Commit Graph

1324 Commits

Author SHA1 Message Date
Christian Hohnstaedt
1e544161f6 Eliminate the use of "mainwin" in lib/db_* 2020-05-08 11:59:09 +02:00
Christian Hohnstaedt
7c65a786ea Revamp database management
The global variable "Database" of class xca_db
can be used by any other class to access. No need
to provide it.

The "xca_db" class managed the "database_model" pointer.
Accessing the name of the current database has been unified.
2020-05-08 07:47:15 +02:00
Christian Hohnstaedt
93a7c6a9a3 Implement option --list-curves and display EC curves 2020-05-06 18:32:37 +02:00
Christian Hohnstaedt
9b201566e2 Improve on cmdline, console, unicode and windows CMD
Improve Windows registry functions

Use *A postfix function explicit becaus e we don't expect
unicode characters.
Also simplify "console_write()"
2020-05-06 18:32:27 +02:00
Christian Hohnstaedt
d1c0970ea1 BioByteArray: Add size() method 2020-05-06 18:08:36 +02:00
Christian Hohnstaedt
b5c9d645e3 More native separators when displaying file names 2020-05-06 17:57:09 +02:00
Christian Hohnstaedt
b2ab7570b8 Minor fixxes and constifies 2020-04-30 18:47:28 +02:00
Christian Hohnstaedt
0f7465dcc5 Add convenience function to convert QModelIndex to pki_base * 2020-04-30 18:46:08 +02:00
Christian Hohnstaedt
03633d7a8a Provide db class name through constructor 2020-04-30 18:44:36 +02:00
Christian Hohnstaedt
a3344100e3 Drop FOR_ALL_pki() makro and use a foreach() loop
The foreach loop iterates over all items of a type.
The iterate method is now superflous
2020-04-30 18:40:49 +02:00
Christian Hohnstaedt
8f46d238e0 Replace __ME makro by pki_base QString() operator
Now a pki item can transform itself to a QString for debugging
2020-04-30 18:37:48 +02:00
Christian Hohnstaedt
5a64725556 Move item store from db_base into separate class "pki_lookup"
Since also pki_base and other classes need to access them.
2020-04-30 18:37:25 +02:00
Christian Hohnstaedt
f889efc4cb Merge branch 'master' into develop 2020-04-30 18:34:16 +02:00
Christian Hohnstaedt
1f2429e677 Avoid filedescriptor leak 2020-04-29 13:29:01 +02:00
Christian Hohnstaedt
76e3f86783 Close #191: OID LN differs warning popups at startup
OpenSSL fixed the 2 LN with commit:
  648b53b88e

in OpenSSL 1.1.1e.

Follow my own advice and delete them from the oids.txt
together with all other OIDs present in OpenSSL
since at least version 0.9.8

Also do the initOIDs after creating the QApplication to
avoid qAbort() when creating the warning (introduced after 2.2.1)
2020-04-27 15:03:36 +02:00
Christian Hohnstaedt
0ac3b2daca Improve and fix VERSION_ITERATION 2020-04-27 15:03:36 +02:00
Christian Hohnstaedt
7d5bb9ca4f Fix newline handling 2020-04-07 15:54:16 +02:00
Christian Hohnstaedt
5cb1b45d81 console_write: takes a QByteArray instead of printf()
Good Windows Unicode font:
https://math.berkeley.edu/~serganov/ilyaz.org/software/fonts/
2020-04-06 22:08:04 +02:00
Christian Hohnstaedt
dd46ff7201 Fix Copy&Paste'o: Put issuer into issuer property and not subject 2020-04-06 22:07:57 +02:00
Christian Hohnstaedt
ea453d4336 Encapsulate all BIOs in the BioByteArray class
If we have a QByteArray (ba) and must provide it to
a BIO* expecting OpenSSL function, the following
construct provides it: BioByteArray(ba).ro()
directly providing the QByteArray buffer as BIO

It also supports mixed writes:
  BIO_write(bba, buf, size)
  bba += QByteArray
2020-04-06 22:07:57 +02:00
Christian Hohnstaedt
4d95912d51 Add console_write() to print also on CMD 2020-04-05 22:45:11 +02:00
Christian Hohnstaedt
b7d3e6a3cc Merge branch 'master' into develop 2020-04-05 13:49:01 +02:00
Christian Hohnstaedt
fb5ee14911 Improve PKCS11 library loading for portable app 2020-04-05 13:12:09 +02:00
Christian Hohnstaedt
a9a4c2b2d6 remote database: Dont show error if the password was empty
Otherwise, first an error message is shown and then
a password is asked.
2020-04-05 13:08:47 +02:00
Christian Hohnstaedt
9d7275ef31 Accept missing "dbhistory" file 2020-04-05 10:59:00 +02:00
Christian Hohnstaedt
c528c37986 Merge branch 'master' into develop 2020-04-05 10:58:47 +02:00
Christian Hohnstaedt
4314b0ead9 constify slotid 2020-04-05 09:16:12 +02:00
Christian Hohnstaedt
500f11c9b3 Get rid of filename2bytearray and QString2filename
We now use QFile or its derivate XFile, who smoothly
handle unicode filenames also on windows.

The lt_dlopen() only handles "char *" not wchar_t.
Try to convert the filename with all known codecs
until we can open it.

filename2QString() remains to differently encode
filenames provided on the commandline on Windows.
2020-04-05 09:16:12 +02:00
Christian Hohnstaedt
2d0980d4f6 Use pkcs11_lib_list as model for Options:pkcs11list
Change pkcs11List from QListWidget to QListView
The pkcs11_lib_list holds the data of the loaded libraries.
For the model a QList "model_data" is used to
hold indexes into QList dirs to allow duplicates,
moves and removes.

On windows it now displays the paths with \ separators.
2020-04-05 09:16:12 +02:00
Christian Hohnstaedt
296ff59f3c PKCS11 library list: Don't get confused by C: when expecting 1: 2020-04-03 21:56:37 +02:00
Christian Hohnstaedt
5543ec2fb8 Merge branch 'master' into develop 2020-04-02 07:35:18 +02:00
Christian Hohnstaedt
b41d322069 Refactor native separators / and \ on windows.
Always only use forward slash /
Drop all "QDir::separator()" and "nativeSeparator()"
functions. Only use it where filenames are displayed for the user.
2020-04-02 06:12:47 +02:00
Christian Hohnstaedt
66a85497b7 Improve development version calculation as 4th digit
The plus sign was not compatible with the WIX toolset.
The 4th digist is the number of commits since the last release.

For a tagged release it is not 00, but empty.
2020-04-01 22:56:53 +02:00
Christian Hohnstaedt
096e57ec8c Close #70: cant open ics file in ical on macos mojave
Fixed syntax errors in the ICS file.
Verified by http://ical-validator.herokuapp.com/validate/
Thanks for the service.
2020-04-01 12:29:55 +02:00
Christian Hohnstaedt
d54aa116db Avoid unused variable warning for OpenSSL 0.9.8 2020-03-29 22:33:57 +02:00
Christian Hohnstaedt
524aff97b8 Load OID lists. Fixup for c89b6aff 2020-03-29 22:33:57 +02:00
Christian Hohnstaedt
799d3262b0 Reactivate translation of x509 expressions 2020-03-29 22:33:57 +02:00
Christian Hohnstaedt
4f1103a64f Close #72: Add checkbox for OCSP staple feature
Also support them in XCA template and transformation from
certificate and request.
2020-03-29 22:23:21 +02:00
Christian Hohnstaedt
9c55caf82f Merge branch 'master' into develop 2020-03-23 06:53:06 +01:00
Christian Hohnstaedt
149ecda63c Fix index-hierarchy functionality
create target directory and name feature "hierarchy"
2020-03-23 06:39:30 +01:00
Christian Hohnstaedt
852da61836 Fix array access 2020-03-22 08:12:38 +01:00
Christian Hohnstaedt
8cf138b409 Drop debugging code 2020-03-22 08:12:38 +01:00
Christian Hohnstaedt
92846d6b38 Close #174: Microsoft's PVK RSA private key format
Support Import and export private and public PVK keys.
2020-03-22 08:12:38 +01:00
Christian Hohnstaedt
f244cec5d3 Drop functions from legacy database modul
Only read-functions are required for an
upgrade
2020-03-20 16:29:43 +01:00
Christian Hohnstaedt
928ff6458c Improve and fix qDeleteAll()
qDeleteAll() does not clear the QList.
Add it, if necessary.

Use dynamic_cast where appropriate
2020-03-20 16:29:42 +01:00
Christian Hohnstaedt
b8b368d787 hashNum() is an unsigned integer 2020-03-19 20:40:36 +01:00
Christian Hohnstaedt
9183f300c8 Add support for validating a keyjob
In case of an invalid keyjob bail out.
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
919f4f6b23 Parse keytype uppercase to also allow "rsa:2048" 2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
ee7739baa6 Improve detection of commands enforcing no-gui
provided cmdline parameter are handled as abbreviated
parameter.
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
7a5936eb9f Replace malloc/free by new/delete 2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
31088b608c cmdline help move the asterisk to the front
indicating the requirement for a database when using this option.
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
7babd609be Drop unneeded pki_base::insert()
Insert / append does not matter,
because the rows are sorted by columns anyway.
2020-03-17 05:13:35 +01:00
Christian Hohnstaedt
51ffe4e43e Drop functions from legacy database modul
Only read-functions are required for an
upgrade
2020-03-17 05:07:59 +01:00
Christian Hohnstaedt
9845a00ca3 Store default database and recently opened file as UTF8 2020-03-17 05:07:46 +01:00
Christian Hohnstaedt
00bf676f0a Fix building for Windows
No ioctl() on windows.

Avoid initialisation race of static arrays
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
595cf9a722 Drop connNewX509() signal and slot
in the past it was used to connect the NewX509 dialog
with requests keys and certs.

The NewX509 dialog knows mainwin since some time
and thus can connect itself to models and views

mainwin: use model<T>() instead of models->model<T>()
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
af3816a7b0 Fix building against OpenSSL 0.9.8 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
dcd2e1a223 Replace typeid by dynamic_cast where appropriate 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
ef9b3aff3d Drop superflous includes from header files 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
2f917237bc Close #157 Generate and export CRLs from commandline
Enable key generation and CRL generation on the commandline
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
aacd9ee5f6 Make XcaProgress and WAITCURSOR cmdline compatible 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
a48ea10e3d Split key generation and data-collection-UI
Use the key job to transfer the information
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
a6ec3a9319 Minor fixes without functional changes 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
f1fd65c9cf Add keyjob (TBC)
Invent keyjob
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
77519936e0 Invent keytype class for mapping type mechanism and name 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
241d7e9c7f Move newItem() function from model to view
Move CRL and Template data collection via UI to
the appropriate views
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
3dd34a61bc Move "showPki()" from the model class to the view
The displaying function requires UI.
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
d0d387b03e Directly display the error instead of signaling others
The XCA_ERROR() is console-compatible and can be used
without GUI
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
c3abd640fc Fix certificate assignment importing a CA certificate
Fix finding our unassigned certificates when importing a CA
(issuerSqlId may be QVariant(int, 0) depending on the database)

Reassign certs from an older CA to the imported one.
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
c098b235ce Minor fix. No Message when exiting 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
10857e3e0c Support item import from the commandline 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
aa55a68782 Let pki_pkcs12 and pki_pkcs7 inherit from pki_multi
And ImportMulti handles pki_multi sufficiently
and does not need to know about pkcs12 or pkcs7

pkcs12 and pkcs7 don't need: print() getCa() addCaCert() numCa()
it is handled by pki_multi()

Take advantage of the power of dynamic_cast<>() instead of using
typeid()
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
1278ef9379 Add self-accounting of items for debugging 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
19eafe1739 Improve and fix qDeleteAll()
qDeleteAll() does not clear the QList.
Add it, if necessary.

Use dynamic_cast where appropriate
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
98593e7462 Compatibility fixes for QT4 and OpenSSL 0.9.8
Need to drop support for those ancient libs.
Not, yet.
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
55d1693015 Improve printing of cmdline items
Unify --print by collecting all properties
Add --pem to print the item in PEM format
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
1544065133 Extend --print and --text functionality 2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
64ef856546 Add flag to option list, declaring whether a database is required 2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
c89b6aff29 Move NID lists for ExtendedKeyUsage and DistinguishedName
into lib/oid.h
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
c5208f1cd7 Consolidate headers, unguard delete operator 2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
e4d0ab8f8e Refactor Image and icon ressources 2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
7d0ab9d787 Add pki_XXX(const pki_XXX*) constructor
pki_XXX(const QString) -> (const QString &)
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
b2a69f3586 Several fixes of previous commit
Passwd::cleanse() also resets the password size
db_base::flushLookup() now deletes all items
and pki_base does not anymore.

Drop TRACE
Colorize pki_base::print()

Set and inherit filename of loaded items
Add print() method to pki_pkcs12
and constify its methods
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
a90d7b5b0d Improve password input handling
Unify password results
Retry on password verification error
Honor the users wish to exit
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
30824964a2 hashNum() is an unsigned integer 2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
9da73073c8 Create CRL by providing a crljob, describing the parameters
The GUI will prepare such a job and the cmdline can do so, too.
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
089c7d39ef Improve console password input 2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
176c2f8169 Improve password input and handling
Use the Passwd class instead of QString

Move password input into the database model
to be available for commandline use.

Repeat in case of wrong password
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
c1ea126efe linewrap in help 2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
113a201d39 Separate database from Mainwin for better cmdline support
New classes:
 - database_model: Manage the database tables (keys, req, cert, crl, templ)
   extracted from widgets/MW_database.cpp
 - arguments: parse commandline, dynamically create help text
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
a1fedfaf9e Fix building against OpenSSL without EC.
This commit amends b982245995
which broke the NO_EC build
2020-03-11 05:56:54 +01:00
Christian Hohnstaedt
176e26e390 Close #170 xca-portable-2.2.1 cannot change language
Use GetModuleFileNameW() and RegGetValueW()
returning the path as UTF-16 encoded unicode.

entropy: Use QFile inherited class for file access

This allows wchar_t encoded file names and paths
on windows.

So glad not having to deal with wchar_t / UTF-16 otherwise,
but using QString and UFT-8. The destiny of early adopters....
2020-03-11 05:49:18 +01:00
Christian Hohnstaedt
84560e26e1 Fix certificate assignment importing a CA certificate
Fix finding our unassigned certificates when importing a CA
(issuerSqlId may be QVariant(int, 0) depending on the database)

Reassign certs from an older CA to the imported one.
2020-03-11 05:49:18 +01:00
Christian Hohnstaedt
8379b51610 Use list initializers for template keys 2020-03-07 06:48:07 +01:00
Christian Hohnstaedt
dc2ef08fa5 Constify db 2020-02-12 22:43:33 +01:00
Christian Hohnstaedt
fe59727825 Move includes required for FreeBSD 2020-02-12 22:43:33 +01:00
Christian Hohnstaedt
b982245995 Close #163: Show key type/size on column of Certificates tab
Reuse HD_key_type, HD_key_size, HD_key_curve IDs from the key tab.
They use the "hd_key" type to put them into a context-submenu.

The certificate either uses the existing or a temporary key
and calls its "column_data()".

Simplify the submenu logic for the context-menu.
2020-02-12 22:42:36 +01:00
Patrick Monnerat
20b1c4fc8a Resolve gcc 9/10 new warnings.
-Wstringop-truncation:
Ensure length passed to strncpy() is < size of destination buffer. The last
buffer byte is already nullified afterwards (in db::init_header() and
db::rename()).

-Wdeprecated-copy:
Explicit define of errorEx copy assignment operator.
Explicit define of x509revList copy assignment operator.
Explicit define of slotid copy constructor.

-Wimplicit-fallthrough:
Refactor code to suppress case fallthrough in pki_key::ssh_key_bn2data().
2020-02-09 01:24:06 +01:00
Guido Falsi
c3d7af01fd Add includes required in FreeBSD to use in6_addr, AF_INET and AF_INET6. 2020-02-01 18:39:59 +01:00
Christian Hohnstaedt
bf09030dc9 Close #159 Opening existing database
Read the database schema from 'settings' uncached.
2020-01-30 17:00:15 +01:00
Christian Hohnstaedt
dcf8c7bcdb No need for KEY_WOW64_32KEY registry flag
Registry entries are also 64bit.
2020-01-22 05:56:11 +01:00
Christian Hohnstaedt
4e16158668 Add missing DLL for PosgreSQL DLL 2020-01-21 21:34:31 +01:00
Christian Hohnstaedt
a12b2e94f5 Close #129 Unattended Installation. Switch to MSI installer
Improve Windows installation xca.wxs

Move documentation to "html" dir and translations to "i18n"
in the portable-app and the MSI installation
Modyfies getDocDir() and Introduces getI18nDir()

Drop Nullsoft installer files
2020-01-20 22:33:05 +01:00
Christian Hohnstaedt
a05349e917 Portable App: xca.exe path differs from registry install path
Even better select the initial working directory
2020-01-19 08:48:02 +01:00
Christian Hohnstaedt
580a2fae2b Close #93 Default output folder / Improve Portable App usability
- allow setting a database as default
- Strip xca-app-folder from database and export filenames.
  This allows renaming/moving the portable app and open the default DB
  and use the working directory inside the folder
- Remember database history and configured language
2020-01-13 07:26:46 +01:00
Christian Hohnstaedt
23a737bbfa Constify getLibExtensions() 2020-01-13 07:26:46 +01:00
Christian Hohnstaedt
2fbadfc9f0 Update Copyright Years to 2020 2020-01-13 07:26:46 +01:00
Christian Hohnstaedt
953d26c419 Close #21 Support for ODBC (MSSQL)
Add ODBC QSQL Database driver

Column "public" in public_keys table is a keyword in
MSSQL. Double quote it.
Double quotes are invalid on MySQL in non-ANSI mode.
Force ANSI mode for MySQL/MariaDB databases.

MSSQL also has a maximum VARCHAR of 8000

Schema updates are not performed for each new database.
New databases are immediately created conforming to schema:7
Schema 5 and 6 get updated to 7.
Schemas < 5 never have been released officially. (pre 2.0.0)

Switch "Database name" label to "DSN" for ODBC databases.
2020-01-13 07:24:08 +01:00
Christian Hohnstaedt
fd09ebe9ff Close #156 secp256k1, secp256r1 and NIST-P256
Highlight RFC 5480 curves at the top of the list
2020-01-08 05:57:32 +01:00
Christian Hohnstaedt
ae94faebaf Transfer Key Usage and Extended Key Usage critical flags
When transforming certificate or request extensions
into a template, the (e)keyusage critical flags storage
had a typo:
  "eKyUseCritical" instead of "ekuCritical" and
  "keyUseCritical" instead of "kuCritical"

Also the eKeyUse value was not transformed completely.
2020-01-07 06:08:30 +01:00
Christian Hohnstaedt
1ea45c8da4 Constify fload() fromPEM_BIO() fromPEMbyteArray()
Use "BIO_from_QByteArray()" instead of "BIO_new_mem_buf()"

Replace qSort() by std::sort()
Replace QString::null by QString()
2020-01-06 21:30:29 +01:00
Christian Hohnstaedt
8726c8b96d Improve item loading. Inspired by #153
If Loading the item results in an openssl error,
even if the item is not empty, discard it.
Otherwise loading it from the database later on will fail.

Improve "autoIntName()"
2020-01-06 19:35:11 +01:00
Christian Hohnstaedt
2105fd8a75 Constify table names 2020-01-05 14:02:50 +01:00
Christian Hohnstaedt
9aa2525fab Remove fopen_error() and its last user. 2019-12-19 07:17:03 +01:00
Christian Hohnstaedt
4199b8dfc6 Fix SSH2 public key export
Amend commit c26e7a4695
where the base64 key got lost in the output!
2019-12-16 17:14:37 +01:00
Christian Hohnstaedt
aac04418f5 Improved language maintainers 2019-12-14 13:24:15 +01:00
Christian Hohnstaedt
212b385022 Fix Typo 2019-12-14 13:24:15 +01:00
Christian Hohnstaedt
91dc86909f Close #138: Portable Version does not remember paths
Store export/import path as workingdir in database
also for the portable app.

Do not load a working dir that does not exist.
2019-12-12 23:20:19 +01:00
Christian Hohnstaedt
4bce90e986 Close 83: Token selection should not insist on name or serial of the token
Only use the public key when searching for
a matching key on the token.

Use token-name and serial to give the user a hint which token
XCA expects to carry the key.
2019-12-07 13:10:57 +01:00
Christian Hohnstaedt
2397ab72de Close #140: Certificate renewal with option to preserved serial number
Add checkbox (unchecked by default) to keep the old serial number
while renewing certificates
2019-12-06 15:28:09 +01:00
Christian Hohnstaedt
7f833a591f Close #144: Database export has issues with wildcards in internal names
Escape more characters when using internal name
as file name according to:
https://docs.microsoft.com/de-de/windows/win32/fileio/naming-a-file

Append a "_" after "CON, PRN, AUX, NUL, COM1-9, LPT1-9" as filename.
2019-12-05 14:56:39 +01:00
Christian Hohnstaedt
bb4b1e3a08 Change chinese language code from "zh" to "zh_CH" 2019-09-10 21:58:49 +02:00
Christian Hohnstädt
39f358e23f
Merge pull request #84 from chipitsine/master
resolve possible null pointer dereference
2019-05-14 17:50:05 +02:00
Christian Hohnstaedt
80affcfa61 CLose #120: Mark signed a request doesn't work
PostgreSQL requires in INT type instead of bool,
when setting the signed column.
2019-05-13 17:06:57 +02:00
Christian Hohnstaedt
c7a0f14283 Close #116: Duplicate extensions erroneously shown
Dynamically add unknown OIDs with its numerical representation
to always resolve them to avalid NID.
2019-05-13 16:45:57 +02:00
Christian Hohnstaedt
58669685eb Close #114: SAN - IPv6 address input not working
Do not try to write an own IP v4/6 validator.
The libc function inet_pton() does what we need.
2019-04-29 19:16:27 +02:00
Christian Hohnstaedt
79441b766d Change hash algo of PKCS#12 certificate to 3DES SHA1
this is for systems where RC2 has been disabled for security reasons.
2019-04-08 06:27:21 +02:00
Christian Hohnstaedt
b9a8bb1a04 Cleanup: remove unused properties and declarations 2019-03-27 05:58:25 +01:00
Christian Hohnstaedt
47d4bfac2c Improve SQL sequence when deleting a certificate 2019-03-27 05:58:20 +01:00
Christian Hohnstaedt
5e3d5e0edc Cancel creating a new database if database-password dialog is cancelled.
Clicking cancel in the password dialog during database creation
does not trigger an assertion during key generation/import
anymore.
2019-03-27 05:58:15 +01:00
Christian Hohnstaedt
68ffb63db6 Use the SQL primary key to reference the CRL issuer
... and avoid the pointer
2019-03-25 07:23:53 +01:00
Christian Hohnstaedt
e9df5b7cda Use the SQL primary key to reference the certificate issuer
... and avoid the pointer
2019-03-25 07:22:35 +01:00
Christian Hohnstaedt
4eb7b170b1 Do not reference the key by pointer, but by Key Id
This way the pointer to the key may change during reload.
2019-03-25 06:59:25 +01:00
Christian Hohnstaedt
f43e7520db Support concurrent database access.
If a database is modified by another instance of XCA the passive
instance reloads and displays the changed parts.
2019-03-25 06:47:25 +01:00
Christian Hohnstaedt
ced0995862 Close #91: Change order of "PKCS#11 provider"
With this commit PKCS#11 libraries may be reordered
and enabled or disabled.

The slot selection dialog iterates over all enabled and successfully
loaded libraries in the configured order and collects the slots
of each of them.

In the options dialog the library info is shown in the tool-tip
2019-03-21 06:12:51 +01:00
Christian Hohnstaedt
8f3335be0f Improve lib detection 2019-03-21 05:25:21 +01:00
Christian Hohnstaedt
157b0a3fae Move Template file reading to QFile API 2019-03-21 05:25:21 +01:00
Christian Hohnstaedt
a28b943b5f Fix missing ; after return 2019-03-20 17:44:08 +01:00
Christian Hohnstaedt
1086329ee1 Fix for Openssl nno-ec 2019-03-18 06:25:20 +01:00
Christian Hohnstaedt
fa704001ca Also change File loading from FILE* to QFile 2019-03-18 06:25:20 +01:00
Christian Hohnstaedt
026d8f8e6d Extend PEM files by human readable information about the item
This can be enabled or disabled during export.
Move from FILE* to QFile
2019-03-18 06:25:20 +01:00
Christian Hohnstaedt
f55c7feee7 Constify some functions 2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
a78d953338 Support ecdsa SSH public keys 2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
742e1536d7 Fix Private key verification 2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
c26e7a4695 Close #98 Add comment at import/export RSA keys from/to SSH public key
When loading the SSH key add the trailing comment to the comment field
When storing the key, append the first line of the comment to the key.
2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
1bc340a0ef Close #104: Also show sha256 digests of public keys
Print digest of public keys in the key details in different formats:

Print SHA256 SSH digest as used to by SSH users:
	ssh-keygen -l -f ~/.ssh/id_rsa.pub

Print SHA1 X509 key digest as shown in the
	Subject key identifier of a certificate

Print SHA256 digest as in:
	openssl pkey -pubout -outform DER < key.pem | sha256sum
as requested by this issue.

Refactored digesting functionality by a generic Digest()
function working with QByteArrays.
The function formatHash() now also expects a QByteArray input.
2019-03-14 06:35:24 +01:00
Christian Hohnstaedt
c41bbf9b23 Close #82: Renew CA ROOT Cert
Enable renewal option in the context menu
for self-signed CA certificates
2019-03-12 22:11:52 +01:00
Christian Hohnstaedt
56687bfc83 Verify imported keys thoroughly
When importing keys, a verification by signing and verifying
some random data is performed now.
2018-12-06 05:50:09 +01:00
Christian Hohnstaedt
a46759a946 Fix workingdir setting 2018-11-17 15:38:18 +01:00
Christian Hohnstaedt
7d5ecacad8 Make debug output configurable
Setting the XCA_DEBUG environment variable != ""
will enable debugging.
2018-11-17 14:14:44 +01:00
Ilya Shipitsin
1e0ca9f755 resolve possible null pointer dereference
[lib/db_temp.cpp:104] -> [lib/db_temp.cpp:103]: (warning) Either the condition 'if(temp)' is redundant or there is possible null pointer dereference: temp.
2018-11-14 23:04:56 +05:00
Christian Hohnstaedt
00fbb85c70 Improve on portable App and registry access 2018-11-07 18:30:14 +01:00
Christian Hohnstaedt
91faa1b675 Improve portable App 2018-11-05 06:21:14 +01:00
Christian Hohnstaedt
736dac6250 Close #40 macOS: Crash after xca v2.0.1 quit
If I select "Quit xca" from the "xca" menu, the application exits gracefully.
Unify code paths between "Quit xca", CMD-Q, ALT-F4 and [X] button
by calling mainwindow->close() from qApplication->quit() slot.
2018-10-29 22:24:22 +01:00
Christian Hohnstaedt
7b7e2644fa Close #74: Exiting XCA 2.1.1 corrupts database
The case-insensitive object search adds all short and long names
to a lookup table mapping the lowercase name to the corrersponding nid.

The array of nids contains 7 undefined nids. Resolving them
raises the error.

This fix deletes those errors after the map has been built.
2018-10-29 22:24:22 +01:00
Christian Hohnstaedt
eba8be37b8 Make PKCS11 libs, working dir and main-window size host-dependent
A "hostId" determines the current host and is appended to
the "workingdir", "pkcs11path" and "mw_geometry" settings
in the database. This allows opening the database
on different hosts without wrong workingdir or not
loadable PKCS#11 libraries
2018-10-29 22:24:22 +01:00
Christian Hohnstaedt
00bd36f19b Support for XCA as portable App
On Windows XCA goes in portable mode if no XCA registry entry is found.
On Mac and Unix it checks the XCA_PORTABLE environment to be non-empty.
In portable mode:
 - The current working directory is not written to the database
 - The configured language and history of opened databases is
   forgotten after a restart of XCA
 - No registry entry is required nor written.
 - No unexpected files are written to disk, except exported items.
 - Portable mode is displayed in the "About" dialog

If setup.exe or "make install" are not used,
 - XCA is not assigned as app for any file types
2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
6f8ca8dd65 Improve DN translation notation 2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
1953f7f1b0 Improve defaultdb / defaultlang handling. No functional change 2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
ed53777e78 Fix compiler warnings
clang version 3.8.0-2ubuntu4
gcc version 5.4.0 20160609 (Ubuntu 5.4.0-6ubuntu1~16.04.10)
2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
96151564ee Activate polish language in the language menu
Add Jacek as Maintainer in the about dialog
2018-10-11 06:00:21 +02:00
Christian Hohnstaedt
18672fae2d Convert workingdir separators to native separators 2018-09-13 18:24:29 +02:00
Christian Hohnstaedt
5b0a57ec59 Update documentation 2018-08-19 08:57:29 +02:00
Christian Hohnstaedt
e4f8f00b34 Inspired by #55: Allow manual override of CSR signed/unsigned mark
Via context menu the "Signed" flag may be toggled manually now.
2018-08-17 09:14:26 +02:00
Christian Hohnstaedt
2fc272247e Close #56: Duplicate Serials after Upgrade 2.1.0
Fix default length of random serial from 8 to 64 bit.
2018-08-17 06:07:03 +02:00
Christian Hohnstaedt
410142f358 Close #57: SAN IP not working in 2.1.0
Fix typo
2018-08-17 06:07:03 +02:00
Christian Hohnstaedt
c9cdb5d61c Close #55: Calculate "CSR signed" information from legacy database
XCA-2.x stores the "request signed" information permanently
in the database.
XCA-1.x dynamically calculated this information by looking
for certificates with the same public key.

When converting an XCA-1.x database, requests with a matching cert
are marked signed in the XCA-2.x database.
2018-08-17 06:03:52 +02:00
Christian Hohnstaedt
340b53f4fd Close #55: Add Certificate counter row for requests.
(XCA 2.x - Relationship CSR <-> issued Certificate broken)

This counter is dynamic and not stored in the DB.
In comparison to the signed flag, which is stored and
remains set in the DB, even if all certificates
issued by signing this request are deleted.
2018-08-17 06:00:40 +02:00
Christian Hohnstaedt
3d4c6cfcf5 Add sanity check when loading table-header information
This results in an error message instead of an assertion failure
if the header configuration is invalid.
2018-07-12 17:42:09 +02:00
Christian Hohnstaedt
2682edacfd Close #48 The SKI tickbox isn't generating an SKI extension for CSRs
Since the first support of extensions for CSR (2005),
the Subject Key Identifier has been skipped.
Enable it, while still removing issuer extensions.

Better fix "Automatic X509v3 extensions for CSR"
2018-07-10 23:04:47 +02:00
Christian Hohnstaedt
4e68d40464 Revert "Extend #36: Automatic X509v3 extensions for CSR"
This reverts commit f1dc9b868a.
2018-07-10 05:54:20 +02:00
Christian Hohnstaedt
f1dc9b868a Extend #36: Automatic X509v3 extensions for CSR
Also apply "DNS:copycn" correctly when generating
PKCS#10 CSR
2018-07-07 07:08:23 +02:00
Christian Hohnstaedt
c88b0b7d70 Improve fix for #35: Configurable size of serial number.
Make sure the first octet of the serial is not 0 and not
interpretable as negative.
2018-07-07 06:58:21 +02:00
Christian Hohnstaedt
c1189b0ff4 Add private key icon to the key name
in the certificate and request table
2018-07-06 06:05:40 +02:00
Christian Hohnstaedt
9691496a98 Oid loading: catch OID creation errors 2018-07-06 06:05:31 +02:00
Christian Hohnstaedt
a8f54c82eb Refactor OID loading
The OID resolver now finds oids independent of the capitalization
2018-07-03 18:49:18 +02:00
Christian Hohnstaedt
07cd638537 Use QFile and QString for NID-list reading 2018-07-02 08:25:11 +02:00
Christian Hohnstaedt
bdfa10d4d5 Close #45: Unable to view Public Key
Allow displaying the public key of a certificate
or request without importing it.

When importing certificates or CRLs,
display the issuer if it exists in the database.
2018-07-01 14:58:23 +02:00
Christian Hohnstaedt
d5305d33c7 Check all dates regularily whether a "view" update is neccessary 2018-06-28 14:33:30 +02:00
Christian Hohnstaedt
2f8c25ba6f Replace TR() by QObject::tr() to get catched by lupdate
lupdate does not find TR(), only tr()
2018-06-27 16:23:10 +02:00
Christian Hohnstaedt
dc5199205c Make all dates in columns fancy, still sorting correctly by age
ToolTip shows the pretty formatted local date with time.
2018-06-27 08:56:07 +02:00
Christian Hohnstaedt
acea9e5c21 Fix translation of dates 2018-06-27 07:50:21 +02:00
Christian Hohnstaedt
96d8c5cf37 Generalize handling of DateTime columns 2018-06-26 23:32:40 +02:00
Christian Hohnstaedt
b10b4f7a53 Inspired by #42: display insertion date relative
Easy to find the most recent entry, because it says
"3 seconds ago"
2018-06-25 21:20:25 +02:00
Christian Hohnstaedt
15d33fdcfc Make the dynamic DN entry adaption configurable.
If the option is selected, the behavior from the
previous commit is enabled. Otherwise, the
explicit DN entries stay as configured.
2018-06-21 20:29:45 +02:00
Christian Hohnstaedt
22966937de Close #36: Support adding CN to X509v3 SAN automatically
Translate the special text "DNS:copycn" in the SAN to
the final common name.

Add checkobox "Copy Common Name" to the SAN Edit box,
for a user-friendly editing of the "DNS:copycn"

During certificate creation, an empty common name together with
"DNS:copycn" in the SAN will raise a warning message and the
opportunity to change the settings.

Change the SAN in the HTTP-server XCA template from
"DNS:your.server.name.here" to "DNS:copycn" to already
take advantage of this feature in the default template.
2018-05-19 22:14:08 +02:00
Christian Hohnstaedt
4b2375101b Transform regexp based IP validator into its own QValidator class 2018-05-19 18:10:13 +02:00
Christian Hohnstaedt
f0e6dc1f1b Close #35: Configurable size of serial number.
Allow to configure the previously fixed serial number length
of 64 bit between 8 and 256 bit
2018-05-19 18:09:28 +02:00
Christian Hohnstaedt
efd3bff700 Add missing break in switch 2018-05-16 17:43:03 +02:00
Christian Hohnstaedt
0c8df14b7e Close #27: Configurable certificate expiry warning threshold
Add configuration values in the Options dialog to
control the time when certificates get marked yellow and
the expiration alarm time in calendar entries.
2018-05-11 09:19:12 +02:00
Christian Hohnstaedt
dc36728df8 Generate calender (.ics) files for certificate and CRL expiries
Also support consolidated calendar entries for a CA,
containing the CA, all issued certificates and the CRL expiry dates.
2018-05-10 12:49:59 +02:00
Christian Hohnstaedt
b362ae3593 Const-ify dbheader in column_data() and getIcon() 2018-04-25 09:34:45 +02:00
Christian Hohnstaedt
84fcc9610e Close #25: Certificates are no longer coloured
Fix function signature of "bg_color" to really overwrite
virtual pki_base::bg_color
2018-04-25 08:59:25 +02:00
Christian Hohnstaedt
8d64db6be3 Const-ify remFromCont() 2018-04-24 23:10:46 +02:00
Christian Hohnstaedt
b74642fa09 Const-ify QSqlRecord of restoreSql() 2018-04-24 09:34:34 +02:00
Christian Hohnstaedt
bfe6fbbc43 Close #24: Add LibreSSL support. Tested with LibreSSL 2.7.2 2018-04-22 16:12:04 +02:00
Christian Hohnstaedt
331b79bd9d Close #23: Improve limiting to pattern in certificate tree view
CA certificates that don't match the search pattern, but have
matching childs are shown disabled with internal name.
2018-04-22 07:06:31 +02:00
Christian Hohnstaedt
94c3835ca5 Issue #19 Replace 3DES encryption by AES-256 2018-04-17 12:12:16 +02:00
Christian Hohnstaedt
ee93c576b9 Remove spaces from DN entries 2018-04-10 07:54:58 +02:00
Christian Hohnstaedt
31ab5595d1 Reject 0 key length when generating RSA/DSA keys (related to issue #18) 2018-04-10 06:02:16 +02:00
Christian Hohnstaedt
c43051df12 Improve Use counter acquirement by one SQL statement for all keys 2018-04-09 06:09:55 +02:00
Christian Hohnstaedt
e95198e775 When overwriting an index.txt file, truncate it. 2018-04-09 05:21:22 +02:00
Christian Hohnstaedt
cd118e4e72 Fixup for "Assure traditional file format if PKCS#8 NOT selected"
Also RSA and DSA keys were marked as EC PRIVATE KEY.
Add break to the switch statement
2018-04-09 05:18:19 +02:00
Christian Hohnstaedt
3ee2fc4015 Document current working directory in the About dialog 2018-04-09 05:17:11 +02:00
Christian Hohnstaedt
ec5507412e Fix private key import of PKCS12 and PEM keys 2018-04-06 06:01:05 +02:00
Christian Hohnstaedt
3073bcd105 Fixup previous commit to build on Qt4 2018-04-04 22:39:50 +02:00
Christian Hohnstaedt
4c75d43b87 Assure traditional file format if PKCS#8 NOT selected 2018-04-04 19:24:16 +02:00
Christian Hohnstaedt
d0eb95f784 Improve error messages by adding SqlItemId information 2018-04-04 19:17:05 +02:00
Christian Hohnstaedt
5fdd84c82c Fix Importing PKCS#12 and PKCS#7 files 2018-03-30 21:34:00 +02:00
Christian Hohnstaedt
6f85548c07 Drop getClassName() 2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
7c4be863f1 Constify x509name and use getMostPopular() when filling the internal name 2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
2c20bd109a Constify and Pure-Virtual pki_base and derived classes 2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
6cf72a38e0 Remove superflous function and mark decryptKey as pure virtual 2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
3eef4bd12b Fix translation artefacts.
No need to translate "X Certificate and Key management",
"Form", "Dialog" or "TimeInput"

"Select Token" and "New Key" window titles were never shown.
Remove them.
2018-03-28 08:13:22 +02:00
Christian Hohnstaedt
e3349aefb0 Accept driver that don't support transactions
Improve report of transaction errors.
2018-03-22 20:26:22 +01:00
Christian Hohnstaedt
64c9c5ccab Add table prefix to be prepended to each table
This allows multiple independent xca databases in one database
2018-03-19 06:14:06 +01:00
Christian Hohnstaedt
139d8509b4 Fix crash during PKCS#12 export
initialize property variable "key"
and duplicate the sqlItemId to enable access to the private key.
2018-03-12 21:06:21 +01:00
Christian Hohnstaedt
0776ead694 Acceppt empty password for private key decryption
d2i_PKCS8PrivateKey_bio does not accept
passwords with 0 length for whatever reason.
2018-03-12 16:15:30 +01:00
Christian Hohnstaedt
f1e0a867fe Fix includes for func.cpp windows build 2018-03-11 19:32:56 +01:00
Christian Hohnstaedt
4eeb856c73 Make hex the default input / output qstring of asn1integer 2018-03-11 10:02:14 +01:00
Christian Hohnstaedt
d22cfb0b53 Allow editing of revocations 2018-03-11 09:31:16 +01:00
Christian Hohnstaedt
0ed9f6926c GitHub Bug #5: Exporting a private key results in too-permissive permissions
Add umask(077) for key export
2018-03-10 14:43:36 +01:00
Christian Hohnstaedt
421ab5840a Minor bugfixes: PostgeSQL does not like setting an integer to "true"
Display renamed request in the NewX509 dialog correctly in the dropdown
2018-03-10 10:45:03 +01:00
Christian Hohnstaedt
6e432238e7 Generalize, simplify and unify settings management
Add settings class to access the settings table in the database
Cache values and improve database writes.
Options dialog simplified
Replace getSetting / storeSetting
Unpack option flags to rows in the settings
2018-03-10 09:04:54 +01:00
Christian Hohnstaedt
1b28d9ab54 Fix display of dates in the Certificate details
The GMT time was displayed as local time
2018-03-08 22:15:19 +01:00
Christian Hohnstaedt
c62339e1ce Adapt Certificate Index creation to the new database capabilities 2018-03-07 23:00:58 +01:00
Christian Hohnstaedt
4288aafe92 Improve automatic commenting actions 2018-03-07 20:51:46 +01:00
Christian Hohnstaedt
4867cfb8ab Improve "Dump database" filename 2018-03-07 05:49:46 +01:00
Christian Hohnstaedt
9cef2415c9 Update slot_label when renaming items on the token or managing the token 2018-03-06 21:28:38 +01:00
Christian Hohnstaedt
3481a63db9 Fix PEM file loading 2018-03-06 21:27:43 +01:00
Christian Hohnstaedt
80471cd3f3 Small fixes: MySQL does not like "DEFAULT (0)" 2018-03-06 16:45:42 +01:00
Christian Hohnstaedt
5ef451ee91 Document in the comment if a public key has been completed by an imported private one 2018-03-06 16:42:28 +01:00
Christian Hohnstaedt
c2007a13ee Minor fixes: Store token in DB, Load settings, 2018-03-06 09:02:06 +01:00
Christian Hohnstaedt
79d6aa0b10 Improve message boxes. Always display plain text
And show a message if a database connection failed.
2018-03-05 19:47:05 +01:00
Christian Hohnstaedt
14421f4ed3 Update Issuer and Key name in the Certificate, Request and CRL details
after editing double-clicked element.
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
545c955616 Add "Primary key" column to show the items internal id
Especially helpful if you want to lookup the item
in the database manually.
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
c14e54c830 Minor fixes: Date from database and affected items
Correctly initialize undefined date from database
Clear list of affected items after commit.
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
879d6bb17c When searching for items, also search in the new "comment" field. 2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
64d64d5130 Allow editing key name and comment in the key details 2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
3e86a1daaa Fix Minor errors 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
af0e0a75b9 Drop dnPolicy for now 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
d079dbde09 Collect affected items 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0f582044e2 More transaction 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
491a01ed1f When signing a request note it in the request-comment 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0b82028644 Add "Legacy Database" as additional source 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
84e4301f6d Tell the user if the SqLite driver is missing 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
e6c92ce890 Improve transactions, fix CA template and CRLdays import
Make ItemCombo a template class
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
d36e6eb0cb Implement nested transactions.
The DbTransaction class automatically rolls back when the scope
is left (destructor) and no commit happenned.

Every transaction begin will increment the counter,
each commit/rollback will decrement it. Only if all transactions
finished with a commit, a final database commit will be performed.
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
24d1f85a26 Make use of C++ templates for more type-safety 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
dc75fa0171 Add token as item source, minor fixes
Use dynamic cast for sqlSELECTpki()
Fix Double-click links in cert details
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0745e18da2 Allow to edit item properties 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
a3900b1473 Several fixes for templates, key encryption etc. 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0921b63763 Fix indentation error 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
3f016c62e7 Fix minor problems during db open and key import 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
07594d1edd Rebase on master 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
fed2dd711a Minor fixes 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
84f25048a7 Remove xca_db_stat application 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
e1b982a346 Replace printf by qDebug 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
af57cc8f13 Extract app not needed anymore 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
431076c90e Change private key encryption in the database to PKCS#8 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
d50dbbd726 Create indexes 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
a545659e1a Add Source column, fix Revocation management 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
fbde63e98d Add Views and a concept of schema updates 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
00145600a7 Improve usecounter performance 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
fc7fc357ac Support opening remote databases MySQL and PostgreSQL 2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
2a0a4630ae Extend authority table and fix CaProperties 2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
fe6062f16e No more increasing serials. Only random serials. 2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
3c981a6742 Avoid updateAfterCrlLoad 2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
cac6b39877 Fix bug in delition order 2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
e624743494 Add PKI Source: generated, imported, transformed 2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
4598ddb4de Convert QByteArray.base64() to QString before writing it to the DB 2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
a75eb6ebd8 Avoid LastInsertID 2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
4b3ee2c705 Switch database format to SQL(ite)
This is a large squash of many small commits.

Allow porting data from the legacy format to SQL.
Store Binaries base64 encoded and use db->transaction
Update password hash to be 8000 x SHA512 with 8 byte Salt
Add revocations table and fixup CRL generation
Add comment and insertion date columns

Fix column saving, remove trust, add XcaDialog
Allow changing the internal name and comment in Cert/Req details view
Extend Comment functionality, Replace About.ui by XcaDialog.ui
2018-03-05 07:42:36 +01:00
Christian Hohnstaedt
b63f50b28b Add more error checks and remove code duplication 2018-03-01 22:10:52 +01:00
Christian Hohnstaedt
365507b36e SF Bug #122 isValid() tried to convert the serial to 64 bit
With OpenSSL 1.1.0 this results in an error message
if the serial was too long.
With OpenSSL 1.0.x it didn't.
2018-03-01 22:06:23 +01:00
Christian Hohnstaedt
bdbaa0a946 Support Dragging certificates and other items as PEM text
Also dragging PEM test into XCA opens the import Dialog
2018-02-20 23:47:17 +01:00
Christian Hohnstaedt
4b9b8e9973 Add more openssl error checks during database load to tackle Bug #122 2018-02-13 11:47:22 +01:00
Christian Hohnstaedt
eb6382d6aa Remove SPKAC support. Netscape is not of this world anymore.
I discovered some bugs in SPKAC handling and fixing them was hard.
Because of this bugs noone may have used the feature in the past.

Remove it.
2018-02-13 11:47:21 +01:00
Dancho Penev
b0d131e79a SF bug #124 Wrong assumptions about slots returned by PKCS11 library
When using PKCS11 library to manage smart cards the code assumes
that all slots returned by the library call are not empty.
In some cases Gemalto's library returns list of slots in which the
first one is empty and the second one is occupied by the smart card,
this causes xca to report an error and isn't able to use the smart card.
2018-02-07 11:10:04 +01:00
Christian Hohnstaedt
3f35cdccf8 Cleanup the OID text files, remove senseless aia.txt
- Remove all aia.txt from the Code, Documentation and ToolTip
- Add an Operating system dependent help hint
- Replace unix LF by DOS CR-LF for windows installation
2018-02-01 00:05:40 +01:00
Christian Hohnstaedt
8333482eef Improve behavior regarding additional OIDs
Depending on the OpenSSL version some OIDs are known, some are not.
When reading "oids.txt" file and adding the new OID definitions:
 - Silently skip definitions that are 100% identical to the OpenSSL values.
 - Give a hint to change identifiers that are used for a different OID
 - Give a hint about definitions that differ to remove them from the file.
   Also accept them as Alias when reading dn.txt and eku.txt
2018-01-31 20:15:07 +01:00
Christian Hohnstaedt
fc4bdaf196 Refine and document Entropy gathering 2018-01-29 14:57:07 +01:00
Christian Hohnstaedt
715b263998 Indicate development and release version by git commit hash
Fix "qmake" build for qt4 and qt5
2018-01-28 11:36:37 +01:00
Christian Hohnstaedt
1d2a1b18c4 Fix dumping private keys during "Dump database"
If the database password is empty, dumping private keys
resulted in an error message.

Fix this by setting the encryption algorithm to NULL if
the password is empty.

Additionally throw the error after closing the filedescriptor.
2018-01-27 12:52:17 +01:00
Christian Hohnstaedt
27482fc080 Fix Null pointer exception when importing PKCS#12 with OpenSSL 1.1.0
Setting the EVP_PKEY type deletes the key with OpenSSL 1.1.0

Reported by Perederyaev Ivan. Thank you.
2018-01-27 12:48:13 +01:00
Christian Hohnstaedt
eaabb2a28d SF Bug #110 Exported private key from 4096 bit SSH key is wrong
Actually, it just differs. It is PKCS#8 instead of PKCS#1
2018-01-06 21:18:31 +01:00
Christian Hohnstaedt
0ba41583fb SF Bug #109 Revoked.png isn't a valid image
It was unused and did not harm. No functional/optical impact.

Delete image and all ist references
2018-01-06 21:17:15 +01:00
Christian Hohnstaedt
704d98b071 Remove duplicate X509_CRL_set_issuer_name()
Found by "Patrick Monnerat <patrick@monnerat.net>"
Thank you
2017-11-29 08:01:19 +01:00
Christian Hohnstaedt
de7b368355 Of course we support Big Endian machines. Remove debugging mechanism
At least during coding. I have not Big Endian platform to
verify the expression above.
2017-11-23 12:44:02 +01:00
Christian Hohnstaedt
8867727926 Refuse overwriting unknown files 2017-11-17 15:53:30 +01:00
Christian Hohnstaedt
2bced828de Translation: Re-translate the OID resolver in case of a language change 2017-11-17 09:06:56 +01:00
Christian Hohnstaedt
8ebaa683ff Translation: Also translate validity dates to the configured language 2017-11-17 09:06:56 +01:00
Christian Hohnstaedt
b9bd5a9344 Fix GCC-6 warning -Wmisleading-indentation 2017-10-25 09:21:12 +02:00
Tino Mettler
f0699d055f Fix further spelling errors found by lintian packge checker 2017-10-24 12:15:58 +02:00
Christian Hohnstaedt
d1a34b8329 Fix Hash algorithm when converting certificate to PKCS#10
Use the one from the certificate instead of SHA1
2017-10-04 23:21:02 +02:00
Christian Hohnstaedt
cefb140601 Switch to Qt5 for Windows build and installation
Don't depend on htonl() and friends to avoid lwsock32
Fixup WIN32 define to use the Qt definition
2017-07-17 09:27:46 +02:00
Christian Hohnstaedt
f12c3ca8aa Improve Copy&Paste behavior: Accept Ctrl-V and MousePaste on MainWindow 2017-07-15 06:51:37 +02:00
Christian Hohnstaedt
ac780d3e77 Fix PEM_BIO loading by using QByteArray instead of BIO and fmemopen 2017-07-15 06:51:37 +02:00
Christian Hohnstaedt
5fbd102493 Fix for MacOS X builds 2017-07-15 06:51:37 +02:00
Christian Hohnstaedt
1ae80c1af7 Do not apply the default template when creating a similar cert 2017-07-12 19:35:21 +02:00
Christian Hohnstaedt
22b441046a SF: #120 Crash when importing CA certificate for certificates which already exist
The QAbstractItemModel is simetimes called with column index -1
Catch those calls.
2017-07-12 19:35:21 +02:00
Christian Hohnstaedt
4ef4c9ad87 SF #116 db_x509.cpp:521: Mismatching allocation and deallocation: cert
free(cert) -> delete cert
2017-07-10 09:12:37 +02:00
Christian Hohnstaedt
b22d82a3f9 OSSL 1.1 vs. 1.0: Windows support 2017-07-08 06:57:04 +02:00
Christian Hohnstaedt
8429817bf0 Typo in openssl-compat 2017-06-30 21:13:06 +02:00
Christian Hohnstaedt
d14b3bf5ed OSSL 1.1: Windows does not know "fmemopen()" 2017-06-19 09:52:33 +02:00
Christian Hohnstaedt
dda100c100 OSSL 1.1 vs. 1.0: Private keys 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
f7e485393c OSSL 1.1 vs. 1.0: EVP 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
a279a8e43e OSSL 1.1 vs. 1.0: Cleanup CRL 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
413ba8bff3 OSSL 1.1 vs. 1.0: Cleanup CRL extensions 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
3f20bce3f9 OSSL 1.1 vs. 1.0: Drop some #ifdef from the pkcs11 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
9d2ed957dd OSSL 1.1 vs. 1.0: Purge BIO_QBA_mem_buf() 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
7f36322f0b OSSL 1.1 vs. 1.0: Extensions, Cert Details 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
62a1711c3b OSSL 1.1 vs. 1.0: Revocations 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
39c2e86ee0 OSSL 1.1 vs. 1.0: Improve Key generation 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
f0c7badf0b OSSL 1.1 vs. 1.0: Store sigAlg as NID instead of Object 2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
077c061d0e OSSL 1.1 vs. 1.0: Add openssl_compat.h centralizing the #ifdef Hell 2017-06-19 08:33:29 +02:00
Patrick Monnerat
ad6c2baae5 Add support for OpenSSL 1.1.0
The API changed heavily. New functions arrived, old functions
disappeared and many structures became opaque.

This version of the patch implements pkcs11 signing as follows:
- openssl < 1.0.0: rsa & dsa without engine
- openssl 1.0.x: rsa, dsa & ec with engine
- openssl >= 1.1.0: rsa, dsa & ec without engine

In the operation, we therefore also gain implementation of dsa signing for openssl < 1.0.0 (ec disabled because EC_KEY_METHOD was not yet invented!).

I've given up trying to use a PKEY_ENGINE with openssl 1.1: seems not possible anymore.

I've succeeded compiling the patched xca with openssl 0.9.8n, 1.0.2j and 1.1.0e.
I've successfully tested pkcs11 signing using softhsm with openssl 1.0.2j and 1.1.0e.

The patch also removes gcc7 new warnings.
2017-06-19 08:32:39 +02:00
Adam Dawidowski
0d34bc1c1c Extend generating an OpenSSL "index.txt"
Updated patch adds another export option automating the creation
of multiple index.txt files to be used with multiple ocsp responders.

New export option is available via command line (-I index.txt) and
the Extras menu (Extra->Export Certificate Index hierarchy).

The option causes the creation of an index.txt file containing
index records for all the children certificates of a parent.
The filenames are generated using the supplied name as prefix
and append a dot and the simplified Internal Name
(the Internal Name stripped of non-alphanumeric characters except underscores).
2016-09-06 20:03:55 +02:00
PF4Public
c0130feafa Some pedantic edits 2016-04-09 06:40:39 +02:00
Adam Dawidowski
e94e9133b1 Support generating an OpenSSL "index.txt"
XCA currently lacks support for generating an index.txt.
Such a file gets created and maintained when using CA
features in openssl. As mentioned here:
https://sourceforge.net/p/xca/discussion/209946/thread/6cbc727c/#2310
such a file can be used by Openssl's built-in OCSP responder.
Additionally, it can be used for configuring a cron job for
reminding of certificate expiration.

Certificate index export is added in 3 places:
 - command line (-i index.txt),
 - the Extras menu (Extra->Export Certificate Index) and
 - the selected file(s) export option in the context menu
   on the Certificates tab (Export->File, Export Format:
    Certificate Index file).

Please note that SubjectDN generated by this feature has
different formatting than the one generated by openssl.
2016-04-09 06:40:39 +02:00
Christian Hohnstaedt
fa38a21a04 Merge Release 1.3.2 based fixes from Tino Mettler and Christohper Knadle 2016-02-11 09:09:51 +01:00
Christohper Knadle
2f3a1de7ac Fix spelling errors found by lintian packge checker 2016-02-11 09:08:38 +01:00
Christian Hohnstaedt
806312800d Thales nCipher key generation changes for EC and DSA keys
Developed and tested by
 Mak, Mcken <Mcken.Mak@thalesesec.com>

Thanks!
2016-01-16 07:54:54 +01:00
Christian Hohnstaedt
735a74f873 On unix use the default clipboard and mouse-selection for export 2016-01-16 07:34:21 +01:00
Christian Hohnstaedt
126fdec51c Improve language handling 2015-10-02 16:45:07 +02:00
Christian Hohnstaedt
78e4207f2e Fix database password change on Windows
Reimplementing the simple unix "mv" command on Windows is PITA!

Renaming an open file -> Error!
Renaming to an existing file -> Error!
Atomicity: No
2015-09-23 10:42:05 +02:00
Christian Hohnstaedt
e5541c6d67 SF. Bug. #81 Make xca qt5 compatible
Extend XCA to also compile against Qt5
Remove directory from Qt includes
2015-09-17 18:42:42 +02:00
Christian Hohnstaedt
2f61c8c711 SF. Bug. #107 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
Gracefully handle malformed Netscape extensions i.e.
Expected IA5 strings not IA5 tagged
2015-09-17 13:02:48 +02:00
Christian Hohnstaedt
6d9c62867f Opening a database with unknown CRL causes endless loop
See discussion on SorceForge: "v1.3.0 freezes on Windows 7"

If a CA certificate with a matching subject but missmatching key
for a CRL exists, XCA enters an endless loop.

Correctly iterate over signer certificates when searching
the signer of a CRL.
2015-08-21 08:33:37 +02:00
Christian Hohnstaedt
d55eb917e2 Silence compiler warnings about unused parameters 2015-08-11 07:17:56 +02:00
Christian Hohnstaedt
88443e5a9b OpenSSL 1.0.x still has the 0.9.8 PEM_write_bio() prototype 2015-05-20 18:28:13 +02:00
Christian Hohnstaedt
85d2a26aa9 Fix all fopen() calls to always use "wb" or "rb"
fix PKI item autodetection
Fix compiler warning because of a changed OpenSSL 0.9.8/1.0.1
  "PEM_load_bio()" API change
2015-05-20 13:14:21 +02:00
Christian Hohnstaedt
68cf3615df Fix saving a single certificate 2015-05-20 13:14:21 +02:00
Christian Hohnstaedt
68781ff47f Fix compile errors 2015-05-19 19:16:17 +02:00
Christian Hohnstaedt
279a6f3fdb Update translation 2015-05-19 06:15:38 +02:00
Christian Hohnstaedt
854d0dbde5 Minor fixes, remove debugging output 2015-05-18 17:51:20 +02:00
Christian Hohnstaedt
825210f606 Minor fixes
double fclose() does not harm on Mac, but on linux
Unify export to token
2015-05-18 05:58:39 +02:00
Christian Hohnstaedt
c00db626c5 Support editing the CRL number when generating CRLs 2015-05-17 13:22:47 +02:00
Christian Hohnstaedt
75a6d117f3 Refactor context menu
Better support multiple selections
 - Export all selected items into one PEM file
 - Batch Revoke/unrevoke/renew of many selected certificates
   of the same issuer
 - allow exporting templates as PEM

Add Feat. Reg. #83 Option to revoke old certificate when renewing

Always put all signed certificate to the newest CA.
If a CA certificate is renewed, all certificates issued by
the old CA are now shown as signed by the new one.
2015-05-17 09:17:04 +02:00
Christian Hohnstaedt
5b40ac664b Add Null-pointer-check and add support for OSCP_noCheck 2015-05-14 12:58:05 +02:00
Christian Hohnstaedt
c691c1cca5 Suuport nameConstraints and policyMappings when creating OpenSSL conf from cert 2015-05-14 12:58:05 +02:00
Christian Hohnstaedt
5fdb362f8c Support InhibitAnyPolicy and PolicyConstraint extensions
... when exporting certificates to templates or OpenSSL configs
2015-05-04 17:20:45 +02:00
Christian Hohnstaedt
5c6bb6c795 Fix typo 2015-04-21 10:17:32 +02:00
Christian Hohnstaedt
90f351b2cb Refactor CRL handling 2015-04-20 18:25:59 +02:00
Christian Hohnstaedt
25a53441e9 Certificate export: Add option to export selected certificates to PEM or PKCS#7
Using the context menu only handles the current item.
This is now reflected by resetting the selection in case of
a context menu event
2015-04-15 08:41:29 +02:00
Christian Hohnstaedt
58142b487c Fix syntax errors in documentation and english phrases
Thx Patrick Monnerat <Patrick.Monnerat@datasphere.ch>
2015-04-10 19:27:05 +02:00
Christian Hohnstaedt
698c10216f Add option for disabling the very very legacy Netscape extensions
Maybe this setting will become the default in future releases....
2015-04-09 18:49:03 +02:00
Christian Hohnstaedt
c5833ebe69 Separate Certificate revocation and CRL expiry in the Columns 2015-04-09 15:06:46 +02:00
Christian Hohnstaedt
acd1c92dfb Fixup Entropy file reader to be non-blocking.
And add a fix for windows that doesn't
know about 'non-blocking'
2015-04-08 20:53:18 +02:00
Christian Hohnstaedt
2909e79317 Move entropy functions into new class
Read and write .rnd file during start and exit
2015-04-08 06:54:55 +02:00