
|
|
* USA.
|
2003-08-05 19:11:04 +02:00
|
|
|
|
*/
|
|
|
|
|
|
|
|
|
|
#include <config.h>
|
|
|
|
|
#include <stdio.h>
|
|
|
|
|
#include <stdlib.h>
|
|
|
|
|
#include <string.h>
|
|
|
|
|
#include <errno.h>
|
|
|
|
|
#include <unistd.h>
|
|
|
|
|
#include <time.h>
|
|
|
|
|
#include <assert.h>
|
2004-03-06 21:11:19 +01:00
|
|
|
|
#ifdef HAVE_LOCALE_H
|
|
|
|
|
#include <locale.h>
|
|
|
|
|
#endif
|
|
|
|
|
#ifdef HAVE_LANGINFO_CODESET
|
|
|
|
|
#include <langinfo.h>
|
|
|
|
|
#endif
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
|
|
#include "gpgsm.h"
|
|
|
|
|
#include <gcrypt.h>
|
|
|
|
|
#include <ksba.h>
|
|
|
|
|
|
|
|
|
|
#include "keydb.h"
|
|
|
|
|
#include "i18n.h"
|
|
|
|
|
|
2006-11-21 12:00:14 +01:00
|
|
|
|
#ifdef HAVE_FOPENCOOKIE
|
|
|
|
|
typedef ssize_t my_funopen_hook_ret_t;
|
|
|
|
|
#else
|
|
|
|
|
typedef int my_funopen_hook_ret_t;
|
|
|
|
|
#endif
|
|
|
|
|
|
|
|
|
|
|
2003-08-05 19:11:04 +02:00
|
|
|
|
struct dn_array_s {
|
|
|
|
|
char *key;
|
|
|
|
|
char *value;
|
2004-01-27 20:10:38 +01:00
|
|
|
|
int multivalued;
|
|
|
|
|
int done;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
/* print the first element of an S-Expression */
|
|
|
|
|
void
|
2005-06-16 10:12:03 +02:00
|
|
|
|
gpgsm_print_serial (FILE *fp, ksba_const_sexp_t sn)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2005-06-16 10:12:03 +02:00
|
|
|
|
const char *p = (const char *)sn;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
unsigned long n;
|
2003-12-17 13:28:24 +01:00
|
|
|
|
char *endp;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
|
|
if (!p)
|
|
|
|
|
fputs (_("none"), fp);
|
|
|
|
|
else if (*p != '(')
|
|
|
|
|
fputs ("[Internal error - not an S-expression]", fp);
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
p++;
|
2003-12-17 13:28:24 +01:00
|
|
|
|
n = strtoul (p, &endp, 10);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
p = endp;
|
|
|
|
|
if (*p!=':')
|
|
|
|
|
fputs ("[Internal Error - invalid S-expression]", fp);
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
for (p++; n; n--, p++)
|
2005-07-20 17:05:05 +02:00
|
|
|
|
fprintf (fp, "%02X", *(const unsigned char*)p);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
2005-04-18 12:44:46 +02:00
|
|
|
|
/* Dump the serial number or any other simple S-expression. */
|
2003-08-05 19:11:04 +02:00
|
|
|
|
void
|
2005-06-16 10:12:03 +02:00
|
|
|
|
gpgsm_dump_serial (ksba_const_sexp_t sn)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2005-06-16 10:12:03 +02:00
|
|
|
|
const char *p = (const char *)sn;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
unsigned long n;
|
2003-12-17 13:28:24 +01:00
|
|
|
|
char *endp;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
|
|
if (!p)
|
|
|
|
|
log_printf ("none");
|
|
|
|
|
else if (*p != '(')
|
|
|
|
|
log_printf ("ERROR - not an S-expression");
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
p++;
|
2003-12-17 13:28:24 +01:00
|
|
|
|
n = strtoul (p, &endp, 10);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
p = endp;
|
|
|
|
|
if (*p!=':')
|
|
|
|
|
log_printf ("ERROR - invalid S-expression");
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
for (p++; n; n--, p++)
|
2005-07-20 17:05:05 +02:00
|
|
|
|
log_printf ("%02X", *(const unsigned char *)p);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
2004-02-13 18:06:50 +01:00
|
|
|
|
|
|
|
|
|
char *
|
2005-06-16 10:12:03 +02:00
|
|
|
|
gpgsm_format_serial (ksba_const_sexp_t sn)
|
2004-02-13 18:06:50 +01:00
|
|
|
|
{
|
2005-06-16 10:12:03 +02:00
|
|
|
|
const char *p = (const char *)sn;
|
2004-02-13 18:06:50 +01:00
|
|
|
|
unsigned long n;
|
|
|
|
|
char *endp;
|
|
|
|
|
char *buffer;
|
|
|
|
|
int i;
|
|
|
|
|
|
|
|
|
|
if (!p)
|
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
|
|
if (*p != '(')
|
|
|
|
|
BUG (); /* Not a valid S-expression. */
|
|
|
|
|
|
|
|
|
|
p++;
|
|
|
|
|
n = strtoul (p, &endp, 10);
|
|
|
|
|
p = endp;
|
|
|
|
|
if (*p!=':')
|
|
|
|
|
BUG (); /* Not a valid S-expression. */
|
|
|
|
|
p++;
|
|
|
|
|
|
|
|
|
|
buffer = xtrymalloc (n*2+1);
|
|
|
|
|
if (buffer)
|
|
|
|
|
{
|
|
|
|
|
for (i=0; n; n--, p++, i+=2)
|
|
|
|
|
sprintf (buffer+i, "%02X", *(unsigned char *)p);
|
|
|
|
|
buffer[i] = 0;
|
|
|
|
|
}
|
|
|
|
|
return buffer;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2003-08-05 19:11:04 +02:00
|
|
|
|
void
|
2003-10-31 13:12:47 +01:00
|
|
|
|
gpgsm_print_time (FILE *fp, ksba_isotime_t t)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2003-10-31 13:12:47 +01:00
|
|
|
|
if (!t || !*t)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
fputs (_("none"), fp);
|
|
|
|
|
else
|
2003-10-31 13:12:47 +01:00
|
|
|
|
fprintf (fp, "%.4s-%.2s-%.2s %.2s:%.2s:%s", t, t+4, t+6, t+9, t+11, t+13);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
void
|
2003-10-31 13:12:47 +01:00
|
|
|
|
gpgsm_dump_time (ksba_isotime_t t)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2003-10-31 13:12:47 +01:00
|
|
|
|
if (!t || !*t)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
log_printf (_("[none]"));
|
|
|
|
|
else
|
2003-10-31 13:12:47 +01:00
|
|
|
|
log_printf ("%.4s-%.2s-%.2s %.2s:%.2s:%s",
|
|
|
|
|
t, t+4, t+6, t+9, t+11, t+13);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
void
|
|
|
|
|
gpgsm_dump_string (const char *string)
|
|
|
|
|
{
|
|
|
|
|
|
|
|
|
|
if (!string)
|
|
|
|
|
log_printf ("[error]");
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
const unsigned char *s;
|
|
|
|
|
|
2005-06-16 10:12:03 +02:00
|
|
|
|
for (s=(const unsigned char*)string; *s; s++)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
|
|
|
|
if (*s < ' ' || (*s >= 0x7f && *s <= 0xa0))
|
|
|
|
|
break;
|
|
|
|
|
}
|
|
|
|
|
if (!*s && *string != '[')
|
|
|
|
|
log_printf ("%s", string);
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
log_printf ( "[ ");
|
|
|
|
|
log_printhex (NULL, string, strlen (string));
|
|
|
|
|
log_printf ( " ]");
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
2004-04-22 15:03:44 +02:00
|
|
|
|
/* This simple dump function is mainly used for debugging purposes. */
|
2003-08-05 19:11:04 +02:00
|
|
|
|
void
|
2003-12-17 13:28:24 +01:00
|
|
|
|
gpgsm_dump_cert (const char *text, ksba_cert_t cert)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2003-12-17 13:28:24 +01:00
|
|
|
|
ksba_sexp_t sexp;
|
2005-06-16 10:12:03 +02:00
|
|
|
|
char *p;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
char *dn;
|
2003-10-31 13:12:47 +01:00
|
|
|
|
ksba_isotime_t t;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
|
|
log_debug ("BEGIN Certificate `%s':\n", text? text:"");
|
|
|
|
|
if (cert)
|
|
|
|
|
{
|
|
|
|
|
sexp = ksba_cert_get_serial (cert);
|
|
|
|
|
log_debug (" serial: ");
|
|
|
|
|
gpgsm_dump_serial (sexp);
|
|
|
|
|
ksba_free (sexp);
|
|
|
|
|
log_printf ("\n");
|
|
|
|
|
|
2003-10-31 13:12:47 +01:00
|
|
|
|
ksba_cert_get_validity (cert, 0, t);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
log_debug (" notBefore: ");
|
|
|
|
|
gpgsm_dump_time (t);
|
|
|
|
|
log_printf ("\n");
|
2003-10-31 13:12:47 +01:00
|
|
|
|
ksba_cert_get_validity (cert, 1, t);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
log_debug (" notAfter: ");
|
|
|
|
|
gpgsm_dump_time (t);
|
|
|
|
|
log_printf ("\n");
|
|
|
|
|
|
|
|
|
|
dn = ksba_cert_get_issuer (cert, 0);
|
|
|
|
|
log_debug (" issuer: ");
|
|
|
|
|
gpgsm_dump_string (dn);
|
|
|
|
|
ksba_free (dn);
|
|
|
|
|
log_printf ("\n");
|
|
|
|
|
|
|
|
|
|
dn = ksba_cert_get_subject (cert, 0);
|
|
|
|
|
log_debug (" subject: ");
|
|
|
|
|
gpgsm_dump_string (dn);
|
|
|
|
|
ksba_free (dn);
|
|
|
|
|
log_printf ("\n");
|
|
|
|
|
|
|
|
|
|
log_debug (" hash algo: %s\n", ksba_cert_get_digest_algo (cert));
|
|
|
|
|
|
|
|
|
|
p = gpgsm_get_fingerprint_string (cert, 0);
|
|
|
|
|
log_debug (" SHA1 Fingerprint: %s\n", p);
|
|
|
|
|
xfree (p);
|
|
|
|
|
}
|
|
|
|
|
log_debug ("END Certificate\n");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
2006-06-27 16:32:34 +02:00
|
|
|
|
/* Log the certificate's name in "#SN/ISSUERDN" format along with
|
|
|
|
|
TEXT. */
|
|
|
|
|
void
|
|
|
|
|
gpgsm_cert_log_name (const char *text, ksba_cert_t cert)
|
|
|
|
|
{
|
|
|
|
|
log_info ("%s", text? text:"certificate" );
|
|
|
|
|
if (cert)
|
|
|
|
|
{
|
|
|
|
|
ksba_sexp_t sn;
|
|
|
|
|
char *p;
|
|
|
|
|
|
|
|
|
|
p = ksba_cert_get_issuer (cert, 0);
|
|
|
|
|
sn = ksba_cert_get_serial (cert);
|
|
|
|
|
if (p && sn)
|
|
|
|
|
{
|
|
|
|
|
log_printf (" #");
|
|
|
|
|
gpgsm_dump_serial (sn);
|
|
|
|
|
log_printf ("/");
|
|
|
|
|
gpgsm_dump_string (p);
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
log_printf (" [invalid]");
|
|
|
|
|
ksba_free (sn);
|
|
|
|
|
xfree (p);
|
|
|
|
|
}
|
|
|
|
|
log_printf ("\n");
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
|
|
/* helper for the rfc2253 string parser */
|
|
|
|
|
static const unsigned char *
|
|
|
|
|
parse_dn_part (struct dn_array_s *array, const unsigned char *string)
|
|
|
|
|
{
|
2004-01-29 08:41:55 +01:00
|
|
|
|
static struct {
|
|
|
|
|
const char *label;
|
|
|
|
|
const char *oid;
|
|
|
|
|
} label_map[] = {
|
|
|
|
|
/* Warning: When adding new labels, make sure that the buffer
|
|
|
|
|
below we be allocated large enough. */
|
|
|
|
|
{"EMail", "1.2.840.113549.1.9.1" },
|
|
|
|
|
{"T", "2.5.4.12" },
|
|
|
|
|
{"GN", "2.5.4.42" },
|
|
|
|
|
{"SN", "2.5.4.4" },
|
|
|
|
|
{"NameDistinguisher", "0.2.262.1.10.7.20"},
|
|
|
|
|
{"ADDR", "2.5.4.16" },
|
|
|
|
|
{"BC", "2.5.4.15" },
|
|
|
|
|
{"D", "2.5.4.13" },
|
|
|
|
|
{"PostalCode", "2.5.4.17" },
|
|
|
|
|
{"Pseudo", "2.5.4.65" },
|
|
|
|
|
{"SerialNumber", "2.5.4.5" },
|
|
|
|
|
{NULL, NULL}
|
|
|
|
|
};
|
2003-08-05 19:11:04 +02:00
|
|
|
|
const unsigned char *s, *s1;
|
|
|
|
|
size_t n;
|
2005-06-16 10:12:03 +02:00
|
|
|
|
char *p;
|
2004-01-29 08:41:55 +01:00
|
|
|
|
int i;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
2004-01-29 08:41:55 +01:00
|
|
|
|
/* Parse attributeType */
|
2003-08-05 19:11:04 +02:00
|
|
|
|
for (s = string+1; *s && *s != '='; s++)
|
|
|
|
|
;
|
|
|
|
|
if (!*s)
|
|
|
|
|
return NULL; /* error */
|
|
|
|
|
n = s - string;
|
|
|
|
|
if (!n)
|
|
|
|
|
return NULL; /* empty key */
|
2004-01-29 08:41:55 +01:00
|
|
|
|
|
|
|
|
|
/* We need to allocate a few bytes more due to the possible mapping
|
|
|
|
|
from the shorter OID to the longer label. */
|
|
|
|
|
array->key = p = xtrymalloc (n+10);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
if (!array->key)
|
|
|
|
|
return NULL;
|
|
|
|
|
memcpy (p, string, n);
|
|
|
|
|
p[n] = 0;
|
|
|
|
|
trim_trailing_spaces (p);
|
2004-01-27 20:10:38 +01:00
|
|
|
|
|
2004-01-29 08:41:55 +01:00
|
|
|
|
if (digitp (p))
|
|
|
|
|
{
|
|
|
|
|
for (i=0; label_map[i].label; i++ )
|
|
|
|
|
if ( !strcmp (p, label_map[i].oid) )
|
|
|
|
|
{
|
|
|
|
|
strcpy (p, label_map[i].label);
|
|
|
|
|
break;
|
|
|
|
|
}
|
|
|
|
|
}
|
2003-08-05 19:11:04 +02:00
|
|
|
|
string = s + 1;
|
|
|
|
|
|
|
|
|
|
if (*string == '#')
|
|
|
|
|
{ /* hexstring */
|
|
|
|
|
string++;
|
|
|
|
|
for (s=string; hexdigitp (s); s++)
|
|
|
|
|
s++;
|
|
|
|
|
n = s - string;
|
|
|
|
|
if (!n || (n & 1))
|
2004-01-29 08:41:55 +01:00
|
|
|
|
return NULL; /* Empty or odd number of digits. */
|
2003-08-05 19:11:04 +02:00
|
|
|
|
n /= 2;
|
|
|
|
|
array->value = p = xtrymalloc (n+1);
|
|
|
|
|
if (!p)
|
|
|
|
|
return NULL;
|
2004-01-29 08:41:55 +01:00
|
|
|
|
for (s1=string; n; s1 += 2, n--, p++)
|
|
|
|
|
{
|
2005-06-16 10:12:03 +02:00
|
|
|
|
*(unsigned char *)p = xtoi_2 (s1);
|
2004-01-29 08:41:55 +01:00
|
|
|
|
if (!*p)
|
|
|
|
|
*p = 0x01; /* Better print a wrong value than truncating
|
|
|
|
|
the string. */
|
|
|
|
|
}
|
2003-08-05 19:11:04 +02:00
|
|
|
|
*p = 0;
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
{ /* regular v3 quoted string */
|
|
|
|
|
for (n=0, s=string; *s; s++)
|
|
|
|
|
{
|
|
|
|
|
if (*s == '\\')
|
|
|
|
|
{ /* pair */
|
|
|
|
|
s++;
|
|
|
|
|
if (*s == ',' || *s == '=' || *s == '+'
|
|
|
|
|
|| *s == '<' || *s == '>' || *s == '#' || *s == ';'
|
|
|
|
|
|| *s == '\\' || *s == '\"' || *s == ' ')
|
|
|
|
|
n++;
|
|
|
|
|
else if (hexdigitp (s) && hexdigitp (s+1))
|
|
|
|
|
{
|
|
|
|
|
s++;
|
|
|
|
|
n++;
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
return NULL; /* invalid escape sequence */
|
|
|
|
|
}
|
|
|
|
|
else if (*s == '\"')
|
|
|
|
|
return NULL; /* invalid encoding */
|
|
|
|
|
else if (*s == ',' || *s == '=' || *s == '+'
|
2006-11-28 17:36:02 +01:00
|
|
|
|
|| *s == '<' || *s == '>' || *s == ';' )
|
2003-08-05 19:11:04 +02:00
|
|
|
|
break;
|
|
|
|
|
else
|
|
|
|
|
n++;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
array->value = p = xtrymalloc (n+1);
|
|
|
|
|
if (!p)
|
|
|
|
|
return NULL;
|
|
|
|
|
for (s=string; n; s++, n--)
|
|
|
|
|
{
|
|
|
|
|
if (*s == '\\')
|
|
|
|
|
{
|
|
|
|
|
s++;
|
|
|
|
|
if (hexdigitp (s))
|
|
|
|
|
{
|
2005-06-16 10:12:03 +02:00
|
|
|
|
*(unsigned char *)p++ = xtoi_2 (s);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
s++;
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
*p++ = *s;
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
*p++ = *s;
|
|
|
|
|
}
|
|
|
|
|
*p = 0;
|
|
|
|
|
}
|
|
|
|
|
return s;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
/* Parse a DN and return an array-ized one. This is not a validating
|
|
|
|
|
parser and it does not support any old-stylish syntax; KSBA is
|
|
|
|
|
expected to return only rfc2253 compatible strings. */
|
|
|
|
|
static struct dn_array_s *
|
|
|
|
|
parse_dn (const unsigned char *string)
|
|
|
|
|
{
|
|
|
|
|
struct dn_array_s *array;
|
|
|
|
|
size_t arrayidx, arraysize;
|
|
|
|
|
int i;
|
|
|
|
|
|
|
|
|
|
arraysize = 7; /* C,ST,L,O,OU,CN,email */
|
|
|
|
|
arrayidx = 0;
|
|
|
|
|
array = xtrymalloc ((arraysize+1) * sizeof *array);
|
|
|
|
|
if (!array)
|
|
|
|
|
return NULL;
|
|
|
|
|
while (*string)
|
|
|
|
|
{
|
|
|
|
|
while (*string == ' ')
|
|
|
|
|
string++;
|
|
|
|
|
if (!*string)
|
|
|
|
|
break; /* ready */
|
|
|
|
|
if (arrayidx >= arraysize)
|
|
|
|
|
{
|
|
|
|
|
struct dn_array_s *a2;
|
|
|
|
|
|
|
|
|
|
arraysize += 5;
|
|
|
|
|
a2 = xtryrealloc (array, (arraysize+1) * sizeof *array);
|
|
|
|
|
if (!a2)
|
|
|
|
|
goto failure;
|
|
|
|
|
array = a2;
|
|
|
|
|
}
|
|
|
|
|
array[arrayidx].key = NULL;
|
|
|
|
|
array[arrayidx].value = NULL;
|
|
|
|
|
string = parse_dn_part (array+arrayidx, string);
|
|
|
|
|
if (!string)
|
|
|
|
|
goto failure;
|
|
|
|
|
while (*string == ' ')
|
|
|
|
|
string++;
|
2004-01-27 20:10:38 +01:00
|
|
|
|
array[arrayidx].multivalued = (*string == '+');
|
|
|
|
|
array[arrayidx].done = 0;
|
|
|
|
|
arrayidx++;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
if (*string && *string != ',' && *string != ';' && *string != '+')
|
|
|
|
|
goto failure; /* invalid delimiter */
|
|
|
|
|
if (*string)
|
|
|
|
|
string++;
|
|
|
|
|
}
|
|
|
|
|
array[arrayidx].key = NULL;
|
|
|
|
|
array[arrayidx].value = NULL;
|
|
|
|
|
return array;
|
|
|
|
|
|
|
|
|
|
failure:
|
|
|
|
|
for (i=0; i < arrayidx; i++)
|
|
|
|
|
{
|
|
|
|
|
xfree (array[i].key);
|
|
|
|
|
xfree (array[i].value);
|
|
|
|
|
}
|
|
|
|
|
xfree (array);
|
|
|
|
|
return NULL;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
static void
|
2004-09-30 23:37:11 +02:00
|
|
|
|
print_dn_part (FILE *fp, struct dn_array_s *dn, const char *key, int translate)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2004-01-27 20:10:38 +01:00
|
|
|
|
struct dn_array_s *first_dn = dn;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
|
|
for (; dn->key; dn++)
|
|
|
|
|
{
|
2004-01-27 20:10:38 +01:00
|
|
|
|
if (!dn->done && !strcmp (dn->key, key))
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2004-01-27 20:10:38 +01:00
|
|
|
|
/* Forward to the last multi-valued RDN, so that we can
|
|
|
|
|
print them all in reverse in the correct order. Note
|
|
|
|
|
that this overrides the the standard sequence but that
|
|
|
|
|
seems to a reasonable thing to do with multi-valued
|
|
|
|
|
RDNs. */
|
|
|
|
|
while (dn->multivalued && dn[1].key)
|
|
|
|
|
dn++;
|
|
|
|
|
next:
|
|
|
|
|
if (!dn->done && dn->value && *dn->value)
|
|
|
|
|
{
|
|
|
|
|
fprintf (fp, "/%s=", dn->key);
|
2004-09-30 23:37:11 +02:00
|
|
|
|
if (translate)
|
|
|
|
|
print_sanitized_utf8_string (fp, dn->value, '/');
|
|
|
|
|
else
|
|
|
|
|
print_sanitized_string (fp, dn->value, '/');
|
2004-01-27 20:10:38 +01:00
|
|
|
|
}
|
|
|
|
|
dn->done = 1;
|
|
|
|
|
if (dn > first_dn && dn[-1].multivalued)
|
|
|
|
|
{
|
|
|
|
|
dn--;
|
|
|
|
|
goto next;
|
|
|
|
|
}
|
2003-08-05 19:11:04 +02:00
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/* Print all parts of a DN in a "standard" sequence. We first print
|
|
|
|
|
all the known parts, followed by the uncommon ones */
|
|
|
|
|
static void
|
2004-09-30 23:37:11 +02:00
|
|
|
|
print_dn_parts (FILE *fp, struct dn_array_s *dn, int translate)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
|
|
|
|
const char *stdpart[] = {
|
|
|
|
|
"CN", "OU", "O", "STREET", "L", "ST", "C", "EMail", NULL
|
|
|
|
|
};
|
|
|
|
|
int i;
|
|
|
|
|
|
|
|
|
|
for (i=0; stdpart[i]; i++)
|
2004-09-30 23:37:11 +02:00
|
|
|
|
print_dn_part (fp, dn, stdpart[i], translate);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
2004-01-27 20:10:38 +01:00
|
|
|
|
/* Now print the rest without any specific ordering */
|
2003-08-05 19:11:04 +02:00
|
|
|
|
for (; dn->key; dn++)
|
2004-09-30 23:37:11 +02:00
|
|
|
|
print_dn_part (fp, dn, dn->key, translate);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
2005-11-13 20:07:06 +01:00
|
|
|
|
/* Print the S-Expression in BUF, which has a valid length of BUFLEN,
|
|
|
|
|
as a human readable string in one line to FP. */
|
|
|
|
|
static void
|
|
|
|
|
pretty_print_sexp (FILE *fp, const unsigned char *buf, size_t buflen)
|
|
|
|
|
{
|
|
|
|
|
size_t len;
|
|
|
|
|
gcry_sexp_t sexp;
|
|
|
|
|
char *result, *p;
|
|
|
|
|
|
|
|
|
|
if ( gcry_sexp_sscan (&sexp, NULL, (const char*)buf, buflen) )
|
|
|
|
|
{
|
|
|
|
|
fputs (_("[Error - invalid encoding]"), fp);
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
len = gcry_sexp_sprint (sexp, GCRYSEXP_FMT_ADVANCED, NULL, 0);
|
|
|
|
|
assert (len);
|
|
|
|
|
result = xtrymalloc (len);
|
|
|
|
|
if (!result)
|
|
|
|
|
{
|
|
|
|
|
fputs (_("[Error - out of core]"), fp);
|
|
|
|
|
gcry_sexp_release (sexp);
|
|
|
|
|
return;
|
|
|
|
|
}
|
|
|
|
|
len = gcry_sexp_sprint (sexp, GCRYSEXP_FMT_ADVANCED, result, len);
|
|
|
|
|
assert (len);
|
|
|
|
|
for (p = result; len; len--, p++)
|
|
|
|
|
{
|
|
|
|
|
if (*p == '\n')
|
|
|
|
|
{
|
|
|
|
|
if (len > 1) /* Avoid printing the trailing LF. */
|
|
|
|
|
fputs ("\\n", fp);
|
|
|
|
|
}
|
|
|
|
|
else if (*p == '\r')
|
|
|
|
|
fputs ("\\r", fp);
|
|
|
|
|
else if (*p == '\v')
|
|
|
|
|
fputs ("\\v", fp);
|
|
|
|
|
else if (*p == '\t')
|
|
|
|
|
fputs ("\\t", fp);
|
|
|
|
|
else
|
|
|
|
|
putc (*p, fp);
|
|
|
|
|
}
|
|
|
|
|
xfree (result);
|
|
|
|
|
gcry_sexp_release (sexp);
|
|
|
|
|
}
|
|
|
|
|
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
|
|
|
|
void
|
2004-09-30 23:37:11 +02:00
|
|
|
|
gpgsm_print_name2 (FILE *fp, const char *name, int translate)
|
2003-08-05 19:11:04 +02:00
|
|
|
|
{
|
2005-06-16 10:12:03 +02:00
|
|
|
|
const unsigned char *s = (const unsigned char *)name;
|
2003-08-05 19:11:04 +02:00
|
|
|
|
int i;
|
|
|
|
|
|
|
|
|
|
if (!s)
|
|
|
|
|
{
|
|
|
|
|
fputs (_("[Error - No name]"), fp);
|
|
|
|
|
}
|
|
|
|
|
else if (*s == '<')
|
|
|
|
|
{
|
2005-06-16 10:12:03 +02:00
|
|
|
|
const char *s2 = strchr ( (char*)s+1, '>');
|
2003-08-05 19:11:04 +02:00
|
|
|
|
if (s2)
|
2004-09-30 23:37:11 +02:00
|
|
|
|
{
|
|
|
|
|
if (translate)
|
2005-06-16 10:12:03 +02:00
|
|
|
|
print_sanitized_utf8_buffer (fp, s + 1, s2 - (char*)s - 1, 0);
|
2004-09-30 23:37:11 +02:00
|
|
|
|
else
|
2005-06-16 10:12:03 +02:00
|
|
|
|
print_sanitized_buffer (fp, s + 1, s2 - (char*)s - 1, 0);
|
2004-09-30 23:37:11 +02:00
|
|
|
|
}
|
2003-08-05 19:11:04 +02:00
|
|
|
|
}
|
|
|
|
|
else if (*s == '(')
|
2005-11-13 20:07:06 +01:00
|
|
|
|
{
|
|
|
|
|
pretty_print_sexp (fp, s, gcry_sexp_canon_len (s, 0, NULL, NULL));
|
|
|
|
|
}
|
2003-08-05 19:11:04 +02:00
|
|
|
|
else if (!((*s >= '0' && *s < '9')
|
|
|
|
|
|| (*s >= 'A' && *s <= 'Z')
|
|
|
|
|
|| (*s >= 'a' && *s <= 'z')))
|
|
|
|
|
fputs (_("[Error - invalid encoding]"), fp);
|
|
|
|
|
else
|
|
|
|
|
{
|
|
|
|
|
struct dn_array_s *dn = parse_dn (s);
|
|
|
|
|
if (!dn)
|
|
|
|
|
fputs (_("[Error - invalid DN]"), fp);
|
|
|
|
|
else
|
|
|
|
|
{
|
2004-09-30 23:37:11 +02:00
|
|
|
|
print_dn_parts (fp, dn, translate);
|
2003-08-05 19:11:04 +02:00
|
|
|
|
for (i=0; dn[i].key; i++)
|
|
|
|
|
{
|
|
|
|
|
xfree (dn[i].key);
|
|
|
|
|
xfree (dn[i].value);
|
|
|
|
|
}
|
|
|
|
|
xfree (dn);
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
2004-09-30 23:37:11 +02:00
|
|
|
|
void
|
|
|
|
|
gpgsm_print_name (FILE *fp, const char *name)
|
|
|
|
|
{
|
|
|
|
|
gpgsm_print_name2 (fp, name, 1);
|
|
|
|
|
}
|
|
|
|
|
|
2003-08-05 19:11:04 +02:00
|
|
|
|
|
2004-02-13 18:06:50 +01:00
|
|
|
|
/* A cookie structure used for the memory stream. */
|
|
|
|
|
struct format_name_cookie
|
|
|
|
|
{
|
|
|
|
|
char *buffer; /* Malloced buffer with the data to deliver. */
|
|
|
|
|
size_t size; /* Allocated size of this buffer. */
|
|
|
|
|
size_t len; /* strlen (buffer). */
|
|
|
|
|
int error; /* system error code if any. */
|
|
|
|
|
};
|
|
|
|
|
|
|
|
|
|
/* The writer function for the memory stream. */
|
2006-11-21 12:00:14 +01:00
|
|
|
|
static my_funopen_hook_ret_t
|
2004-02-13 18:06:50 +01:00
|
|
|
|
format_name_writer (void *cookie, const char *buffer, size_t size)
|
|
|
|
|
{
|
|
|
|
|
struct format_name_cookie *c = cookie;
|
|
|
|
|
char *p;
|
|
|
|
|
|
|
|
|
|
if (c->buffer)
|
|
|
|
|
p = xtryrealloc (c->buffer, c->size + size + 1);
|
|
|
|
|
else
|
|
|
|
|
p = xtrymalloc (size + 1);
|
|
|
|
|
if (!p)
|
|
|
|
|
{
|
|
|
|
|
c->error = errno;
|
|
|
|
|
xfree (c->buffer);
|
|
|
|
|
errno = c->error;
|
|
|
|
|
return -1;
|
|
|
|
|
}
|
|
|
|
|
c->buffer = p;
|
|
|
|
|
memcpy (p + c->len, buffer, size);
|
|
|
|
|
c->len += size;
|
|
|
|
|
p[c->len] = 0; /* Terminate string. */
|
|
|
|
|
|
|
|
|
|
return size;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
/* Format NAME which is expected to be in rfc2253 format into a better
|
|
|
|
|
human readable format. Caller must free the returned string. NULL
|
2004-09-30 23:37:11 +02:00
|
|
|
|
is returned in case of an error. With TRANSLATE set to true the
|
2005-11-13 20:07:06 +01:00
|
|
|
|
name will be translated to the native encoding. Note that NAME is
|
2004-09-30 23:37:11 +02:00
|
|
|
|
internally always UTF-8 encoded. */
|
2004-02-13 18:06:50 +01:00
|
|
|
|
char *
|
2004-09-30 23:37:11 +02:00
|
|
|
|
gpgsm_format_name2 (const char *name, int translate)
|
2004-02-13 18:06:50 +01:00
|
|
|
|
{
|
2004-02-18 18:00:21 +01:00
|
|
|
|
#if defined (HAVE_FOPENCOOKIE) || defined (HAVE_FUNOPEN)
|
2004-02-13 18:06:50 +01:00
|
|
|
|
FILE *fp;
|
|
|
|
|
struct format_name_cookie cookie;
|
|
|
|
|
|
|
|
|
|
memset (&cookie, 0, sizeof cookie);
|
|
|
|
|
|
|
|
|
|
#ifdef HAVE_FOPENCOOKIE
|
|
|
|
|
{
|
|
|
|
|
cookie_io_functions_t io = { NULL };
|
|
|
|
|
io.write = format_name_writer;
|
|
|
|
|
|
|
|
|
|
fp = fopencookie (&cookie, "w", io);
|
|
|
|
|
}
|
|
|
|
|
#else /*!HAVE_FOPENCOOKIE*/
|
|
|
|
|
{
|
|
|
|
|
fp = funopen (&cookie, NULL, format_name_writer, NULL, NULL);
|
|
|
|
|
}
|
|
|
|
|
#endif /*!HAVE_FOPENCOOKIE*/
|
|
|
|
|
if (!fp)
|
|
|
|
|
{
|
|
|
|
|
int save_errno = errno;
|
|
|
|
|
log_error ("error creating memory stream: %s\n", strerror (errno));
|
|
|
|
|
errno = save_errno;
|
|
|
|
|
return NULL;
|
|
|
|
|
}
|
2004-09-30 23:37:11 +02:00
|
|
|
|
gpgsm_print_name2 (fp, name, translate);
|
2004-02-13 18:06:50 +01:00
|
|
|
|
fclose (fp);
|
|
|
|
|
if (cookie.error || !cookie.buffer)
|
|
|
|
|
{
|
|
|
|
|
xfree (cookie.buffer);
|
|
|
|
|
errno = cookie.error;
|
|
|
|
|
return NULL;
|
|
|
|
|
}
|
|
|
|
|
return cookie.buffer;
|
|
|
|
|
#else /* No fun - use the name verbatim. */
|
|
|
|
|
return xtrystrdup (name);
|
|
|
|
|
#endif /* No fun. */
|
|
|
|
|
}
|
|
|
|
|
|
2004-09-30 23:37:11 +02:00
|
|
|
|
char *
|
|
|
|
|
gpgsm_format_name (const char *name)
|
|
|
|
|
{
|
|
|
|
|
return gpgsm_format_name2 (name, 1);
|
|
|
|
|
}
|
|
|
|
|
|
2004-02-13 18:06:50 +01:00
|
|
|
|
|
2006-11-14 11:23:21 +01:00
|
|
|
|
/* Return fingerprint and a percent escaped name in a human readable
|
|
|
|
|
format suitable for status messages like GOODSIG. May return NULL
|
|
|
|
|
on error (out of core). */
|
|
|
|
|
char *
|
|
|
|
|
gpgsm_fpr_and_name_for_status (ksba_cert_t cert)
|
|
|
|
|
{
|
|
|
|
|
char *fpr, *name, *p;
|
|
|
|
|
char *buffer;
|
|
|
|
|
|
|
|
|
|
fpr = gpgsm_get_fingerprint_hexstring (cert, GCRY_MD_SHA1);
|
|
|
|
|
if (!fpr)
|
|
|
|
|
return NULL;
|
|
|
|
|
|
|
|
|
|
name = ksba_cert_get_subject (cert, 0);
|
|
|
|
|
if (!name)
|
|
|
|
|
{
|
|
|
|
|
xfree (fpr);
|
|
|
|
|
return NULL;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
p = gpgsm_format_name2 (name, 0);
|
|
|
|
|
ksba_free (name);
|
|
|
|
|
name = p;
|
|
|
|
|
if (!name)
|
|
|
|
|
{
|
|
|
|
|
xfree (fpr);
|
|
|
|
|
return NULL;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
buffer = xtrymalloc (strlen (fpr) + 1 + 3*strlen (name) + 1);
|
|
|
|
|
if (buffer)
|
|
|
|
|
{
|
|
|
|
|
const unsigned char *s;
|
|
|
|
|
|
|
|
|
|
p = stpcpy (stpcpy (buffer, fpr), " ");
|
|
|
|
|
for (s = name; *s; s++)
|
|
|
|
|
{
|
|
|
|
|
if (*s < ' ')
|
|
|
|
|
{
|
|
|
|
|
sprintf (p, "%%%02X", *s);
|
|
|
|
|
p += 3;
|
|
|
|
|
}
|
|
|
|
|
else
|
|
|
|
|
*p++ = *s;
|
|
|
|
|
}
|
|
|
|
|
*p = 0;
|
|
|
|
|
}
|
|
|
|
|
xfree (fpr);
|
|
|
|
|
xfree (name);
|
|
|
|
|
return buffer;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
|
2004-02-13 18:06:50 +01:00
|
|
|
|
/* Create a key description for the CERT, this may be passed to the
|
|
|
|
|
pinentry. The caller must free the returned string. NULL may be
|
|
|
|
|
returned on error. */
|
|
|
|
|
char *
|
|
|
|
|
gpgsm_format_keydesc (ksba_cert_t cert)
|
|
|
|
|
{
|
2004-03-06 21:11:19 +01:00
|
|
|
|
int rc;
|
2004-02-13 18:06:50 +01:00
|
|
|
|
char *name, *subject, *buffer, *p;
|
|
|
|
|
const char *s;
|
|
|
|
|
ksba_isotime_t t;
|
|
|
|
|
char created[20];
|
|
|
|
|
char *sn;
|
|
|
|
|
ksba_sexp_t sexp;
|
2004-03-06 21:11:19 +01:00
|
|
|
|
char *orig_codeset = NULL;
|
2004-02-13 18:06:50 +01:00
|
|
|
|
|
|
|
|
|
name = ksba_cert_get_subject (cert, 0);
|
2004-09-30 23:37:11 +02:00
|
|
|
|
subject = name? gpgsm_format_name2 (name, 0) : NULL;
|
2004-02-13 18:06:50 +01:00
|
|
|
|
ksba_free (name); name = NULL;
|
|
|
|
|
|
|
|
|
|
sexp = ksba_cert_get_serial (cert);
|
|
|
|
|
sn = sexp? gpgsm_format_serial (sexp) : NULL;
|
|
|
|
|
ksba_free (sexp);
|
|
|
|
|
|
|
|
|
|
ksba_cert_get_validity (cert, 0, t);
|
|
|
|
|
if (t && *t)
|
|
|
|
|
sprintf (created, "%.4s-%.2s-%.2s", t, t+4, t+6);
|
|
|
|
|
else
|
|
|
|
|
*created = 0;
|
|
|
|
|
|
2004-03-06 21:11:19 +01:00
|
|
|
|
|
|
|
|
|
#ifdef ENABLE_NLS
|
2005-11-13 20:07:06 +01:00
|
|
|
|
/* The Assuan agent protocol requires us to transmit utf-8 strings */
|
2004-04-06 12:01:04 +02:00
|
|
|
|
orig_codeset = bind_textdomain_codeset (PACKAGE_GT, NULL);
|
2004-03-06 21:11:19 +01:00
|
|
|
|
#ifdef HAVE_LANGINFO_CODESET
|
|
|
|
|
if (!orig_codeset)
|
|
|
|
|
orig_codeset = nl_langinfo (CODESET);
|
|
|
|
|
#endif
|
|
|
|
|
if (orig_codeset)
|
2004-09-30 09:54:12 +02:00
|
|
|
|
{ /* We only switch when we are able to restore the codeset later.
|
|
|
|
|
Note that bind_textdomain_codeset does only return on memory
|
|
|
|
|
errors but not if a codeset is not available. Thus we don't
|
|
|
|
|
bother printing a diagnostic here. */
|
2004-03-06 21:11:19 +01:00
|
|
|
|
orig_codeset = xstrdup (orig_codeset);
|
2004-04-06 12:01:04 +02:00
|
|
|
|
if (!bind_textdomain_codeset (PACKAGE_GT, "utf-8"))
|
2004-03-06 21:11:19 +01:00
|
|
|
|
orig_codeset = NULL;
|
|
|
|
|
}
|
|
|
|
|
#endif
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
rc = asprintf (&name,
|
2004-02-13 18:06:50 +01:00
|
|
|
|
_("Please enter the passphrase to unlock the"
|
|
|
|
|
" secret key for:\n"
|
|
|
|
|
"\"%s\"\n"
|
|
|
|
|
"S/N %s, ID %08lX, created %s" ),
|
|
|
|
|
subject? subject:"?",
|
|
|
|
|
sn? sn: "?",
|
|
|
|
|
gpgsm_get_short_fingerprint (cert),
|
2004-03-06 21:11:19 +01:00
|
|
|
|
created);
|
|
|
|
|
|
|
|
|
|
#ifdef ENABLE_NLS
|
|
|
|
|
if (orig_codeset)
|
2004-04-06 12:01:04 +02:00
|
|
|
|
bind_textdomain_codeset (PACKAGE_GT, orig_codeset);
|
2004-03-06 21:11:19 +01:00
|
|
|
|
#endif
|
|
|
|
|
xfree (orig_codeset);
|
|
|
|
|
|
|
|
|
|
if (rc < 0)
|
2004-02-13 18:06:50 +01:00
|
|
|
|
{
|
|
|
|
|
int save_errno = errno;
|
|
|
|
|
xfree (subject);
|
|
|
|
|
xfree (sn);
|
|
|
|
|
errno = save_errno;
|
|
|
|
|
return NULL;
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
xfree (subject);
|
|
|
|
|
xfree (sn);
|
|
|
|
|
|
|
|
|
|
buffer = p = xtrymalloc (strlen (name) * 3 + 1);
|
|
|
|
|
for (s=name; *s; s++)
|
|
|
|
|
{
|
|
|
|
|
if (*s < ' ' || *s == '+')
|
|
|
|
|
{
|
|
|
|
|
sprintf (p, "%%%02X", *(unsigned char *)s);
|
|
|
|
|
p += 3;
|
|
|
|
|
}
|
|
|
|
|
else if (*s == ' ')
|
|
|
|
|
*p++ = '+';
|
|
|
|
|
else
|
|
|
|
|
*p++ = *s;
|
|
|
|
|
}
|
|
|
|
|
*p = 0;
|
|
|
|
|
free (name);
|
|
|
|
|
|
|
|
|
|
return buffer;
|
|
|
|
|
}
|
2006-11-14 11:23:21 +01:00
|
|
|
|
|