Christian Hohnstaedt
1e544161f6
Eliminate the use of "mainwin" in lib/db_*
2020-05-08 11:59:09 +02:00
Christian Hohnstaedt
7c65a786ea
Revamp database management
...
The global variable "Database" of class xca_db
can be used by any other class to access. No need
to provide it.
The "xca_db" class managed the "database_model" pointer.
Accessing the name of the current database has been unified.
2020-05-08 07:47:15 +02:00
Christian Hohnstaedt
93a7c6a9a3
Implement option --list-curves and display EC curves
2020-05-06 18:32:37 +02:00
Christian Hohnstaedt
9b201566e2
Improve on cmdline, console, unicode and windows CMD
...
Improve Windows registry functions
Use *A postfix function explicit becaus e we don't expect
unicode characters.
Also simplify "console_write()"
2020-05-06 18:32:27 +02:00
Christian Hohnstaedt
d1c0970ea1
BioByteArray: Add size() method
2020-05-06 18:08:36 +02:00
Christian Hohnstaedt
b5c9d645e3
More native separators when displaying file names
2020-05-06 17:57:09 +02:00
Christian Hohnstaedt
b2ab7570b8
Minor fixxes and constifies
2020-04-30 18:47:28 +02:00
Christian Hohnstaedt
0f7465dcc5
Add convenience function to convert QModelIndex to pki_base *
2020-04-30 18:46:08 +02:00
Christian Hohnstaedt
03633d7a8a
Provide db class name through constructor
2020-04-30 18:44:36 +02:00
Christian Hohnstaedt
a3344100e3
Drop FOR_ALL_pki() makro and use a foreach() loop
...
The foreach loop iterates over all items of a type.
The iterate method is now superflous
2020-04-30 18:40:49 +02:00
Christian Hohnstaedt
8f46d238e0
Replace __ME makro by pki_base QString() operator
...
Now a pki item can transform itself to a QString for debugging
2020-04-30 18:37:48 +02:00
Christian Hohnstaedt
5a64725556
Move item store from db_base into separate class "pki_lookup"
...
Since also pki_base and other classes need to access them.
2020-04-30 18:37:25 +02:00
Christian Hohnstaedt
f889efc4cb
Merge branch 'master' into develop
2020-04-30 18:34:16 +02:00
Christian Hohnstaedt
1f2429e677
Avoid filedescriptor leak
2020-04-29 13:29:01 +02:00
Christian Hohnstaedt
76e3f86783
Close #191 : OID LN differs warning popups at startup
...
OpenSSL fixed the 2 LN with commit:
648b53b88e
in OpenSSL 1.1.1e.
Follow my own advice and delete them from the oids.txt
together with all other OIDs present in OpenSSL
since at least version 0.9.8
Also do the initOIDs after creating the QApplication to
avoid qAbort() when creating the warning (introduced after 2.2.1)
2020-04-27 15:03:36 +02:00
Christian Hohnstaedt
0ac3b2daca
Improve and fix VERSION_ITERATION
2020-04-27 15:03:36 +02:00
Christian Hohnstaedt
7d5bb9ca4f
Fix newline handling
2020-04-07 15:54:16 +02:00
Christian Hohnstaedt
5cb1b45d81
console_write: takes a QByteArray instead of printf()
...
Good Windows Unicode font:
https://math.berkeley.edu/~serganov/ilyaz.org/software/fonts/
2020-04-06 22:08:04 +02:00
Christian Hohnstaedt
dd46ff7201
Fix Copy&Paste'o: Put issuer into issuer property and not subject
2020-04-06 22:07:57 +02:00
Christian Hohnstaedt
ea453d4336
Encapsulate all BIOs in the BioByteArray class
...
If we have a QByteArray (ba) and must provide it to
a BIO* expecting OpenSSL function, the following
construct provides it: BioByteArray(ba).ro()
directly providing the QByteArray buffer as BIO
It also supports mixed writes:
BIO_write(bba, buf, size)
bba += QByteArray
2020-04-06 22:07:57 +02:00
Christian Hohnstaedt
4d95912d51
Add console_write() to print also on CMD
2020-04-05 22:45:11 +02:00
Christian Hohnstaedt
b7d3e6a3cc
Merge branch 'master' into develop
2020-04-05 13:49:01 +02:00
Christian Hohnstaedt
fb5ee14911
Improve PKCS11 library loading for portable app
2020-04-05 13:12:09 +02:00
Christian Hohnstaedt
a9a4c2b2d6
remote database: Dont show error if the password was empty
...
Otherwise, first an error message is shown and then
a password is asked.
2020-04-05 13:08:47 +02:00
Christian Hohnstaedt
9d7275ef31
Accept missing "dbhistory" file
2020-04-05 10:59:00 +02:00
Christian Hohnstaedt
c528c37986
Merge branch 'master' into develop
2020-04-05 10:58:47 +02:00
Christian Hohnstaedt
4314b0ead9
constify slotid
2020-04-05 09:16:12 +02:00
Christian Hohnstaedt
500f11c9b3
Get rid of filename2bytearray and QString2filename
...
We now use QFile or its derivate XFile, who smoothly
handle unicode filenames also on windows.
The lt_dlopen() only handles "char *" not wchar_t.
Try to convert the filename with all known codecs
until we can open it.
filename2QString() remains to differently encode
filenames provided on the commandline on Windows.
2020-04-05 09:16:12 +02:00
Christian Hohnstaedt
2d0980d4f6
Use pkcs11_lib_list as model for Options:pkcs11list
...
Change pkcs11List from QListWidget to QListView
The pkcs11_lib_list holds the data of the loaded libraries.
For the model a QList "model_data" is used to
hold indexes into QList dirs to allow duplicates,
moves and removes.
On windows it now displays the paths with \ separators.
2020-04-05 09:16:12 +02:00
Christian Hohnstaedt
296ff59f3c
PKCS11 library list: Don't get confused by C: when expecting 1:
2020-04-03 21:56:37 +02:00
Christian Hohnstaedt
5543ec2fb8
Merge branch 'master' into develop
2020-04-02 07:35:18 +02:00
Christian Hohnstaedt
b41d322069
Refactor native separators / and \ on windows.
...
Always only use forward slash /
Drop all "QDir::separator()" and "nativeSeparator()"
functions. Only use it where filenames are displayed for the user.
2020-04-02 06:12:47 +02:00
Christian Hohnstaedt
66a85497b7
Improve development version calculation as 4th digit
...
The plus sign was not compatible with the WIX toolset.
The 4th digist is the number of commits since the last release.
For a tagged release it is not 00, but empty.
2020-04-01 22:56:53 +02:00
Christian Hohnstaedt
096e57ec8c
Close #70 : cant open ics file in ical on macos mojave
...
Fixed syntax errors in the ICS file.
Verified by http://ical-validator.herokuapp.com/validate/
Thanks for the service.
2020-04-01 12:29:55 +02:00
Christian Hohnstaedt
d54aa116db
Avoid unused variable warning for OpenSSL 0.9.8
2020-03-29 22:33:57 +02:00
Christian Hohnstaedt
524aff97b8
Load OID lists. Fixup for c89b6aff
2020-03-29 22:33:57 +02:00
Christian Hohnstaedt
799d3262b0
Reactivate translation of x509 expressions
2020-03-29 22:33:57 +02:00
Christian Hohnstaedt
4f1103a64f
Close #72 : Add checkbox for OCSP staple feature
...
Also support them in XCA template and transformation from
certificate and request.
2020-03-29 22:23:21 +02:00
Christian Hohnstaedt
9c55caf82f
Merge branch 'master' into develop
2020-03-23 06:53:06 +01:00
Christian Hohnstaedt
149ecda63c
Fix index-hierarchy functionality
...
create target directory and name feature "hierarchy"
2020-03-23 06:39:30 +01:00
Christian Hohnstaedt
852da61836
Fix array access
2020-03-22 08:12:38 +01:00
Christian Hohnstaedt
8cf138b409
Drop debugging code
2020-03-22 08:12:38 +01:00
Christian Hohnstaedt
92846d6b38
Close #174 : Microsoft's PVK RSA private key format
...
Support Import and export private and public PVK keys.
2020-03-22 08:12:38 +01:00
Christian Hohnstaedt
f244cec5d3
Drop functions from legacy database modul
...
Only read-functions are required for an
upgrade
2020-03-20 16:29:43 +01:00
Christian Hohnstaedt
928ff6458c
Improve and fix qDeleteAll()
...
qDeleteAll() does not clear the QList.
Add it, if necessary.
Use dynamic_cast where appropriate
2020-03-20 16:29:42 +01:00
Christian Hohnstaedt
b8b368d787
hashNum() is an unsigned integer
2020-03-19 20:40:36 +01:00
Christian Hohnstaedt
9183f300c8
Add support for validating a keyjob
...
In case of an invalid keyjob bail out.
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
919f4f6b23
Parse keytype uppercase to also allow "rsa:2048"
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
ee7739baa6
Improve detection of commands enforcing no-gui
...
provided cmdline parameter are handled as abbreviated
parameter.
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
7a5936eb9f
Replace malloc/free by new/delete
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
31088b608c
cmdline help move the asterisk to the front
...
indicating the requirement for a database when using this option.
2020-03-18 05:26:16 +01:00
Christian Hohnstaedt
7babd609be
Drop unneeded pki_base::insert()
...
Insert / append does not matter,
because the rows are sorted by columns anyway.
2020-03-17 05:13:35 +01:00
Christian Hohnstaedt
51ffe4e43e
Drop functions from legacy database modul
...
Only read-functions are required for an
upgrade
2020-03-17 05:07:59 +01:00
Christian Hohnstaedt
9845a00ca3
Store default database and recently opened file as UTF8
2020-03-17 05:07:46 +01:00
Christian Hohnstaedt
00bf676f0a
Fix building for Windows
...
No ioctl() on windows.
Avoid initialisation race of static arrays
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
595cf9a722
Drop connNewX509() signal and slot
...
in the past it was used to connect the NewX509 dialog
with requests keys and certs.
The NewX509 dialog knows mainwin since some time
and thus can connect itself to models and views
mainwin: use model<T>() instead of models->model<T>()
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
af3816a7b0
Fix building against OpenSSL 0.9.8
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
dcd2e1a223
Replace typeid by dynamic_cast where appropriate
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
ef9b3aff3d
Drop superflous includes from header files
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
2f917237bc
Close #157 Generate and export CRLs from commandline
...
Enable key generation and CRL generation on the commandline
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
aacd9ee5f6
Make XcaProgress and WAITCURSOR cmdline compatible
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
a48ea10e3d
Split key generation and data-collection-UI
...
Use the key job to transfer the information
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
a6ec3a9319
Minor fixes without functional changes
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
f1fd65c9cf
Add keyjob (TBC)
...
Invent keyjob
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
77519936e0
Invent keytype class for mapping type mechanism and name
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
241d7e9c7f
Move newItem() function from model to view
...
Move CRL and Template data collection via UI to
the appropriate views
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
3dd34a61bc
Move "showPki()" from the model class to the view
...
The displaying function requires UI.
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
d0d387b03e
Directly display the error instead of signaling others
...
The XCA_ERROR() is console-compatible and can be used
without GUI
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
c3abd640fc
Fix certificate assignment importing a CA certificate
...
Fix finding our unassigned certificates when importing a CA
(issuerSqlId may be QVariant(int, 0) depending on the database)
Reassign certs from an older CA to the imported one.
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
c098b235ce
Minor fix. No Message when exiting
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
10857e3e0c
Support item import from the commandline
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
aa55a68782
Let pki_pkcs12 and pki_pkcs7 inherit from pki_multi
...
And ImportMulti handles pki_multi sufficiently
and does not need to know about pkcs12 or pkcs7
pkcs12 and pkcs7 don't need: print() getCa() addCaCert() numCa()
it is handled by pki_multi()
Take advantage of the power of dynamic_cast<>() instead of using
typeid()
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
1278ef9379
Add self-accounting of items for debugging
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
19eafe1739
Improve and fix qDeleteAll()
...
qDeleteAll() does not clear the QList.
Add it, if necessary.
Use dynamic_cast where appropriate
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
98593e7462
Compatibility fixes for QT4 and OpenSSL 0.9.8
...
Need to drop support for those ancient libs.
Not, yet.
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
55d1693015
Improve printing of cmdline items
...
Unify --print by collecting all properties
Add --pem to print the item in PEM format
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
1544065133
Extend --print and --text functionality
2020-03-13 12:13:27 +01:00
Christian Hohnstaedt
64ef856546
Add flag to option list, declaring whether a database is required
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
c89b6aff29
Move NID lists for ExtendedKeyUsage and DistinguishedName
...
into lib/oid.h
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
c5208f1cd7
Consolidate headers, unguard delete operator
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
e4d0ab8f8e
Refactor Image and icon ressources
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
7d0ab9d787
Add pki_XXX(const pki_XXX*) constructor
...
pki_XXX(const QString) -> (const QString &)
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
b2a69f3586
Several fixes of previous commit
...
Passwd::cleanse() also resets the password size
db_base::flushLookup() now deletes all items
and pki_base does not anymore.
Drop TRACE
Colorize pki_base::print()
Set and inherit filename of loaded items
Add print() method to pki_pkcs12
and constify its methods
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
a90d7b5b0d
Improve password input handling
...
Unify password results
Retry on password verification error
Honor the users wish to exit
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
30824964a2
hashNum() is an unsigned integer
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
9da73073c8
Create CRL by providing a crljob, describing the parameters
...
The GUI will prepare such a job and the cmdline can do so, too.
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
089c7d39ef
Improve console password input
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
176c2f8169
Improve password input and handling
...
Use the Passwd class instead of QString
Move password input into the database model
to be available for commandline use.
Repeat in case of wrong password
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
c1ea126efe
linewrap in help
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
113a201d39
Separate database from Mainwin for better cmdline support
...
New classes:
- database_model: Manage the database tables (keys, req, cert, crl, templ)
extracted from widgets/MW_database.cpp
- arguments: parse commandline, dynamically create help text
2020-03-11 07:19:56 +01:00
Christian Hohnstaedt
a1fedfaf9e
Fix building against OpenSSL without EC.
...
This commit amends b982245995
which broke the NO_EC build
2020-03-11 05:56:54 +01:00
Christian Hohnstaedt
176e26e390
Close #170 xca-portable-2.2.1 cannot change language
...
Use GetModuleFileNameW() and RegGetValueW()
returning the path as UTF-16 encoded unicode.
entropy: Use QFile inherited class for file access
This allows wchar_t encoded file names and paths
on windows.
So glad not having to deal with wchar_t / UTF-16 otherwise,
but using QString and UFT-8. The destiny of early adopters....
2020-03-11 05:49:18 +01:00
Christian Hohnstaedt
84560e26e1
Fix certificate assignment importing a CA certificate
...
Fix finding our unassigned certificates when importing a CA
(issuerSqlId may be QVariant(int, 0) depending on the database)
Reassign certs from an older CA to the imported one.
2020-03-11 05:49:18 +01:00
Christian Hohnstaedt
8379b51610
Use list initializers for template keys
2020-03-07 06:48:07 +01:00
Christian Hohnstaedt
dc2ef08fa5
Constify db
2020-02-12 22:43:33 +01:00
Christian Hohnstaedt
fe59727825
Move includes required for FreeBSD
2020-02-12 22:43:33 +01:00
Christian Hohnstaedt
b982245995
Close #163 : Show key type/size on column of Certificates tab
...
Reuse HD_key_type, HD_key_size, HD_key_curve IDs from the key tab.
They use the "hd_key" type to put them into a context-submenu.
The certificate either uses the existing or a temporary key
and calls its "column_data()".
Simplify the submenu logic for the context-menu.
2020-02-12 22:42:36 +01:00
Patrick Monnerat
20b1c4fc8a
Resolve gcc 9/10 new warnings.
...
-Wstringop-truncation:
Ensure length passed to strncpy() is < size of destination buffer. The last
buffer byte is already nullified afterwards (in db::init_header() and
db::rename()).
-Wdeprecated-copy:
Explicit define of errorEx copy assignment operator.
Explicit define of x509revList copy assignment operator.
Explicit define of slotid copy constructor.
-Wimplicit-fallthrough:
Refactor code to suppress case fallthrough in pki_key::ssh_key_bn2data().
2020-02-09 01:24:06 +01:00
Guido Falsi
c3d7af01fd
Add includes required in FreeBSD to use in6_addr, AF_INET and AF_INET6.
2020-02-01 18:39:59 +01:00
Christian Hohnstaedt
bf09030dc9
Close #159 Opening existing database
...
Read the database schema from 'settings' uncached.
2020-01-30 17:00:15 +01:00
Christian Hohnstaedt
dcf8c7bcdb
No need for KEY_WOW64_32KEY registry flag
...
Registry entries are also 64bit.
2020-01-22 05:56:11 +01:00
Christian Hohnstaedt
4e16158668
Add missing DLL for PosgreSQL DLL
2020-01-21 21:34:31 +01:00
Christian Hohnstaedt
a12b2e94f5
Close #129 Unattended Installation. Switch to MSI installer
...
Improve Windows installation xca.wxs
Move documentation to "html" dir and translations to "i18n"
in the portable-app and the MSI installation
Modyfies getDocDir() and Introduces getI18nDir()
Drop Nullsoft installer files
2020-01-20 22:33:05 +01:00
Christian Hohnstaedt
a05349e917
Portable App: xca.exe path differs from registry install path
...
Even better select the initial working directory
2020-01-19 08:48:02 +01:00
Christian Hohnstaedt
580a2fae2b
Close #93 Default output folder / Improve Portable App usability
...
- allow setting a database as default
- Strip xca-app-folder from database and export filenames.
This allows renaming/moving the portable app and open the default DB
and use the working directory inside the folder
- Remember database history and configured language
2020-01-13 07:26:46 +01:00
Christian Hohnstaedt
23a737bbfa
Constify getLibExtensions()
2020-01-13 07:26:46 +01:00
Christian Hohnstaedt
2fbadfc9f0
Update Copyright Years to 2020
2020-01-13 07:26:46 +01:00
Christian Hohnstaedt
953d26c419
Close #21 Support for ODBC (MSSQL)
...
Add ODBC QSQL Database driver
Column "public" in public_keys table is a keyword in
MSSQL. Double quote it.
Double quotes are invalid on MySQL in non-ANSI mode.
Force ANSI mode for MySQL/MariaDB databases.
MSSQL also has a maximum VARCHAR of 8000
Schema updates are not performed for each new database.
New databases are immediately created conforming to schema:7
Schema 5 and 6 get updated to 7.
Schemas < 5 never have been released officially. (pre 2.0.0)
Switch "Database name" label to "DSN" for ODBC databases.
2020-01-13 07:24:08 +01:00
Christian Hohnstaedt
fd09ebe9ff
Close #156 secp256k1, secp256r1 and NIST-P256
...
Highlight RFC 5480 curves at the top of the list
2020-01-08 05:57:32 +01:00
Christian Hohnstaedt
ae94faebaf
Transfer Key Usage and Extended Key Usage critical flags
...
When transforming certificate or request extensions
into a template, the (e)keyusage critical flags storage
had a typo:
"eKyUseCritical" instead of "ekuCritical" and
"keyUseCritical" instead of "kuCritical"
Also the eKeyUse value was not transformed completely.
2020-01-07 06:08:30 +01:00
Christian Hohnstaedt
1ea45c8da4
Constify fload() fromPEM_BIO() fromPEMbyteArray()
...
Use "BIO_from_QByteArray()" instead of "BIO_new_mem_buf()"
Replace qSort() by std::sort()
Replace QString::null by QString()
2020-01-06 21:30:29 +01:00
Christian Hohnstaedt
8726c8b96d
Improve item loading. Inspired by #153
...
If Loading the item results in an openssl error,
even if the item is not empty, discard it.
Otherwise loading it from the database later on will fail.
Improve "autoIntName()"
2020-01-06 19:35:11 +01:00
Christian Hohnstaedt
2105fd8a75
Constify table names
2020-01-05 14:02:50 +01:00
Christian Hohnstaedt
9aa2525fab
Remove fopen_error() and its last user.
2019-12-19 07:17:03 +01:00
Christian Hohnstaedt
4199b8dfc6
Fix SSH2 public key export
...
Amend commit c26e7a4695
where the base64 key got lost in the output!
2019-12-16 17:14:37 +01:00
Christian Hohnstaedt
aac04418f5
Improved language maintainers
2019-12-14 13:24:15 +01:00
Christian Hohnstaedt
212b385022
Fix Typo
2019-12-14 13:24:15 +01:00
Christian Hohnstaedt
91dc86909f
Close #138 : Portable Version does not remember paths
...
Store export/import path as workingdir in database
also for the portable app.
Do not load a working dir that does not exist.
2019-12-12 23:20:19 +01:00
Christian Hohnstaedt
4bce90e986
Close 83: Token selection should not insist on name or serial of the token
...
Only use the public key when searching for
a matching key on the token.
Use token-name and serial to give the user a hint which token
XCA expects to carry the key.
2019-12-07 13:10:57 +01:00
Christian Hohnstaedt
2397ab72de
Close #140 : Certificate renewal with option to preserved serial number
...
Add checkbox (unchecked by default) to keep the old serial number
while renewing certificates
2019-12-06 15:28:09 +01:00
Christian Hohnstaedt
7f833a591f
Close #144 : Database export has issues with wildcards in internal names
...
Escape more characters when using internal name
as file name according to:
https://docs.microsoft.com/de-de/windows/win32/fileio/naming-a-file
Append a "_" after "CON, PRN, AUX, NUL, COM1-9, LPT1-9" as filename.
2019-12-05 14:56:39 +01:00
Christian Hohnstaedt
bb4b1e3a08
Change chinese language code from "zh" to "zh_CH"
2019-09-10 21:58:49 +02:00
Christian Hohnstädt
39f358e23f
Merge pull request #84 from chipitsine/master
...
resolve possible null pointer dereference
2019-05-14 17:50:05 +02:00
Christian Hohnstaedt
80affcfa61
CLose #120 : Mark signed a request doesn't work
...
PostgreSQL requires in INT type instead of bool,
when setting the signed column.
2019-05-13 17:06:57 +02:00
Christian Hohnstaedt
c7a0f14283
Close #116 : Duplicate extensions erroneously shown
...
Dynamically add unknown OIDs with its numerical representation
to always resolve them to avalid NID.
2019-05-13 16:45:57 +02:00
Christian Hohnstaedt
58669685eb
Close #114 : SAN - IPv6 address input not working
...
Do not try to write an own IP v4/6 validator.
The libc function inet_pton() does what we need.
2019-04-29 19:16:27 +02:00
Christian Hohnstaedt
79441b766d
Change hash algo of PKCS#12 certificate to 3DES SHA1
...
this is for systems where RC2 has been disabled for security reasons.
2019-04-08 06:27:21 +02:00
Christian Hohnstaedt
b9a8bb1a04
Cleanup: remove unused properties and declarations
2019-03-27 05:58:25 +01:00
Christian Hohnstaedt
47d4bfac2c
Improve SQL sequence when deleting a certificate
2019-03-27 05:58:20 +01:00
Christian Hohnstaedt
5e3d5e0edc
Cancel creating a new database if database-password dialog is cancelled.
...
Clicking cancel in the password dialog during database creation
does not trigger an assertion during key generation/import
anymore.
2019-03-27 05:58:15 +01:00
Christian Hohnstaedt
68ffb63db6
Use the SQL primary key to reference the CRL issuer
...
... and avoid the pointer
2019-03-25 07:23:53 +01:00
Christian Hohnstaedt
e9df5b7cda
Use the SQL primary key to reference the certificate issuer
...
... and avoid the pointer
2019-03-25 07:22:35 +01:00
Christian Hohnstaedt
4eb7b170b1
Do not reference the key by pointer, but by Key Id
...
This way the pointer to the key may change during reload.
2019-03-25 06:59:25 +01:00
Christian Hohnstaedt
f43e7520db
Support concurrent database access.
...
If a database is modified by another instance of XCA the passive
instance reloads and displays the changed parts.
2019-03-25 06:47:25 +01:00
Christian Hohnstaedt
ced0995862
Close #91 : Change order of "PKCS#11 provider"
...
With this commit PKCS#11 libraries may be reordered
and enabled or disabled.
The slot selection dialog iterates over all enabled and successfully
loaded libraries in the configured order and collects the slots
of each of them.
In the options dialog the library info is shown in the tool-tip
2019-03-21 06:12:51 +01:00
Christian Hohnstaedt
8f3335be0f
Improve lib detection
2019-03-21 05:25:21 +01:00
Christian Hohnstaedt
157b0a3fae
Move Template file reading to QFile API
2019-03-21 05:25:21 +01:00
Christian Hohnstaedt
a28b943b5f
Fix missing ; after return
2019-03-20 17:44:08 +01:00
Christian Hohnstaedt
1086329ee1
Fix for Openssl nno-ec
2019-03-18 06:25:20 +01:00
Christian Hohnstaedt
fa704001ca
Also change File loading from FILE* to QFile
2019-03-18 06:25:20 +01:00
Christian Hohnstaedt
026d8f8e6d
Extend PEM files by human readable information about the item
...
This can be enabled or disabled during export.
Move from FILE* to QFile
2019-03-18 06:25:20 +01:00
Christian Hohnstaedt
f55c7feee7
Constify some functions
2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
a78d953338
Support ecdsa SSH public keys
2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
742e1536d7
Fix Private key verification
2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
c26e7a4695
Close #98 Add comment at import/export RSA keys from/to SSH public key
...
When loading the SSH key add the trailing comment to the comment field
When storing the key, append the first line of the comment to the key.
2019-03-14 06:35:25 +01:00
Christian Hohnstaedt
1bc340a0ef
Close #104 : Also show sha256 digests of public keys
...
Print digest of public keys in the key details in different formats:
Print SHA256 SSH digest as used to by SSH users:
ssh-keygen -l -f ~/.ssh/id_rsa.pub
Print SHA1 X509 key digest as shown in the
Subject key identifier of a certificate
Print SHA256 digest as in:
openssl pkey -pubout -outform DER < key.pem | sha256sum
as requested by this issue.
Refactored digesting functionality by a generic Digest()
function working with QByteArrays.
The function formatHash() now also expects a QByteArray input.
2019-03-14 06:35:24 +01:00
Christian Hohnstaedt
c41bbf9b23
Close #82 : Renew CA ROOT Cert
...
Enable renewal option in the context menu
for self-signed CA certificates
2019-03-12 22:11:52 +01:00
Christian Hohnstaedt
56687bfc83
Verify imported keys thoroughly
...
When importing keys, a verification by signing and verifying
some random data is performed now.
2018-12-06 05:50:09 +01:00
Christian Hohnstaedt
a46759a946
Fix workingdir setting
2018-11-17 15:38:18 +01:00
Christian Hohnstaedt
7d5ecacad8
Make debug output configurable
...
Setting the XCA_DEBUG environment variable != ""
will enable debugging.
2018-11-17 14:14:44 +01:00
Ilya Shipitsin
1e0ca9f755
resolve possible null pointer dereference
...
[lib/db_temp.cpp:104] -> [lib/db_temp.cpp:103]: (warning) Either the condition 'if(temp)' is redundant or there is possible null pointer dereference: temp.
2018-11-14 23:04:56 +05:00
Christian Hohnstaedt
00fbb85c70
Improve on portable App and registry access
2018-11-07 18:30:14 +01:00
Christian Hohnstaedt
91faa1b675
Improve portable App
2018-11-05 06:21:14 +01:00
Christian Hohnstaedt
736dac6250
Close #40 macOS: Crash after xca v2.0.1 quit
...
If I select "Quit xca" from the "xca" menu, the application exits gracefully.
Unify code paths between "Quit xca", CMD-Q, ALT-F4 and [X] button
by calling mainwindow->close() from qApplication->quit() slot.
2018-10-29 22:24:22 +01:00
Christian Hohnstaedt
7b7e2644fa
Close #74 : Exiting XCA 2.1.1 corrupts database
...
The case-insensitive object search adds all short and long names
to a lookup table mapping the lowercase name to the corrersponding nid.
The array of nids contains 7 undefined nids. Resolving them
raises the error.
This fix deletes those errors after the map has been built.
2018-10-29 22:24:22 +01:00
Christian Hohnstaedt
eba8be37b8
Make PKCS11 libs, working dir and main-window size host-dependent
...
A "hostId" determines the current host and is appended to
the "workingdir", "pkcs11path" and "mw_geometry" settings
in the database. This allows opening the database
on different hosts without wrong workingdir or not
loadable PKCS#11 libraries
2018-10-29 22:24:22 +01:00
Christian Hohnstaedt
00bd36f19b
Support for XCA as portable App
...
On Windows XCA goes in portable mode if no XCA registry entry is found.
On Mac and Unix it checks the XCA_PORTABLE environment to be non-empty.
In portable mode:
- The current working directory is not written to the database
- The configured language and history of opened databases is
forgotten after a restart of XCA
- No registry entry is required nor written.
- No unexpected files are written to disk, except exported items.
- Portable mode is displayed in the "About" dialog
If setup.exe or "make install" are not used,
- XCA is not assigned as app for any file types
2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
6f8ca8dd65
Improve DN translation notation
2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
1953f7f1b0
Improve defaultdb / defaultlang handling. No functional change
2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
ed53777e78
Fix compiler warnings
...
clang version 3.8.0-2ubuntu4
gcc version 5.4.0 20160609 (Ubuntu 5.4.0-6ubuntu1~16.04.10)
2018-10-25 16:43:19 +02:00
Christian Hohnstaedt
96151564ee
Activate polish language in the language menu
...
Add Jacek as Maintainer in the about dialog
2018-10-11 06:00:21 +02:00
Christian Hohnstaedt
18672fae2d
Convert workingdir separators to native separators
2018-09-13 18:24:29 +02:00
Christian Hohnstaedt
5b0a57ec59
Update documentation
2018-08-19 08:57:29 +02:00
Christian Hohnstaedt
e4f8f00b34
Inspired by #55 : Allow manual override of CSR signed/unsigned mark
...
Via context menu the "Signed" flag may be toggled manually now.
2018-08-17 09:14:26 +02:00
Christian Hohnstaedt
2fc272247e
Close #56 : Duplicate Serials after Upgrade 2.1.0
...
Fix default length of random serial from 8 to 64 bit.
2018-08-17 06:07:03 +02:00
Christian Hohnstaedt
410142f358
Close #57 : SAN IP not working in 2.1.0
...
Fix typo
2018-08-17 06:07:03 +02:00
Christian Hohnstaedt
c9cdb5d61c
Close #55 : Calculate "CSR signed" information from legacy database
...
XCA-2.x stores the "request signed" information permanently
in the database.
XCA-1.x dynamically calculated this information by looking
for certificates with the same public key.
When converting an XCA-1.x database, requests with a matching cert
are marked signed in the XCA-2.x database.
2018-08-17 06:03:52 +02:00
Christian Hohnstaedt
340b53f4fd
Close #55 : Add Certificate counter row for requests.
...
(XCA 2.x - Relationship CSR <-> issued Certificate broken)
This counter is dynamic and not stored in the DB.
In comparison to the signed flag, which is stored and
remains set in the DB, even if all certificates
issued by signing this request are deleted.
2018-08-17 06:00:40 +02:00
Christian Hohnstaedt
3d4c6cfcf5
Add sanity check when loading table-header information
...
This results in an error message instead of an assertion failure
if the header configuration is invalid.
2018-07-12 17:42:09 +02:00
Christian Hohnstaedt
2682edacfd
Close #48 The SKI tickbox isn't generating an SKI extension for CSRs
...
Since the first support of extensions for CSR (2005),
the Subject Key Identifier has been skipped.
Enable it, while still removing issuer extensions.
Better fix "Automatic X509v3 extensions for CSR"
2018-07-10 23:04:47 +02:00
Christian Hohnstaedt
4e68d40464
Revert "Extend #36 : Automatic X509v3 extensions for CSR"
...
This reverts commit f1dc9b868a .
2018-07-10 05:54:20 +02:00
Christian Hohnstaedt
f1dc9b868a
Extend #36 : Automatic X509v3 extensions for CSR
...
Also apply "DNS:copycn" correctly when generating
PKCS#10 CSR
2018-07-07 07:08:23 +02:00
Christian Hohnstaedt
c88b0b7d70
Improve fix for #35 : Configurable size of serial number.
...
Make sure the first octet of the serial is not 0 and not
interpretable as negative.
2018-07-07 06:58:21 +02:00
Christian Hohnstaedt
c1189b0ff4
Add private key icon to the key name
...
in the certificate and request table
2018-07-06 06:05:40 +02:00
Christian Hohnstaedt
9691496a98
Oid loading: catch OID creation errors
2018-07-06 06:05:31 +02:00
Christian Hohnstaedt
a8f54c82eb
Refactor OID loading
...
The OID resolver now finds oids independent of the capitalization
2018-07-03 18:49:18 +02:00
Christian Hohnstaedt
07cd638537
Use QFile and QString for NID-list reading
2018-07-02 08:25:11 +02:00
Christian Hohnstaedt
bdfa10d4d5
Close #45 : Unable to view Public Key
...
Allow displaying the public key of a certificate
or request without importing it.
When importing certificates or CRLs,
display the issuer if it exists in the database.
2018-07-01 14:58:23 +02:00
Christian Hohnstaedt
d5305d33c7
Check all dates regularily whether a "view" update is neccessary
2018-06-28 14:33:30 +02:00
Christian Hohnstaedt
2f8c25ba6f
Replace TR() by QObject::tr() to get catched by lupdate
...
lupdate does not find TR(), only tr()
2018-06-27 16:23:10 +02:00
Christian Hohnstaedt
dc5199205c
Make all dates in columns fancy, still sorting correctly by age
...
ToolTip shows the pretty formatted local date with time.
2018-06-27 08:56:07 +02:00
Christian Hohnstaedt
acea9e5c21
Fix translation of dates
2018-06-27 07:50:21 +02:00
Christian Hohnstaedt
96d8c5cf37
Generalize handling of DateTime columns
2018-06-26 23:32:40 +02:00
Christian Hohnstaedt
b10b4f7a53
Inspired by #42 : display insertion date relative
...
Easy to find the most recent entry, because it says
"3 seconds ago"
2018-06-25 21:20:25 +02:00
Christian Hohnstaedt
15d33fdcfc
Make the dynamic DN entry adaption configurable.
...
If the option is selected, the behavior from the
previous commit is enabled. Otherwise, the
explicit DN entries stay as configured.
2018-06-21 20:29:45 +02:00
Christian Hohnstaedt
22966937de
Close #36 : Support adding CN to X509v3 SAN automatically
...
Translate the special text "DNS:copycn" in the SAN to
the final common name.
Add checkobox "Copy Common Name" to the SAN Edit box,
for a user-friendly editing of the "DNS:copycn"
During certificate creation, an empty common name together with
"DNS:copycn" in the SAN will raise a warning message and the
opportunity to change the settings.
Change the SAN in the HTTP-server XCA template from
"DNS:your.server.name.here" to "DNS:copycn" to already
take advantage of this feature in the default template.
2018-05-19 22:14:08 +02:00
Christian Hohnstaedt
4b2375101b
Transform regexp based IP validator into its own QValidator class
2018-05-19 18:10:13 +02:00
Christian Hohnstaedt
f0e6dc1f1b
Close #35 : Configurable size of serial number.
...
Allow to configure the previously fixed serial number length
of 64 bit between 8 and 256 bit
2018-05-19 18:09:28 +02:00
Christian Hohnstaedt
efd3bff700
Add missing break in switch
2018-05-16 17:43:03 +02:00
Christian Hohnstaedt
0c8df14b7e
Close #27 : Configurable certificate expiry warning threshold
...
Add configuration values in the Options dialog to
control the time when certificates get marked yellow and
the expiration alarm time in calendar entries.
2018-05-11 09:19:12 +02:00
Christian Hohnstaedt
dc36728df8
Generate calender (.ics) files for certificate and CRL expiries
...
Also support consolidated calendar entries for a CA,
containing the CA, all issued certificates and the CRL expiry dates.
2018-05-10 12:49:59 +02:00
Christian Hohnstaedt
b362ae3593
Const-ify dbheader in column_data() and getIcon()
2018-04-25 09:34:45 +02:00
Christian Hohnstaedt
84fcc9610e
Close #25 : Certificates are no longer coloured
...
Fix function signature of "bg_color" to really overwrite
virtual pki_base::bg_color
2018-04-25 08:59:25 +02:00
Christian Hohnstaedt
8d64db6be3
Const-ify remFromCont()
2018-04-24 23:10:46 +02:00
Christian Hohnstaedt
b74642fa09
Const-ify QSqlRecord of restoreSql()
2018-04-24 09:34:34 +02:00
Christian Hohnstaedt
bfe6fbbc43
Close #24 : Add LibreSSL support. Tested with LibreSSL 2.7.2
2018-04-22 16:12:04 +02:00
Christian Hohnstaedt
331b79bd9d
Close #23 : Improve limiting to pattern in certificate tree view
...
CA certificates that don't match the search pattern, but have
matching childs are shown disabled with internal name.
2018-04-22 07:06:31 +02:00
Christian Hohnstaedt
94c3835ca5
Issue #19 Replace 3DES encryption by AES-256
2018-04-17 12:12:16 +02:00
Christian Hohnstaedt
ee93c576b9
Remove spaces from DN entries
2018-04-10 07:54:58 +02:00
Christian Hohnstaedt
31ab5595d1
Reject 0 key length when generating RSA/DSA keys (related to issue #18 )
2018-04-10 06:02:16 +02:00
Christian Hohnstaedt
c43051df12
Improve Use counter acquirement by one SQL statement for all keys
2018-04-09 06:09:55 +02:00
Christian Hohnstaedt
e95198e775
When overwriting an index.txt file, truncate it.
2018-04-09 05:21:22 +02:00
Christian Hohnstaedt
cd118e4e72
Fixup for "Assure traditional file format if PKCS#8 NOT selected"
...
Also RSA and DSA keys were marked as EC PRIVATE KEY.
Add break to the switch statement
2018-04-09 05:18:19 +02:00
Christian Hohnstaedt
3ee2fc4015
Document current working directory in the About dialog
2018-04-09 05:17:11 +02:00
Christian Hohnstaedt
ec5507412e
Fix private key import of PKCS12 and PEM keys
2018-04-06 06:01:05 +02:00
Christian Hohnstaedt
3073bcd105
Fixup previous commit to build on Qt4
2018-04-04 22:39:50 +02:00
Christian Hohnstaedt
4c75d43b87
Assure traditional file format if PKCS#8 NOT selected
2018-04-04 19:24:16 +02:00
Christian Hohnstaedt
d0eb95f784
Improve error messages by adding SqlItemId information
2018-04-04 19:17:05 +02:00
Christian Hohnstaedt
5fdd84c82c
Fix Importing PKCS#12 and PKCS#7 files
2018-03-30 21:34:00 +02:00
Christian Hohnstaedt
6f85548c07
Drop getClassName()
2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
7c4be863f1
Constify x509name and use getMostPopular() when filling the internal name
2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
2c20bd109a
Constify and Pure-Virtual pki_base and derived classes
2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
6cf72a38e0
Remove superflous function and mark decryptKey as pure virtual
2018-03-30 14:38:09 +02:00
Christian Hohnstaedt
3eef4bd12b
Fix translation artefacts.
...
No need to translate "X Certificate and Key management",
"Form", "Dialog" or "TimeInput"
"Select Token" and "New Key" window titles were never shown.
Remove them.
2018-03-28 08:13:22 +02:00
Christian Hohnstaedt
e3349aefb0
Accept driver that don't support transactions
...
Improve report of transaction errors.
2018-03-22 20:26:22 +01:00
Christian Hohnstaedt
64c9c5ccab
Add table prefix to be prepended to each table
...
This allows multiple independent xca databases in one database
2018-03-19 06:14:06 +01:00
Christian Hohnstaedt
139d8509b4
Fix crash during PKCS#12 export
...
initialize property variable "key"
and duplicate the sqlItemId to enable access to the private key.
2018-03-12 21:06:21 +01:00
Christian Hohnstaedt
0776ead694
Acceppt empty password for private key decryption
...
d2i_PKCS8PrivateKey_bio does not accept
passwords with 0 length for whatever reason.
2018-03-12 16:15:30 +01:00
Christian Hohnstaedt
f1e0a867fe
Fix includes for func.cpp windows build
2018-03-11 19:32:56 +01:00
Christian Hohnstaedt
4eeb856c73
Make hex the default input / output qstring of asn1integer
2018-03-11 10:02:14 +01:00
Christian Hohnstaedt
d22cfb0b53
Allow editing of revocations
2018-03-11 09:31:16 +01:00
Christian Hohnstaedt
0ed9f6926c
GitHub Bug #5 : Exporting a private key results in too-permissive permissions
...
Add umask(077) for key export
2018-03-10 14:43:36 +01:00
Christian Hohnstaedt
421ab5840a
Minor bugfixes: PostgeSQL does not like setting an integer to "true"
...
Display renamed request in the NewX509 dialog correctly in the dropdown
2018-03-10 10:45:03 +01:00
Christian Hohnstaedt
6e432238e7
Generalize, simplify and unify settings management
...
Add settings class to access the settings table in the database
Cache values and improve database writes.
Options dialog simplified
Replace getSetting / storeSetting
Unpack option flags to rows in the settings
2018-03-10 09:04:54 +01:00
Christian Hohnstaedt
1b28d9ab54
Fix display of dates in the Certificate details
...
The GMT time was displayed as local time
2018-03-08 22:15:19 +01:00
Christian Hohnstaedt
c62339e1ce
Adapt Certificate Index creation to the new database capabilities
2018-03-07 23:00:58 +01:00
Christian Hohnstaedt
4288aafe92
Improve automatic commenting actions
2018-03-07 20:51:46 +01:00
Christian Hohnstaedt
4867cfb8ab
Improve "Dump database" filename
2018-03-07 05:49:46 +01:00
Christian Hohnstaedt
9cef2415c9
Update slot_label when renaming items on the token or managing the token
2018-03-06 21:28:38 +01:00
Christian Hohnstaedt
3481a63db9
Fix PEM file loading
2018-03-06 21:27:43 +01:00
Christian Hohnstaedt
80471cd3f3
Small fixes: MySQL does not like "DEFAULT (0)"
2018-03-06 16:45:42 +01:00
Christian Hohnstaedt
5ef451ee91
Document in the comment if a public key has been completed by an imported private one
2018-03-06 16:42:28 +01:00
Christian Hohnstaedt
c2007a13ee
Minor fixes: Store token in DB, Load settings,
2018-03-06 09:02:06 +01:00
Christian Hohnstaedt
79d6aa0b10
Improve message boxes. Always display plain text
...
And show a message if a database connection failed.
2018-03-05 19:47:05 +01:00
Christian Hohnstaedt
14421f4ed3
Update Issuer and Key name in the Certificate, Request and CRL details
...
after editing double-clicked element.
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
545c955616
Add "Primary key" column to show the items internal id
...
Especially helpful if you want to lookup the item
in the database manually.
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
c14e54c830
Minor fixes: Date from database and affected items
...
Correctly initialize undefined date from database
Clear list of affected items after commit.
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
879d6bb17c
When searching for items, also search in the new "comment" field.
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
64d64d5130
Allow editing key name and comment in the key details
2018-03-05 07:46:11 +01:00
Christian Hohnstaedt
3e86a1daaa
Fix Minor errors
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
af0e0a75b9
Drop dnPolicy for now
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
d079dbde09
Collect affected items
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0f582044e2
More transaction
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
491a01ed1f
When signing a request note it in the request-comment
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0b82028644
Add "Legacy Database" as additional source
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
84e4301f6d
Tell the user if the SqLite driver is missing
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
e6c92ce890
Improve transactions, fix CA template and CRLdays import
...
Make ItemCombo a template class
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
d36e6eb0cb
Implement nested transactions.
...
The DbTransaction class automatically rolls back when the scope
is left (destructor) and no commit happenned.
Every transaction begin will increment the counter,
each commit/rollback will decrement it. Only if all transactions
finished with a commit, a final database commit will be performed.
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
24d1f85a26
Make use of C++ templates for more type-safety
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
dc75fa0171
Add token as item source, minor fixes
...
Use dynamic cast for sqlSELECTpki()
Fix Double-click links in cert details
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0745e18da2
Allow to edit item properties
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
a3900b1473
Several fixes for templates, key encryption etc.
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
0921b63763
Fix indentation error
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
3f016c62e7
Fix minor problems during db open and key import
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
07594d1edd
Rebase on master
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
fed2dd711a
Minor fixes
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
84f25048a7
Remove xca_db_stat application
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
e1b982a346
Replace printf by qDebug
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
af57cc8f13
Extract app not needed anymore
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
431076c90e
Change private key encryption in the database to PKCS#8
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
d50dbbd726
Create indexes
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
a545659e1a
Add Source column, fix Revocation management
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
fbde63e98d
Add Views and a concept of schema updates
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
00145600a7
Improve usecounter performance
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
fc7fc357ac
Support opening remote databases MySQL and PostgreSQL
2018-03-05 07:46:10 +01:00
Christian Hohnstaedt
2a0a4630ae
Extend authority table and fix CaProperties
2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
fe6062f16e
No more increasing serials. Only random serials.
2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
3c981a6742
Avoid updateAfterCrlLoad
2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
cac6b39877
Fix bug in delition order
2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
e624743494
Add PKI Source: generated, imported, transformed
2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
4598ddb4de
Convert QByteArray.base64() to QString before writing it to the DB
2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
a75eb6ebd8
Avoid LastInsertID
2018-03-05 07:46:09 +01:00
Christian Hohnstaedt
4b3ee2c705
Switch database format to SQL(ite)
...
This is a large squash of many small commits.
Allow porting data from the legacy format to SQL.
Store Binaries base64 encoded and use db->transaction
Update password hash to be 8000 x SHA512 with 8 byte Salt
Add revocations table and fixup CRL generation
Add comment and insertion date columns
Fix column saving, remove trust, add XcaDialog
Allow changing the internal name and comment in Cert/Req details view
Extend Comment functionality, Replace About.ui by XcaDialog.ui
2018-03-05 07:42:36 +01:00
Christian Hohnstaedt
b63f50b28b
Add more error checks and remove code duplication
2018-03-01 22:10:52 +01:00
Christian Hohnstaedt
365507b36e
SF Bug #122 isValid() tried to convert the serial to 64 bit
...
With OpenSSL 1.1.0 this results in an error message
if the serial was too long.
With OpenSSL 1.0.x it didn't.
2018-03-01 22:06:23 +01:00
Christian Hohnstaedt
bdbaa0a946
Support Dragging certificates and other items as PEM text
...
Also dragging PEM test into XCA opens the import Dialog
2018-02-20 23:47:17 +01:00
Christian Hohnstaedt
4b9b8e9973
Add more openssl error checks during database load to tackle Bug #122
2018-02-13 11:47:22 +01:00
Christian Hohnstaedt
eb6382d6aa
Remove SPKAC support. Netscape is not of this world anymore.
...
I discovered some bugs in SPKAC handling and fixing them was hard.
Because of this bugs noone may have used the feature in the past.
Remove it.
2018-02-13 11:47:21 +01:00
Dancho Penev
b0d131e79a
SF bug #124 Wrong assumptions about slots returned by PKCS11 library
...
When using PKCS11 library to manage smart cards the code assumes
that all slots returned by the library call are not empty.
In some cases Gemalto's library returns list of slots in which the
first one is empty and the second one is occupied by the smart card,
this causes xca to report an error and isn't able to use the smart card.
2018-02-07 11:10:04 +01:00
Christian Hohnstaedt
3f35cdccf8
Cleanup the OID text files, remove senseless aia.txt
...
- Remove all aia.txt from the Code, Documentation and ToolTip
- Add an Operating system dependent help hint
- Replace unix LF by DOS CR-LF for windows installation
2018-02-01 00:05:40 +01:00
Christian Hohnstaedt
8333482eef
Improve behavior regarding additional OIDs
...
Depending on the OpenSSL version some OIDs are known, some are not.
When reading "oids.txt" file and adding the new OID definitions:
- Silently skip definitions that are 100% identical to the OpenSSL values.
- Give a hint to change identifiers that are used for a different OID
- Give a hint about definitions that differ to remove them from the file.
Also accept them as Alias when reading dn.txt and eku.txt
2018-01-31 20:15:07 +01:00
Christian Hohnstaedt
fc4bdaf196
Refine and document Entropy gathering
2018-01-29 14:57:07 +01:00
Christian Hohnstaedt
715b263998
Indicate development and release version by git commit hash
...
Fix "qmake" build for qt4 and qt5
2018-01-28 11:36:37 +01:00
Christian Hohnstaedt
1d2a1b18c4
Fix dumping private keys during "Dump database"
...
If the database password is empty, dumping private keys
resulted in an error message.
Fix this by setting the encryption algorithm to NULL if
the password is empty.
Additionally throw the error after closing the filedescriptor.
2018-01-27 12:52:17 +01:00
Christian Hohnstaedt
27482fc080
Fix Null pointer exception when importing PKCS#12 with OpenSSL 1.1.0
...
Setting the EVP_PKEY type deletes the key with OpenSSL 1.1.0
Reported by Perederyaev Ivan. Thank you.
2018-01-27 12:48:13 +01:00
Christian Hohnstaedt
eaabb2a28d
SF Bug #110 Exported private key from 4096 bit SSH key is wrong
...
Actually, it just differs. It is PKCS#8 instead of PKCS#1
2018-01-06 21:18:31 +01:00
Christian Hohnstaedt
0ba41583fb
SF Bug #109 Revoked.png isn't a valid image
...
It was unused and did not harm. No functional/optical impact.
Delete image and all ist references
2018-01-06 21:17:15 +01:00
Christian Hohnstaedt
704d98b071
Remove duplicate X509_CRL_set_issuer_name()
...
Found by "Patrick Monnerat <patrick@monnerat.net>"
Thank you
2017-11-29 08:01:19 +01:00
Christian Hohnstaedt
de7b368355
Of course we support Big Endian machines. Remove debugging mechanism
...
At least during coding. I have not Big Endian platform to
verify the expression above.
2017-11-23 12:44:02 +01:00
Christian Hohnstaedt
8867727926
Refuse overwriting unknown files
2017-11-17 15:53:30 +01:00
Christian Hohnstaedt
2bced828de
Translation: Re-translate the OID resolver in case of a language change
2017-11-17 09:06:56 +01:00
Christian Hohnstaedt
8ebaa683ff
Translation: Also translate validity dates to the configured language
2017-11-17 09:06:56 +01:00
Christian Hohnstaedt
b9bd5a9344
Fix GCC-6 warning -Wmisleading-indentation
2017-10-25 09:21:12 +02:00
Tino Mettler
f0699d055f
Fix further spelling errors found by lintian packge checker
2017-10-24 12:15:58 +02:00
Christian Hohnstaedt
d1a34b8329
Fix Hash algorithm when converting certificate to PKCS#10
...
Use the one from the certificate instead of SHA1
2017-10-04 23:21:02 +02:00
Christian Hohnstaedt
cefb140601
Switch to Qt5 for Windows build and installation
...
Don't depend on htonl() and friends to avoid lwsock32
Fixup WIN32 define to use the Qt definition
2017-07-17 09:27:46 +02:00
Christian Hohnstaedt
f12c3ca8aa
Improve Copy&Paste behavior: Accept Ctrl-V and MousePaste on MainWindow
2017-07-15 06:51:37 +02:00
Christian Hohnstaedt
ac780d3e77
Fix PEM_BIO loading by using QByteArray instead of BIO and fmemopen
2017-07-15 06:51:37 +02:00
Christian Hohnstaedt
5fbd102493
Fix for MacOS X builds
2017-07-15 06:51:37 +02:00
Christian Hohnstaedt
1ae80c1af7
Do not apply the default template when creating a similar cert
2017-07-12 19:35:21 +02:00
Christian Hohnstaedt
22b441046a
SF: #120 Crash when importing CA certificate for certificates which already exist
...
The QAbstractItemModel is simetimes called with column index -1
Catch those calls.
2017-07-12 19:35:21 +02:00
Christian Hohnstaedt
4ef4c9ad87
SF #116 db_x509.cpp:521: Mismatching allocation and deallocation: cert
...
free(cert) -> delete cert
2017-07-10 09:12:37 +02:00
Christian Hohnstaedt
b22d82a3f9
OSSL 1.1 vs. 1.0: Windows support
2017-07-08 06:57:04 +02:00
Christian Hohnstaedt
8429817bf0
Typo in openssl-compat
2017-06-30 21:13:06 +02:00
Christian Hohnstaedt
d14b3bf5ed
OSSL 1.1: Windows does not know "fmemopen()"
2017-06-19 09:52:33 +02:00
Christian Hohnstaedt
dda100c100
OSSL 1.1 vs. 1.0: Private keys
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
f7e485393c
OSSL 1.1 vs. 1.0: EVP
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
a279a8e43e
OSSL 1.1 vs. 1.0: Cleanup CRL
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
413ba8bff3
OSSL 1.1 vs. 1.0: Cleanup CRL extensions
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
3f20bce3f9
OSSL 1.1 vs. 1.0: Drop some #ifdef from the pkcs11
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
9d2ed957dd
OSSL 1.1 vs. 1.0: Purge BIO_QBA_mem_buf()
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
7f36322f0b
OSSL 1.1 vs. 1.0: Extensions, Cert Details
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
62a1711c3b
OSSL 1.1 vs. 1.0: Revocations
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
39c2e86ee0
OSSL 1.1 vs. 1.0: Improve Key generation
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
f0c7badf0b
OSSL 1.1 vs. 1.0: Store sigAlg as NID instead of Object
2017-06-19 08:33:29 +02:00
Christian Hohnstaedt
077c061d0e
OSSL 1.1 vs. 1.0: Add openssl_compat.h centralizing the #ifdef Hell
2017-06-19 08:33:29 +02:00
Patrick Monnerat
ad6c2baae5
Add support for OpenSSL 1.1.0
...
The API changed heavily. New functions arrived, old functions
disappeared and many structures became opaque.
This version of the patch implements pkcs11 signing as follows:
- openssl < 1.0.0: rsa & dsa without engine
- openssl 1.0.x: rsa, dsa & ec with engine
- openssl >= 1.1.0: rsa, dsa & ec without engine
In the operation, we therefore also gain implementation of dsa signing for openssl < 1.0.0 (ec disabled because EC_KEY_METHOD was not yet invented!).
I've given up trying to use a PKEY_ENGINE with openssl 1.1: seems not possible anymore.
I've succeeded compiling the patched xca with openssl 0.9.8n, 1.0.2j and 1.1.0e.
I've successfully tested pkcs11 signing using softhsm with openssl 1.0.2j and 1.1.0e.
The patch also removes gcc7 new warnings.
2017-06-19 08:32:39 +02:00
Adam Dawidowski
0d34bc1c1c
Extend generating an OpenSSL "index.txt"
...
Updated patch adds another export option automating the creation
of multiple index.txt files to be used with multiple ocsp responders.
New export option is available via command line (-I index.txt) and
the Extras menu (Extra->Export Certificate Index hierarchy).
The option causes the creation of an index.txt file containing
index records for all the children certificates of a parent.
The filenames are generated using the supplied name as prefix
and append a dot and the simplified Internal Name
(the Internal Name stripped of non-alphanumeric characters except underscores).
2016-09-06 20:03:55 +02:00
PF4Public
c0130feafa
Some pedantic edits
2016-04-09 06:40:39 +02:00
Adam Dawidowski
e94e9133b1
Support generating an OpenSSL "index.txt"
...
XCA currently lacks support for generating an index.txt.
Such a file gets created and maintained when using CA
features in openssl. As mentioned here:
https://sourceforge.net/p/xca/discussion/209946/thread/6cbc727c/#2310
such a file can be used by Openssl's built-in OCSP responder.
Additionally, it can be used for configuring a cron job for
reminding of certificate expiration.
Certificate index export is added in 3 places:
- command line (-i index.txt),
- the Extras menu (Extra->Export Certificate Index) and
- the selected file(s) export option in the context menu
on the Certificates tab (Export->File, Export Format:
Certificate Index file).
Please note that SubjectDN generated by this feature has
different formatting than the one generated by openssl.
2016-04-09 06:40:39 +02:00
Christian Hohnstaedt
fa38a21a04
Merge Release 1.3.2 based fixes from Tino Mettler and Christohper Knadle
2016-02-11 09:09:51 +01:00
Christohper Knadle
2f3a1de7ac
Fix spelling errors found by lintian packge checker
2016-02-11 09:08:38 +01:00
Christian Hohnstaedt
806312800d
Thales nCipher key generation changes for EC and DSA keys
...
Developed and tested by
Mak, Mcken <Mcken.Mak@thalesesec.com>
Thanks!
2016-01-16 07:54:54 +01:00
Christian Hohnstaedt
735a74f873
On unix use the default clipboard and mouse-selection for export
2016-01-16 07:34:21 +01:00
Christian Hohnstaedt
126fdec51c
Improve language handling
2015-10-02 16:45:07 +02:00
Christian Hohnstaedt
78e4207f2e
Fix database password change on Windows
...
Reimplementing the simple unix "mv" command on Windows is PITA!
Renaming an open file -> Error!
Renaming to an existing file -> Error!
Atomicity: No
2015-09-23 10:42:05 +02:00
Christian Hohnstaedt
e5541c6d67
SF. Bug. #81 Make xca qt5 compatible
...
Extend XCA to also compile against Qt5
Remove directory from Qt includes
2015-09-17 18:42:42 +02:00
Christian Hohnstaedt
2f61c8c711
SF. Bug. #107 error:0D0680A8:asn1 encoding routines:ASN1_CHECK_TLEN:wrong tag
...
Gracefully handle malformed Netscape extensions i.e.
Expected IA5 strings not IA5 tagged
2015-09-17 13:02:48 +02:00
Christian Hohnstaedt
6d9c62867f
Opening a database with unknown CRL causes endless loop
...
See discussion on SorceForge: "v1.3.0 freezes on Windows 7"
If a CA certificate with a matching subject but missmatching key
for a CRL exists, XCA enters an endless loop.
Correctly iterate over signer certificates when searching
the signer of a CRL.
2015-08-21 08:33:37 +02:00
Christian Hohnstaedt
d55eb917e2
Silence compiler warnings about unused parameters
2015-08-11 07:17:56 +02:00
Christian Hohnstaedt
88443e5a9b
OpenSSL 1.0.x still has the 0.9.8 PEM_write_bio() prototype
2015-05-20 18:28:13 +02:00
Christian Hohnstaedt
85d2a26aa9
Fix all fopen() calls to always use "wb" or "rb"
...
fix PKI item autodetection
Fix compiler warning because of a changed OpenSSL 0.9.8/1.0.1
"PEM_load_bio()" API change
2015-05-20 13:14:21 +02:00
Christian Hohnstaedt
68cf3615df
Fix saving a single certificate
2015-05-20 13:14:21 +02:00
Christian Hohnstaedt
68781ff47f
Fix compile errors
2015-05-19 19:16:17 +02:00
Christian Hohnstaedt
279a6f3fdb
Update translation
2015-05-19 06:15:38 +02:00
Christian Hohnstaedt
854d0dbde5
Minor fixes, remove debugging output
2015-05-18 17:51:20 +02:00
Christian Hohnstaedt
825210f606
Minor fixes
...
double fclose() does not harm on Mac, but on linux
Unify export to token
2015-05-18 05:58:39 +02:00
Christian Hohnstaedt
c00db626c5
Support editing the CRL number when generating CRLs
2015-05-17 13:22:47 +02:00
Christian Hohnstaedt
75a6d117f3
Refactor context menu
...
Better support multiple selections
- Export all selected items into one PEM file
- Batch Revoke/unrevoke/renew of many selected certificates
of the same issuer
- allow exporting templates as PEM
Add Feat. Reg. #83 Option to revoke old certificate when renewing
Always put all signed certificate to the newest CA.
If a CA certificate is renewed, all certificates issued by
the old CA are now shown as signed by the new one.
2015-05-17 09:17:04 +02:00
Christian Hohnstaedt
5b40ac664b
Add Null-pointer-check and add support for OSCP_noCheck
2015-05-14 12:58:05 +02:00
Christian Hohnstaedt
c691c1cca5
Suuport nameConstraints and policyMappings when creating OpenSSL conf from cert
2015-05-14 12:58:05 +02:00
Christian Hohnstaedt
5fdb362f8c
Support InhibitAnyPolicy and PolicyConstraint extensions
...
... when exporting certificates to templates or OpenSSL configs
2015-05-04 17:20:45 +02:00
Christian Hohnstaedt
5c6bb6c795
Fix typo
2015-04-21 10:17:32 +02:00
Christian Hohnstaedt
90f351b2cb
Refactor CRL handling
2015-04-20 18:25:59 +02:00
Christian Hohnstaedt
25a53441e9
Certificate export: Add option to export selected certificates to PEM or PKCS#7
...
Using the context menu only handles the current item.
This is now reflected by resetting the selection in case of
a context menu event
2015-04-15 08:41:29 +02:00
Christian Hohnstaedt
58142b487c
Fix syntax errors in documentation and english phrases
...
Thx Patrick Monnerat <Patrick.Monnerat@datasphere.ch>
2015-04-10 19:27:05 +02:00
Christian Hohnstaedt
698c10216f
Add option for disabling the very very legacy Netscape extensions
...
Maybe this setting will become the default in future releases....
2015-04-09 18:49:03 +02:00
Christian Hohnstaedt
c5833ebe69
Separate Certificate revocation and CRL expiry in the Columns
2015-04-09 15:06:46 +02:00
Christian Hohnstaedt
acd1c92dfb
Fixup Entropy file reader to be non-blocking.
...
And add a fix for windows that doesn't
know about 'non-blocking'
2015-04-08 20:53:18 +02:00
Christian Hohnstaedt
2909e79317
Move entropy functions into new class
...
Read and write .rnd file during start and exit
2015-04-08 06:54:55 +02:00