/* vi: set sw=4 ts=4: * * Copyright (C) 2001 - 2014 Christian Hohnstaedt. * * All rights reserved. */ #include "CertDetail.h" #include "KeyDetail.h" #include "MainWindow.h" #include "distname.h" #include "clicklabel.h" #include "Help.h" #include "OidResolver.h" #include "lib/func_base.h" #include "lib/func.h" #include "lib/XcaWarningCore.h" #include #include #include #include CertDetail::CertDetail(QWidget *w) : XcaDetail(w) { setupUi(this); tabwidget->setCurrentIndex(0); } void CertDetail::on_showExt_clicked() { if (showConf) { showConf = false; v3extensions->document()->setHtml(exts); showExt->setText(tr("Show config")); } else { showConf = true; v3extensions->document()->setPlainText(conf); showExt->setText(tr("Show extensions")); } } int CertDetail::tabIndexByName(const QString &tabname) const { for (int i=0; icount(); i++) { if (tabwidget->widget(i)->objectName() == tabname) return i; } return -1; } void CertDetail::setX509super(pki_x509super *x) { description->setText(x->getIntName()); thisSqlId = x->getSqlItemId(); connect_pki(x); // examine the key myPubKey = x->getRefKey(); if (myPubKey) { privKey->setText(myPubKey->getIntName()); privKey->setClickText(myPubKey->getSqlItemId().toString()); if (myPubKey->isPrivKey()) { privKey->setGreen(); } else { privKey->setRed(); } } else { tmpPubKey = myPubKey = x->getPubKey(); privKey->setText(tr("Show public key")); privKey->setRed(); myPubKey->setIntName(x->getIntName()); myPubKey->setComment(tr("This key is not in the database.")); } if (!myPubKey) { privKey->setText(tr("Not available")); privKey->setDisabled(true); privKey->disableToolTip(); } else { keySqlId = myPubKey->getSqlItemId(); } connect(privKey, SIGNAL(doubleClicked(QString)), this, SLOT(showPubKey())); // details of the subject subject->setX509name(x->getSubject()); // V3 extensions extList el = x->getV3ext(); if (el.count() == 0) { tabwidget->removeTab(tabIndexByName("extensionsTab")); tabwidget->removeTab(tabIndexByName("validationTab")); } else { exts = el.getHtml("
"); el.genGenericConf(&conf); v3extensions->document()->setHtml(exts); } // Algorithm sigAlgo->setText(x->getSigAlg()); connect(sigAlgo, SIGNAL(doubleClicked(QString)), MainWindow::getResolver(), SLOT(searchOid(QString))); // Comment comment->setPlainText(x->getComment()); setCert(dynamic_cast(x)); setReq(dynamic_cast(x)); } void CertDetail::setCert(pki_x509 *cert) { if (!cert) return; QList errors; init("certdetail", ":certImg"); errors = cert->ossl_verify(); QString html; for (int err : errors) { html += QString("
  • %1:
    %2
  • \n") .arg(get_ossl_verify_error(err)) .arg(X509_verify_cert_error_string(err)); } if (html.isEmpty()) html = tr("No verification errors found."); else html = "
      \n" + html + "
    \n"; validation->setHtml(html); QList purposes = cert->purposes(); for (X509_PURPOSE *purp : purposes) { QString purpname = X509_PURPOSE_get0_name(purp); int id = X509_PURPOSE_get_id(purp); qDebug() << "Purpose: " << purpname << " (" << id << ")"; purposeList->addItem(QString("%1 (%2)").arg(purpname).arg(id)); } headerLabel->setText(tr("Details of the Certificate")); try { // No attributes tabwidget->removeTab(tabIndexByName("attributesTab")); if (cert->isCA()) { tabwidget->removeTab(tabIndexByName("validationTab")); } else { if (errors.size() > 0) tabwidget->tabBar()->setTabTextColor(tabIndexByName("validationTab"),Qt::red); } // examine the signature if (cert->getSigner() == NULL) { signature->setText(tr("Signer unknown")); signature->setDisabled(true); signature->disableToolTip(); } else if (cert == cert->getSigner()) { signature->setText(tr("Self signed")); signature->setGreen(); signature->disableToolTip(); } else { pki_x509 *issuer = cert->getSigner(); signature->setText(issuer->getIntName()); signature->setClickText(issuer->getSqlItemId().toString()); signature->setGreen(); issuerSqlId = issuer->getSqlItemId(); connect(signature, SIGNAL(doubleClicked(QString)), this, SLOT(showIssuer())); } // the serial serialNr->setText(cert->getSerial()); // details of the issuer issuer->setX509name(cert->getIssuerName()); // The dates notBefore->setText(cert->getNotBefore().toPretty()); notBefore->setToolTip(cert->getNotBefore().toPrettyGMT()); notAfter->setText(cert->getNotAfter().toPretty()); notAfter->setToolTip(cert->getNotAfter().toPrettyGMT()); // validation of the Date dateValid->disableToolTip(); if (cert->isRevoked()) { x509rev rev = cert->getRevocation(); dateValid->setText(tr("Revoked at %1") .arg(rev.getDate().toPretty())); dateValid->setRed(); dateValid->setToolTip(rev.getDate().toPrettyGMT()); } else if (!cert->checkDate()) { dateValid->setText(tr("Not valid")); dateValid->setRed(); } else { dateValid->setGreen(); dateValid->setText(tr("Valid")); } // the fingerprints fpMD5->setText(cert->fingerprint(EVP_md5())); fpSHA1->setText(cert->fingerprint(EVP_sha1())); QString fp = cert->fingerprint(EVP_sha256()); int x = fp.size() / 2; fp = fp.mid(0,x) + "\n" + fp.mid(x+1, -1); fpSHA256->setText(fp); openssl_error(); } catch (errorEx &err) { XCA_WARN(err.getString()); } } void CertDetail::setReq(pki_x509req *req) { if (!req) return; init("csrdetail", ":csrImg"); headerLabel->setText(tr("Details of the certificate signing request")); try { // No issuer tabwidget->removeTab(tabIndexByName("issuerTab")); tabwidget->removeTab(tabIndexByName("validationTab")); // verification if (!req->verify() ) { signature->setRed(); signature->setText("Failed"); } else { signature->setGreen(); signature->setText("PKCS#10"); } signature->disableToolTip(); fingerprints->hide(); validity->hide(); serialLabel->hide(); serialNr->hide(); // The non extension attributes int cnt = X509_REQ_get_attr_count(req->getReq()); int added = 0; QGridLayout *attrLayout = new QGridLayout(attributes); attrLayout->setAlignment(Qt::AlignTop); attrLayout->setSpacing(6); attrLayout->setContentsMargins(11, 11, 11, 11); for (int i = 0, ii = 0; igetReq(), i); nid = OBJ_obj2nid(X509_ATTRIBUTE_get0_object(att)); if (X509_REQ_extension_nid(nid)) { continue; } label = new QLabel(this); trans = dn_translations[nid]; if (Settings["translate_dn"] && !trans.isEmpty()) { label->setText(trans); label->setToolTip(QString(OBJ_nid2sn(nid))); } else { label->setText(QString(OBJ_nid2ln(nid))); label->setToolTip(trans); } label->setText(QString(OBJ_nid2ln(nid))); label->setToolTip(QString(OBJ_nid2sn(nid))); attrLayout->addWidget(label, ii, 0); added++; int count = X509_ATTRIBUTE_count(att); for (int j=0; jvalue.asn1_string); attrLayout->addWidget(label, ii, j +1); } ii++; } if (!added) { tabwidget->removeTab(tabIndexByName("attributesTab")); } openssl_error(); } catch (errorEx &err) { XCA_WARN(err.getString()); } } QLabel *CertDetail::labelFromAsn1String(ASN1_STRING *s) { QLabel *label; label = new CopyLabel(this); label->setText(asn1ToQString(s)); label->setToolTip(QString(ASN1_tag2str(s->type))); return label; } void CertDetail::itemChanged(pki_base *pki) { QVariant pkiSqlId = pki->getSqlItemId(); if (pkiSqlId == keySqlId) privKey->setText(pki->getIntName()); if (pkiSqlId == issuerSqlId) signature->setText(pki->getIntName()); if (pkiSqlId == thisSqlId) description->setText(pki->getIntName()); } void CertDetail::showPubKey() { KeyDetail::showKey(this, myPubKey, keySqlId.isValid()); } void CertDetail::showIssuer() { showCert(this, Store.lookupPki(issuerSqlId)); } void CertDetail::showCert(QWidget *parent, pki_x509super *x) { if (!x) return; CertDetail *dlg = new CertDetail(parent); dlg->setX509super(x); dlg->exec(); delete dlg; } CertDetail::~CertDetail() { delete tmpPubKey; }