gpgsm.c 4.1 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152
  1. /* gpgsm.c - Talking to gpgsm.
  2. Copyright (C) 2006, 2008 g10 Code GmbH
  3. This file is part of Scute.
  4. Scute is free software; you can redistribute it and/or modify it
  5. under the terms of the GNU General Public License as published by
  6. the Free Software Foundation; either version 2 of the License, or
  7. (at your option) any later version.
  8. Scute is distributed in the hope that it will be useful, but
  9. WITHOUT ANY WARRANTY; without even the implied warranty of
  10. MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
  11. General Public License for more details.
  12. You should have received a copy of the GNU General Public License
  13. along with Scute; if not, write to the Free Software Foundation,
  14. Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301 USA
  15. In addition, as a special exception, g10 Code GmbH gives permission
  16. to link this library: with the Mozilla Foundation's code for
  17. Mozilla (or with modified versions of it that use the same license
  18. as the "Mozilla" code), and distribute the linked executables. You
  19. must obey the GNU General Public License in all respects for all of
  20. the code used other than "Mozilla". If you modify this file, you
  21. may extend this exception to your version of the file, but you are
  22. not obligated to do so. If you do not wish to do so, delete this
  23. exception statement from your version. */
  24. #if HAVE_CONFIG_H
  25. #include <config.h>
  26. #endif
  27. #include <assert.h>
  28. #include <locale.h>
  29. #include <errno.h>
  30. #include <string.h>
  31. #include <stdbool.h>
  32. #include <time.h>
  33. #include <assuan.h>
  34. #include <gpg-error.h>
  35. #include "cryptoki.h"
  36. #include "support.h"
  37. #include "cert.h"
  38. #include "agent.h"
  39. #include "gpgsm.h"
  40. #include "debug.h"
  41. struct search
  42. {
  43. bool found;
  44. cert_get_cb_t cert_get_cb;
  45. void *hook;
  46. bool with_chain;
  47. };
  48. static gpg_error_t
  49. search_cb (void *hook, struct cert *cert)
  50. {
  51. struct search *ctx = hook;
  52. gpg_error_t err = 0;
  53. CK_ATTRIBUTE_PTR attrp;
  54. CK_ULONG attr_countp;
  55. /* Add the private key object only once. */
  56. if (!ctx->found)
  57. {
  58. err = scute_attr_prv (cert, &attrp, &attr_countp);
  59. if (err)
  60. return err;
  61. err = (*ctx->cert_get_cb) (ctx->hook, attrp, attr_countp);
  62. if (err)
  63. {
  64. scute_attr_free (attrp, attr_countp);
  65. return err;
  66. }
  67. ctx->found = true;
  68. }
  69. /* Add the certificate chain recursively before adding the
  70. certificate. But ignore errors. If the chain is incomplete, we
  71. might still be able to proceed, for example with client
  72. authentication. */
  73. if (ctx->with_chain && strcmp (cert->chain_id, cert->fpr))
  74. err = scute_gpgsm_search_certs_by_fpr (cert->chain_id, search_cb, ctx);
  75. /* Turn this certificate into a certificate object. */
  76. err = scute_attr_cert (cert, &attrp, &attr_countp);
  77. if (err)
  78. return err;
  79. err = (*ctx->cert_get_cb) (ctx->hook, attrp, attr_countp);
  80. if (err)
  81. {
  82. scute_attr_free (attrp, attr_countp);
  83. return err;
  84. }
  85. return err;
  86. }
  87. /* Create the attributes required for a new certificate object.
  88. Returns allocated attributes for the certificate object in ATTRP
  89. and ATTR_COUNTP, and for the private key object in PRV_ATTRP
  90. and PRV_ATTR_COUNTP. */
  91. gpg_error_t
  92. scute_gpgsm_get_cert (char *grip, int no, cert_get_cb_t cert_get_cb, void *hook)
  93. {
  94. gpg_error_t err;
  95. struct search search;
  96. search.found = false;
  97. search.cert_get_cb = cert_get_cb;
  98. search.hook = hook;
  99. search.with_chain = false;
  100. /* If the key is from the card, we might get the certificate from
  101. the card as well. */
  102. if (no >= 0)
  103. {
  104. struct cert cert;
  105. memset (&cert, '\0', sizeof (cert));
  106. err = scute_agent_get_cert (no, &cert);
  107. if (! err)
  108. {
  109. #if 0
  110. /* For now, we don't need no stinking chain. */
  111. /* As we only have the DER certificate from the card, we need to
  112. parse that and fill out the missing info and try to get the
  113. certificate chain from gpgsm. */
  114. err = scute_cert_from_der (&cert);
  115. #endif
  116. if (! err)
  117. err = search_cb (&search, &cert);
  118. return err;
  119. }
  120. }
  121. search.with_chain = true;
  122. err = scute_gpgsm_search_certs_by_grip (grip, search_cb, &search);
  123. return err;
  124. }