From 583da1a1f5788d02e2b628493f89e042cdae02f5 Mon Sep 17 00:00:00 2001 From: chris Date: Thu, 24 Oct 2002 20:41:27 +0000 Subject: [PATCH] request-kontextmenu contains "sign" create request from certificate FreeBSD paths and libs recognized by configure segfault removed (viewing freshly signed requests) --- MainWindow.h | 3 ++ MainWindowX509.cpp | 64 +++++++++++++++++++++++++++++++++++-------- MainWindowX509Req.cpp | 25 ++++++++++++++--- NewX509.cpp | 22 ++++++++++++++- NewX509.h | 1 + configure.ac | 15 ++++++---- lib/db_x509.cpp | 4 +++ lib/pki_x509.cpp | 3 +- lib/pki_x509req.cpp | 46 ++++++++++++++++++++----------- lib/pki_x509req.h | 4 +++ 10 files changed, 146 insertions(+), 41 deletions(-) diff --git a/MainWindow.h b/MainWindow.h index 1f98f587..81f20c42 100644 --- a/MainWindow.h +++ b/MainWindow.h @@ -151,6 +151,7 @@ class MainWindow: public MainWindow_UI void newKey(); void newReq(pki_temp *templ); void newCert(pki_temp *templ); + void newCert(pki_x509req *req); void newCert(NewX509 *dlg); void newReq(){newReq(NULL);} void newCert(); @@ -195,7 +196,9 @@ class MainWindow: public MainWindow_UI void setCrlDays(); void setTemplate(); void genCrl(); + void signReq(); void crashApp(); + void toRequest(); void setPath(QFileDialog *dlg); void newPath(QFileDialog *dlg); signals: diff --git a/MainWindowX509.cpp b/MainWindowX509.cpp index 8b99d0ea..47d66261 100644 --- a/MainWindowX509.cpp +++ b/MainWindowX509.cpp @@ -74,6 +74,19 @@ void MainWindow::newCert(pki_temp *templ) delete dlg; } +void MainWindow::newCert(pki_x509req *req) +{ + NewX509 *dlg = new NewX509(this, NULL, keys, reqs, certs, temps, certImg, nsImg ); + if (req) { + dlg->defineRequest(req); + } + dlg->setCert(); + if (dlg->exec()) { + newCert(dlg); + } + delete dlg; +} + void MainWindow::newCert(NewX509 *dlg) { pki_x509 *cert = NULL; @@ -81,7 +94,7 @@ void MainWindow::newCert(NewX509 *dlg) pki_x509req *req = NULL; pki_key *signkey = NULL, *clientkey = NULL; int serial = 42; // :-) - bool tempReq; + bool tempReq=false; int i, x, days; string cont="", subAltName="", issAltName="", constraints="", keyuse="", keyuse1="", pathstr="", certTypeStr = ""; @@ -262,6 +275,11 @@ void MainWindow::newCert(NewX509 *dlg) CERR("IssAltName:" << issAltName); cert->addV3ext(NID_issuer_alt_name, issAltName); } + // CRL distribution points + if (!dlg->crlDist->text().isEmpty()) { + CERR("CRL dist. Point: "<< dlg->crlDist->text().latin1() ); + cert->addV3ext(NID_crl_distribution_points, dlg->crlDist->text().latin1()); + } // Step 5 // Nestcape extensions @@ -661,9 +679,10 @@ void MainWindow::writePKCS12() void MainWindow::showPopupCert(QListViewItem *item, const QPoint &pt, int x) { CERR( "popup Cert"); QPopupMenu *menu = new QPopupMenu(this); - QPopupMenu *subMenu = new QPopupMenu(this); - int itemExtend, itemRevoke, itemTrust, itemCA, itemTemplate; - bool canSign, parentCanSign, hasTemplates; + QPopupMenu *subCa = new QPopupMenu(this); + QPopupMenu *subExport = new QPopupMenu(this); + int itemExtend, itemRevoke, itemTrust, itemCA, itemTemplate, itemReq; + bool canSign, parentCanSign, hasTemplates, hasPrivkey; if (!item) { menu->insertItem(tr("New Certificate"), this, SLOT(newCert())); @@ -673,15 +692,19 @@ void MainWindow::showPopupCert(QListViewItem *item, const QPoint &pt, int x) { pki_x509 *cert = (pki_x509 *)certs->getSelectedPKI(item->text(0).latin1()); menu->insertItem(tr("Rename"), this, SLOT(startRenameCert())); menu->insertItem(tr("Show Details"), this, SLOT(showDetailsCert())); - menu->insertItem(tr("Export"), this, SLOT(writeCert())); + menu->insertItem(tr("Export"), subExport); + subExport->insertItem(tr("File"), this, SLOT(writeCert())); + itemReq = subExport->insertItem(tr("Request"), this, SLOT(toRequest())); + subExport->insertItem(tr("Template")); + menu->insertItem(tr("Delete"), this, SLOT(deleteCert())); itemTrust = menu->insertItem(tr("Trust"), this, SLOT(setTrust())); menu->insertSeparator(); - itemCA = menu->insertItem(tr("CA"), subMenu); - subMenu->insertItem(tr("Serial"), this, SLOT(setSerial())); - subMenu->insertItem(tr("CRL days"), this, SLOT(setCrlDays())); - itemTemplate = subMenu->insertItem(tr("Signing Template"), this, SLOT(setTemplate())); - subMenu->insertItem(tr("Generate CRL"), this, SLOT(genCrl())); + itemCA = menu->insertItem(tr("CA"), subCa); + subCa->insertItem(tr("Serial"), this, SLOT(setSerial())); + subCa->insertItem(tr("CRL days"), this, SLOT(setCrlDays())); + itemTemplate = subCa->insertItem(tr("Signing Template"), this, SLOT(setTemplate())); + subCa->insertItem(tr("Generate CRL"), this, SLOT(genCrl())); menu->insertSeparator(); itemExtend = menu->insertItem(tr("Extend")); if (cert) { @@ -694,16 +717,19 @@ void MainWindow::showPopupCert(QListViewItem *item, const QPoint &pt, int x) { parentCanSign = (cert->getSigner() && cert->getSigner()->canSign() && (cert->getSigner() != cert)); canSign = cert->canSign(); hasTemplates = temps->getDesc().count() > 0 ; + hasPrivkey = cert->getKey(); } menu->setItemEnabled(itemExtend, parentCanSign); menu->setItemEnabled(itemRevoke, parentCanSign); menu->setItemEnabled(itemCA, canSign); - subMenu->setItemEnabled(itemTemplate, hasTemplates); + subExport->setItemEnabled(itemReq, hasPrivkey); + subCa->setItemEnabled(itemTemplate, hasTemplates); } menu->exec(pt); delete menu; - delete subMenu; + delete subCa; + delete subExport; return; } @@ -749,6 +775,20 @@ void MainWindow::setTrust() delete dlg; } +void MainWindow::toRequest() +{ + pki_x509 *cert = (pki_x509 *)certs->getSelectedPKI(); + if (!cert) return; + try { + pki_x509req *req = new pki_x509req(cert); + insertReq(req); + } + catch (errorEx &err) { + Error(err); + } + +} + void MainWindow::revoke() { pki_x509 *cert = (pki_x509 *)certs->getSelectedPKI(); diff --git a/MainWindowX509Req.cpp b/MainWindowX509Req.cpp index 13219145..505a8cd1 100644 --- a/MainWindowX509Req.cpp +++ b/MainWindowX509Req.cpp @@ -76,7 +76,6 @@ void MainWindow::newReq(pki_temp *temp) string desc = dlg->description->text().latin1(); pki_x509req *req = new pki_x509req(key, cn,c,l,st,o,ou,email,desc, ""); insertReq(req); - keys->updateView(); } catch (errorEx &err) { Error(err); @@ -101,10 +100,15 @@ void MainWindow::showDetailsReq(pki_x509req *req) if (!req) return; try { ReqDetail_UI *dlg = new ReqDetail_UI(this,0,true); + MARK dlg->descr->setText(req->getDescription().c_str()); + MARK dlg->setCaption(tr(XCA_TITLE)); + MARK if (!req->verify() ) { + MARK dlg->verify->setDisabled(true); + MARK dlg->verify->setText("FEHLER"); } pki_key *key =req->getKey(); @@ -185,9 +189,7 @@ void MainWindow::loadReq() try { pki_x509req *req = new pki_x509req(s.latin1()); insertReq(req); - pki_key *pkey = req->getKey(); MARK - if (pkey) keys->updateViewPKI(pkey); } catch (errorEx &err) { Error(err); @@ -232,6 +234,20 @@ void MainWindow::writeReq() } } +void MainWindow::signReq() +{ + pki_x509req *req; + try { + req = (pki_x509req *)reqs->getSelectedPKI(); + } + catch (errorEx &err) { + Error(err); + return; + } + newCert(req); +} + + void MainWindow::insertReq(pki_x509req *req) { pki_x509 *oldreq; @@ -258,6 +274,7 @@ void MainWindow::insertReq(pki_x509req *req) MARK reqs->insertPKI(req); MARK + if (req->getKey()) keys->updateViewPKI(req->getKey()); } catch (errorEx &err) { Error(err); @@ -275,7 +292,7 @@ void MainWindow::showPopupReq(QListViewItem *item, const QPoint &pt, int x) { else { menu->insertItem(tr("Rename"), this, SLOT(startRenameReq())); menu->insertItem(tr("Show Details"), this, SLOT(showDetailsReq())); - //menu->insertItem(tr("Sign"), this, SLOT(signReq())); + menu->insertItem(tr("Sign"), this, SLOT(signReq())); menu->insertItem(tr("Export"), this, SLOT(writeReq())); menu->insertItem(tr("Delete"), this, SLOT(deleteReq())); } diff --git a/NewX509.cpp b/NewX509.cpp index d6599932..239aac4f 100644 --- a/NewX509.cpp +++ b/NewX509.cpp @@ -172,7 +172,7 @@ void NewX509::setRequest() changeDefault->setEnabled(false); changeDefault->setChecked(false); signerBox->setEnabled(false); - startText=tr("Welcome to the settings for Certificate signing requests.... (needs more prosa)"); + startText=tr("Welcome to the settings for Certificate signing requests.... (needs more prosa, volunteers ?)"); endText=tr("You are done with entering all parameters for generating a Certificate signing request..... (needs more prosa, volunteers ?)"); tText=tr("Certificate request"); setup(); @@ -227,6 +227,26 @@ void NewX509::defineTemplate(pki_temp *temp) fromTemplate(temp); } +void NewX509::defineRequest(pki_x509req *req) +{ + if (!req) return; + fromReqCB->setEnabled(true); + fromReqCB->setChecked(true); + QString reqname = req->getDescription().c_str(); +#ifdef qt3 + reqList->setCurrentText(reqname); +#else + for (int i=0; icount(); i++) { + if (reqList->text(i) == reqname) { + reqList->setCurrentItem(i); + break; + } + } +#endif + +} + + int NewX509::lb2int(QListBox *lb) { diff --git a/NewX509.h b/NewX509.h index 21350dd5..007e9f87 100644 --- a/NewX509.h +++ b/NewX509.h @@ -95,6 +95,7 @@ class NewX509: public NewX509_UI void toTemplate(pki_temp *temp); void fromTemplate(pki_temp *temp); void defineTemplate(pki_temp *temp); + void defineRequest(pki_x509req *req); int lb2int(QListBox *lb); void int2lb(QListBox *lb, int x); diff --git a/configure.ac b/configure.ac index a3465978..cbb319e4 100644 --- a/configure.ac +++ b/configure.ac @@ -12,8 +12,9 @@ if test -d "$QTDIR" ; then export LDFLAGS="$LDFLAGS -L$QTDIR/lib" AC_MSG_NOTICE([Using QT in $QTDIR....]) else - export CPPFLAGS="$CPPFLAGS -I/usr/include/qt -I/usr/local/include/qt" - AC_MSG_NOTICE([QTDIR was not set, using default locations]) + export CPPFLAGS="$CPPFLAGS -I/usr/include/qt -I/usr/local/include" + export LDFLAGS="$LDFLAGS -L/usr/local/lib -L/usr/X11R6/lib" + AC_MSG_NOTICE([QTDIR was not set, using system locations]) fi H_SSL=no H_DB=no @@ -45,16 +46,18 @@ LQT=y AC_CHECK_LIB([qt], [atexit], ,[LQT=no]) if test "$LQT" == "no"; then LQT=y - AC_CHECK_LIB([qt${QT_VER}], [atexit], ,[LQT=no]) + AC_CHECK_LIB([c_r], [atexit]) + AC_CHECK_LIB([qt-mt], [atexit], ,[LQT=no]) + fi -AC_PATH_PROG(MOC,moc,[moc],[$PATH],,[LQT=no]) -AC_PATH_PROG(UIC,uic,[uic],[$PATH],,[LQT=no]) +AC_PATH_PROG(MOC,moc,[moc],[$PATH /usr/X11R6/bin],,[LQT=no]) +AC_PATH_PROG(UIC,uic,[uic],[$PATH /usr/X11R6/bin],,[LQT=no]) if test "$LDB" == "no"; then AC_MSG_ERROR([QT library and tools not found, try setting $QTDIR apropriate or install qt-dev]) fi -AC_ARG_ENABLE([printf-debug],[--enable-printf-debug switch on or off the printf-debugging :-) ], +AC_ARG_ENABLE([printf-debug],[ --enable-printf-debug switch on or off the printf-debugging ], [if test "x$enableval" == "xyes"; then AC_DEFINE(PRINTF_DEBUG) fi], AC_DEFINE(PRINTF_DEBUG) ) diff --git a/lib/db_x509.cpp b/lib/db_x509.cpp index 71351e8b..2d726099 100644 --- a/lib/db_x509.cpp +++ b/lib/db_x509.cpp @@ -79,6 +79,10 @@ pki_x509 *db_x509::findSigner(pki_x509 *client) pki_x509 *signer; if ((signer = client->getSigner()) != NULL) return signer; QListIterator it(container); + if (client->verify(client)) { + CERR("SELF signed"); + return signer; + } for ( ; it.current(); ++it ) { signer = (pki_x509 *)it.current(); if (client->verify(signer)) { diff --git a/lib/pki_x509.cpp b/lib/pki_x509.cpp index d14dfedf..e4a67ad0 100644 --- a/lib/pki_x509.cpp +++ b/lib/pki_x509.cpp @@ -93,8 +93,7 @@ pki_x509::pki_x509(string d,pki_key *clientKey, pki_x509req *req, pki_x509 *sign X509V3_set_ctx(&ext_ctx, signer->cert, cert, req->request, NULL, 0); X509V3_set_ctx_nodb((&ext_ctx)) - if (pkey) - pkey->incUcount(); + setKey(req->getKey()); openssl_error(); } diff --git a/lib/pki_x509req.cpp b/lib/pki_x509req.cpp index 0fa013f5..d746d03f 100644 --- a/lib/pki_x509req.cpp +++ b/lib/pki_x509req.cpp @@ -50,7 +50,7 @@ -#include "pki_x509req.h" +#include "pki_x509.h" void pki_x509req::init() { @@ -68,19 +68,8 @@ pki_x509req::pki_x509req(pki_key *key, const string cn, :pki_base( d ) { init(); - request = X509_REQ_new(); - openssl_error(); - if (key == NULL) { - openssl_error("key ist null"); - return; - } - openssl_error(); - X509_REQ_set_version(request, 0L); - openssl_error(); - X509_REQ_set_pubkey(request, key->key); - openssl_error(); - X509_NAME *subj = X509_REQ_get_subject_name(request); + X509_NAME *subj = X509_NAME_new(); if (cn != "") X509_NAME_add_entry_by_NID(subj,NID_commonName, MBSTRING_ASC, (unsigned char*)cn.c_str(),-1,-1,0); @@ -103,15 +92,40 @@ pki_x509req::pki_x509req(pki_key *key, const string cn, X509_NAME_add_entry_by_NID(subj,NID_pkcs9_emailAddress, MBSTRING_ASC, (unsigned char*)email.c_str() , -1, -1, 0); + createReq(key, subj); + X509_NAME_free(subj); +} + +pki_x509req::pki_x509req(pki_x509 *cert) :pki_base() +{ + init(); + if (!cert) return; + setDescription(cert->getDescription()); + createReq(cert->getKey(), X509_get_subject_name(cert->getCert())); +} + +void pki_x509req::createReq(pki_key *key, X509_NAME *dist_name) +{ + request = X509_REQ_new(); + openssl_error(); + if (!key || key->isPubKey()) { + openssl_error("key not valid"); + return; + } + openssl_error(); + X509_REQ_set_version(request, 0L); + openssl_error(); + X509_REQ_set_pubkey(request, key->key); + openssl_error(); + X509_REQ_get_subject_name(request) = X509_NAME_dup( dist_name); + openssl_error(); const EVP_MD *digest = EVP_md5(); X509_REQ_sign(request,key->key ,digest); openssl_error(); - privkey = key; - key->incUcount(); + setKey(key); } - pki_x509req::pki_x509req() : pki_base() { init(); diff --git a/lib/pki_x509req.h b/lib/pki_x509req.h index 71c71940..cd4abcd6 100644 --- a/lib/pki_x509req.h +++ b/lib/pki_x509req.h @@ -57,6 +57,8 @@ #ifndef PKI_X509REQ_H #define PKI_X509REQ_H +class pki_x509; + class pki_x509req : public pki_base { protected: @@ -69,6 +71,7 @@ class pki_x509req : public pki_base const string ou,const string email, const string d, const string challenge); pki_x509req(); + pki_x509req(pki_x509 *cert); pki_x509req(const string fname); ~pki_x509req(); void init(); @@ -81,6 +84,7 @@ class pki_x509req : public pki_base pki_key *getPubKey(); pki_key *getKey(); bool setKey(pki_key *key); + void createReq(pki_key *key, X509_NAME *dist_name); }; #endif