Latest update.
This commit is contained in:
+11
-33
@@ -1,3 +1,5 @@
|
||||
SUBDIRS=lib
|
||||
|
||||
# Program init source, that don't have direct linkage with the rest of the
|
||||
# source, and can therefore not be part of a library.
|
||||
IF[{- !$disabled{uplink} -}]
|
||||
@@ -7,37 +9,18 @@ IF[{- $config{target} =~ /^vms-/ -}]
|
||||
$INITSRC=vms_decc_init.c
|
||||
ENDIF
|
||||
|
||||
# Auxilliary program source
|
||||
IF[{- $config{target} =~ /^(?:VC-|mingw)/ -}]
|
||||
# It's called 'init', but doesn't have much 'init' in it...
|
||||
$AUXLIBAPPSSRC=win32_init.c
|
||||
ENDIF
|
||||
IF[{- $config{target} =~ /^vms-/ -}]
|
||||
$AUXLIBAPPSSRC=vms_term_sock.c vms_decc_argv.c
|
||||
ENDIF
|
||||
|
||||
# Source for the 'openssl' program
|
||||
# We need the perl variable for the DEPEND generator further down.
|
||||
$OPENSSLSRC={-
|
||||
our @opensslsrc =
|
||||
qw(openssl.c
|
||||
asn1pars.c ca.c ciphers.c cms.c crl.c crl2p7.c dgst.c dhparam.c
|
||||
dsa.c dsaparam.c ec.c ecparam.c enc.c engine.c errstr.c gendsa.c
|
||||
genpkey.c genrsa.c kdf.c mac.c nseq.c ocsp.c passwd.c pkcs12.c pkcs7.c
|
||||
pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c rsa.c
|
||||
rsautl.c s_client.c s_server.c s_time.c sess_id.c smime.c speed.c
|
||||
spkac.c srp.c ts.c verify.c version.c x509.c rehash.c storeutl.c
|
||||
info.c);
|
||||
join(' ', @opensslsrc); -}
|
||||
# Source for libapps
|
||||
$LIBAPPSSRC=apps.c apps_ui.c opt.c fmt.c s_cb.c s_socket.c app_rand.c \
|
||||
bf_prefix.c
|
||||
$OPENSSLSRC=\
|
||||
openssl.c progs.c \
|
||||
asn1pars.c ca.c ciphers.c cms.c crl.c crl2p7.c dgst.c dhparam.c \
|
||||
dsa.c dsaparam.c ec.c ecparam.c enc.c engine.c errstr.c gendsa.c \
|
||||
genpkey.c genrsa.c kdf.c mac.c nseq.c ocsp.c passwd.c pkcs12.c pkcs7.c \
|
||||
pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c rsa.c \
|
||||
rsautl.c s_client.c s_server.c s_time.c sess_id.c smime.c speed.c \
|
||||
spkac.c srp.c ts.c verify.c version.c x509.c rehash.c storeutl.c \
|
||||
list.c info.c provider.c fipsinstall.c
|
||||
|
||||
IF[{- !$disabled{apps} -}]
|
||||
LIBS{noinst}=libapps.a
|
||||
SOURCE[libapps.a]=$LIBAPPSSRC $AUXLIBAPPSSRC
|
||||
INCLUDE[libapps.a]=.. ../include include
|
||||
|
||||
PROGRAMS=openssl
|
||||
SOURCE[openssl]=$INITSRC $OPENSSLSRC
|
||||
INCLUDE[openssl]=.. ../include include
|
||||
@@ -48,11 +31,6 @@ IF[{- !$disabled{apps} -}]
|
||||
SOURCE[openssl]=openssl.rc
|
||||
ENDIF
|
||||
|
||||
{- join("\n ", map { (my $x = $_) =~ s|\.c$|.o|; "DEPEND[$x]=progs.h" }
|
||||
@opensslsrc) -}
|
||||
GENERATE[progs.h]=progs.pl $(APPS_OPENSSL)
|
||||
DEPEND[progs.h]=../configdata.pm
|
||||
|
||||
SCRIPTS{misc}=CA.pl
|
||||
SOURCE[CA.pl]=CA.pl.in
|
||||
# linkname tells build files that a symbolic link or copy of this script
|
||||
|
||||
+1
-1
@@ -461,7 +461,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout,
|
||||
size_t len;
|
||||
int i, backslash = 0;
|
||||
|
||||
for (;;) {
|
||||
while (BIO_pending(bp) || !BIO_eof(bp)) {
|
||||
i = BIO_read(bp, (char *)buf, BUFSIZE);
|
||||
if (i < 0) {
|
||||
BIO_printf(bio_err, "Read Error in %s\n", file);
|
||||
|
||||
+5
-1
@@ -37,7 +37,7 @@ typedef enum OPTION_choice {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP,
|
||||
OPT_INFORM, OPT_OUTFORM, OPT_IN, OPT_OUT,
|
||||
OPT_ENGINE, OPT_CHECK, OPT_TEXT, OPT_NOOUT,
|
||||
OPT_DSAPARAM, OPT_C, OPT_2, OPT_5,
|
||||
OPT_DSAPARAM, OPT_C, OPT_2, OPT_3, OPT_5,
|
||||
OPT_R_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
@@ -55,6 +55,7 @@ const OPTIONS dhparam_options[] = {
|
||||
OPT_R_OPTIONS,
|
||||
{"C", OPT_C, '-', "Print C code"},
|
||||
{"2", OPT_2, '-', "Generate parameters using 2 as the generator value"},
|
||||
{"3", OPT_3, '-', "Generate parameters using 3 as the generator value"},
|
||||
{"5", OPT_5, '-', "Generate parameters using 5 as the generator value"},
|
||||
# ifndef OPENSSL_NO_DSA
|
||||
{"dsaparam", OPT_DSAPARAM, '-',
|
||||
@@ -125,6 +126,9 @@ int dhparam_main(int argc, char **argv)
|
||||
case OPT_2:
|
||||
g = 2;
|
||||
break;
|
||||
case OPT_3:
|
||||
g = 3;
|
||||
break;
|
||||
case OPT_5:
|
||||
g = 5;
|
||||
break;
|
||||
|
||||
+1
-1
@@ -273,7 +273,7 @@ int ecparam_main(int argc, char **argv)
|
||||
|
||||
if (check_named) {
|
||||
BIO_printf(bio_err, "validating named elliptic curve parameters: ");
|
||||
if (EC_GROUP_check_named_curve(group, 0) <= 0) {
|
||||
if (EC_GROUP_check_named_curve(group, 0, NULL) <= 0) {
|
||||
BIO_printf(bio_err, "failed\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
|
||||
+1
-1
@@ -586,7 +586,7 @@ int enc_main(int argc, char **argv)
|
||||
if (benc != NULL)
|
||||
wbio = BIO_push(benc, wbio);
|
||||
|
||||
for (;;) {
|
||||
while (BIO_pending(rbio) || !BIO_eof(rbio)) {
|
||||
inl = BIO_read(rbio, (char *)buff, bsize);
|
||||
if (inl <= 0)
|
||||
break;
|
||||
|
||||
@@ -0,0 +1,420 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <string.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/provider.h>
|
||||
#include <openssl/params.h>
|
||||
#include <openssl/fips_names.h>
|
||||
#include "apps.h"
|
||||
#include "progs.h"
|
||||
|
||||
#define BUFSIZE 4096
|
||||
#define DEFAULT_MAC_NAME "HMAC"
|
||||
#define DEFAULT_FIPS_SECTION "fips_check_section"
|
||||
|
||||
/* Configuration file values */
|
||||
#define VERSION_KEY "version"
|
||||
#define VERSION_VAL "1"
|
||||
#define INSTALL_STATUS_VAL "INSTALL_SELF_TEST_KATS_RUN"
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP,
|
||||
OPT_IN, OPT_OUT, OPT_MODULE,
|
||||
OPT_PROV_NAME, OPT_SECTION_NAME, OPT_MAC_NAME, OPT_MACOPT, OPT_VERIFY
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS fipsinstall_options[] = {
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{OPT_MORE_STR, 0, 0, "e.g: openssl fipsinstall -provider_name fips"
|
||||
"-section_name fipsinstall -out fips.conf -module ./fips.so"
|
||||
"-mac_name HMAC -macopt digest:SHA256 -macopt hexkey:00"},
|
||||
{"verify", OPT_VERIFY, '-', "Verification mode, i.e verify a config file "
|
||||
"instead of generating one"},
|
||||
{"in", OPT_IN, '<', "Input config file, used when verifying"},
|
||||
{"out", OPT_OUT, '>', "Output config file, used when generating"},
|
||||
{"module", OPT_MODULE, '<', "File name of the provider module"},
|
||||
{"provider_name", OPT_PROV_NAME, 's', "FIPS provider name"},
|
||||
{"section_name", OPT_SECTION_NAME, 's',
|
||||
"FIPS Provider config section name (optional)"},
|
||||
{"mac_name", OPT_MAC_NAME, 's', "MAC name"},
|
||||
{"macopt", OPT_MACOPT, 's', "MAC algorithm parameters in n:v form. "
|
||||
"See 'PARAMETER NAMES' in the EVP_MAC_ docs"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static int do_mac(EVP_MAC_CTX *ctx, unsigned char *tmp, BIO *in,
|
||||
unsigned char *out, size_t *out_len)
|
||||
{
|
||||
int ret = 0;
|
||||
int i;
|
||||
size_t outsz = *out_len;
|
||||
|
||||
if (!EVP_MAC_init(ctx))
|
||||
goto err;
|
||||
if (EVP_MAC_size(ctx) > outsz)
|
||||
goto end;
|
||||
while ((i = BIO_read(in, (char *)tmp, BUFSIZE)) != 0) {
|
||||
if (i < 0 || !EVP_MAC_update(ctx, tmp, i))
|
||||
goto err;
|
||||
}
|
||||
end:
|
||||
if (!EVP_MAC_final(ctx, out, out_len, outsz))
|
||||
goto err;
|
||||
ret = 1;
|
||||
err:
|
||||
return ret;
|
||||
}
|
||||
|
||||
static int load_fips_prov_and_run_self_test(const char *prov_name)
|
||||
{
|
||||
int ret = 0;
|
||||
OSSL_PROVIDER *prov = NULL;
|
||||
|
||||
prov = OSSL_PROVIDER_load(NULL, prov_name);
|
||||
if (prov == NULL) {
|
||||
BIO_printf(bio_err, "Failed to load FIPS module\n");
|
||||
goto end;
|
||||
}
|
||||
ret = 1;
|
||||
end:
|
||||
OSSL_PROVIDER_unload(prov);
|
||||
return ret;
|
||||
}
|
||||
|
||||
static int print_mac(BIO *bio, const char *label, const unsigned char *mac,
|
||||
size_t len)
|
||||
{
|
||||
int ret;
|
||||
char *hexstr = NULL;
|
||||
|
||||
hexstr = OPENSSL_buf2hexstr(mac, (long)len);
|
||||
if (hexstr == NULL)
|
||||
return 0;
|
||||
ret = BIO_printf(bio, "%s = %s\n", label, hexstr);
|
||||
OPENSSL_free(hexstr);
|
||||
return ret;
|
||||
}
|
||||
|
||||
static int write_config_header(BIO *out, const char *prov_name,
|
||||
const char *section)
|
||||
{
|
||||
return BIO_printf(out, "openssl_conf = openssl_init\n\n")
|
||||
&& BIO_printf(out, "[openssl_init]\n")
|
||||
&& BIO_printf(out, "providers = provider_section\n\n")
|
||||
&& BIO_printf(out, "[provider_section]\n")
|
||||
&& BIO_printf(out, "%s = %s\n\n", prov_name, section);
|
||||
}
|
||||
|
||||
/*
|
||||
* Outputs a fips related config file that contains entries for the fips
|
||||
* module checksum and the installation indicator checksum.
|
||||
*
|
||||
* Returns 1 if the config file is written otherwise it returns 0 on error.
|
||||
*/
|
||||
static int write_config_fips_section(BIO *out, const char *section,
|
||||
unsigned char *module_mac,
|
||||
size_t module_mac_len,
|
||||
unsigned char *install_mac,
|
||||
size_t install_mac_len)
|
||||
{
|
||||
int ret = 0;
|
||||
|
||||
if (!(BIO_printf(out, "[%s]\n", section) > 0
|
||||
&& BIO_printf(out, "activate = 1\n") > 0
|
||||
&& BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_INSTALL_VERSION,
|
||||
VERSION_VAL) > 0
|
||||
&& print_mac(out, OSSL_PROV_FIPS_PARAM_MODULE_MAC, module_mac,
|
||||
module_mac_len)))
|
||||
goto end;
|
||||
|
||||
if (install_mac != NULL) {
|
||||
if (!(print_mac(out, OSSL_PROV_FIPS_PARAM_INSTALL_MAC, install_mac,
|
||||
install_mac_len)
|
||||
&& BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_FIPS_PARAM_INSTALL_STATUS,
|
||||
INSTALL_STATUS_VAL) > 0))
|
||||
goto end;
|
||||
}
|
||||
ret = 1;
|
||||
end:
|
||||
return ret;
|
||||
}
|
||||
|
||||
static CONF *generate_config_and_load(const char *prov_name,
|
||||
const char *section,
|
||||
unsigned char *module_mac,
|
||||
size_t module_mac_len)
|
||||
{
|
||||
BIO *mem_bio = NULL;
|
||||
CONF *conf = NULL;
|
||||
|
||||
mem_bio = BIO_new(BIO_s_mem());
|
||||
if (mem_bio == NULL)
|
||||
return 0;
|
||||
if (!write_config_header(mem_bio, prov_name, section)
|
||||
|| !write_config_fips_section(mem_bio, section, module_mac,
|
||||
module_mac_len, NULL, 0))
|
||||
goto end;
|
||||
|
||||
conf = app_load_config_bio(mem_bio, NULL);
|
||||
if (conf == NULL)
|
||||
goto end;
|
||||
|
||||
if (!CONF_modules_load(conf, NULL, 0))
|
||||
goto end;
|
||||
BIO_free(mem_bio);
|
||||
return conf;
|
||||
end:
|
||||
NCONF_free(conf);
|
||||
BIO_free(mem_bio);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
static void free_config_and_unload(CONF *conf)
|
||||
{
|
||||
if (conf != NULL) {
|
||||
NCONF_free(conf);
|
||||
CONF_modules_unload(1);
|
||||
}
|
||||
}
|
||||
|
||||
/*
|
||||
* Returns 1 if the config file entries match the passed in module_mac and
|
||||
* install_mac values, otherwise it returns 0.
|
||||
*/
|
||||
static int verify_config(const char *infile, const char *section,
|
||||
unsigned char *module_mac, size_t module_mac_len,
|
||||
unsigned char *install_mac, size_t install_mac_len)
|
||||
{
|
||||
int ret = 0;
|
||||
char *s = NULL;
|
||||
unsigned char *buf1 = NULL, *buf2 = NULL;
|
||||
long len;
|
||||
CONF *conf = NULL;
|
||||
|
||||
/* read in the existing values and check they match the saved values */
|
||||
conf = app_load_config(infile);
|
||||
if (conf == NULL)
|
||||
goto end;
|
||||
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_VERSION);
|
||||
if (s == NULL || strcmp(s, VERSION_VAL) != 0) {
|
||||
BIO_printf(bio_err, "version not found\n");
|
||||
goto end;
|
||||
}
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_STATUS);
|
||||
if (s == NULL || strcmp(s, INSTALL_STATUS_VAL) != 0) {
|
||||
BIO_printf(bio_err, "install status not found\n");
|
||||
goto end;
|
||||
}
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_MODULE_MAC);
|
||||
if (s == NULL) {
|
||||
BIO_printf(bio_err, "Module integrity MAC not found\n");
|
||||
goto end;
|
||||
}
|
||||
buf1 = OPENSSL_hexstr2buf(s, &len);
|
||||
if (buf1 == NULL
|
||||
|| (size_t)len != module_mac_len
|
||||
|| memcmp(module_mac, buf1, module_mac_len) != 0) {
|
||||
BIO_printf(bio_err, "Module integrity mismatch\n");
|
||||
goto end;
|
||||
}
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_MAC);
|
||||
if (s == NULL) {
|
||||
BIO_printf(bio_err, "Install indicator MAC not found\n");
|
||||
goto end;
|
||||
}
|
||||
buf2 = OPENSSL_hexstr2buf(s, &len);
|
||||
if (buf2 == NULL
|
||||
|| (size_t)len != install_mac_len
|
||||
|| memcmp(install_mac, buf2, install_mac_len) != 0) {
|
||||
BIO_printf(bio_err, "Install indicator status mismatch\n");
|
||||
goto end;
|
||||
}
|
||||
ret = 1;
|
||||
end:
|
||||
OPENSSL_free(buf1);
|
||||
OPENSSL_free(buf2);
|
||||
NCONF_free(conf);
|
||||
return ret;
|
||||
}
|
||||
|
||||
int fipsinstall_main(int argc, char **argv)
|
||||
{
|
||||
int ret = 1, verify = 0;
|
||||
BIO *module_bio = NULL, *mem_bio = NULL, *fout = NULL;
|
||||
char *in_fname = NULL, *out_fname = NULL, *prog, *section_name = NULL;
|
||||
char *prov_name = NULL, *module_fname = NULL;
|
||||
static const char *mac_name = DEFAULT_MAC_NAME;
|
||||
EVP_MAC_CTX *ctx = NULL, *ctx2 = NULL;
|
||||
STACK_OF(OPENSSL_STRING) *opts = NULL;
|
||||
OPTION_CHOICE o;
|
||||
unsigned char *read_buffer = NULL;
|
||||
unsigned char module_mac[EVP_MAX_MD_SIZE];
|
||||
size_t module_mac_len = EVP_MAX_MD_SIZE;
|
||||
unsigned char install_mac[EVP_MAX_MD_SIZE];
|
||||
size_t install_mac_len = EVP_MAX_MD_SIZE;
|
||||
EVP_MAC *mac = NULL;
|
||||
CONF *conf = NULL;
|
||||
|
||||
section_name = DEFAULT_FIPS_SECTION;
|
||||
|
||||
prog = opt_init(argc, argv, fipsinstall_options);
|
||||
while ((o = opt_next()) != OPT_EOF) {
|
||||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
opt_help(fipsinstall_options);
|
||||
ret = 0;
|
||||
goto end;
|
||||
case OPT_IN:
|
||||
in_fname = opt_arg();
|
||||
break;
|
||||
case OPT_OUT:
|
||||
out_fname = opt_arg();
|
||||
break;
|
||||
case OPT_PROV_NAME:
|
||||
prov_name = opt_arg();
|
||||
break;
|
||||
case OPT_MODULE:
|
||||
module_fname = opt_arg();
|
||||
break;
|
||||
case OPT_SECTION_NAME:
|
||||
section_name = opt_arg();
|
||||
break;
|
||||
case OPT_MAC_NAME:
|
||||
mac_name = opt_arg();
|
||||
break;
|
||||
case OPT_MACOPT:
|
||||
if (opts == NULL)
|
||||
opts = sk_OPENSSL_STRING_new_null();
|
||||
if (opts == NULL || !sk_OPENSSL_STRING_push(opts, opt_arg()))
|
||||
goto opthelp;
|
||||
break;
|
||||
case OPT_VERIFY:
|
||||
verify = 1;
|
||||
break;
|
||||
}
|
||||
}
|
||||
argc = opt_num_rest();
|
||||
if (module_fname == NULL
|
||||
|| (verify && in_fname == NULL)
|
||||
|| (!verify && (out_fname == NULL || prov_name == NULL))
|
||||
|| opts == NULL
|
||||
|| argc != 0)
|
||||
goto opthelp;
|
||||
|
||||
module_bio = bio_open_default(module_fname, 'r', FORMAT_BINARY);
|
||||
if (module_bio == NULL) {
|
||||
BIO_printf(bio_err, "Failed to open module file\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
read_buffer = app_malloc(BUFSIZE, "I/O buffer");
|
||||
if (read_buffer == NULL)
|
||||
goto end;
|
||||
|
||||
mac = EVP_MAC_fetch(NULL, mac_name, NULL);
|
||||
if (mac == NULL) {
|
||||
BIO_printf(bio_err, "Unable to get MAC of type %s\n", mac_name);
|
||||
goto end;
|
||||
}
|
||||
|
||||
ctx = EVP_MAC_CTX_new(mac);
|
||||
if (ctx == NULL) {
|
||||
BIO_printf(bio_err, "Unable to create MAC CTX for module check\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (opts != NULL) {
|
||||
int ok = 1;
|
||||
OSSL_PARAM *params =
|
||||
app_params_new_from_opts(opts, EVP_MAC_CTX_settable_params(mac));
|
||||
|
||||
if (params == NULL)
|
||||
goto end;
|
||||
|
||||
if (!EVP_MAC_CTX_set_params(ctx, params)) {
|
||||
BIO_printf(bio_err, "MAC parameter error\n");
|
||||
ERR_print_errors(bio_err);
|
||||
ok = 0;
|
||||
}
|
||||
app_params_free(params);
|
||||
if (!ok)
|
||||
goto end;
|
||||
}
|
||||
|
||||
ctx2 = EVP_MAC_CTX_dup(ctx);
|
||||
if (ctx2 == NULL) {
|
||||
BIO_printf(bio_err, "Unable to create MAC CTX for install indicator\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (!do_mac(ctx, read_buffer, module_bio, module_mac, &module_mac_len))
|
||||
goto end;
|
||||
|
||||
mem_bio = BIO_new_mem_buf((const void *)INSTALL_STATUS_VAL,
|
||||
strlen(INSTALL_STATUS_VAL));
|
||||
if (mem_bio == NULL) {
|
||||
BIO_printf(bio_err, "Unable to create memory BIO\n");
|
||||
goto end;
|
||||
}
|
||||
if (!do_mac(ctx2, read_buffer, mem_bio, install_mac, &install_mac_len))
|
||||
goto end;
|
||||
|
||||
if (verify) {
|
||||
if (!verify_config(in_fname, section_name, module_mac, module_mac_len,
|
||||
install_mac, install_mac_len))
|
||||
goto end;
|
||||
BIO_printf(bio_out, "VERIFY PASSED\n");
|
||||
} else {
|
||||
|
||||
conf = generate_config_and_load(prov_name, section_name, module_mac,
|
||||
module_mac_len);
|
||||
if (conf == NULL)
|
||||
goto end;
|
||||
if (!load_fips_prov_and_run_self_test(prov_name))
|
||||
goto end;
|
||||
|
||||
fout = bio_open_default(out_fname, 'w', FORMAT_TEXT);
|
||||
if (fout == NULL) {
|
||||
BIO_printf(bio_err, "Failed to open file\n");
|
||||
goto end;
|
||||
}
|
||||
if (!write_config_fips_section(fout, section_name, module_mac,
|
||||
module_mac_len, install_mac,
|
||||
install_mac_len))
|
||||
goto end;
|
||||
BIO_printf(bio_out, "INSTALL PASSED\n");
|
||||
}
|
||||
|
||||
ret = 0;
|
||||
end:
|
||||
if (ret == 1) {
|
||||
BIO_printf(bio_err, "%s FAILED\n", verify ? "VERIFY" : "INSTALL");
|
||||
ERR_print_errors(bio_err);
|
||||
}
|
||||
|
||||
BIO_free(fout);
|
||||
BIO_free(mem_bio);
|
||||
BIO_free(module_bio);
|
||||
sk_OPENSSL_STRING_free(opts);
|
||||
EVP_MAC_free(mac);
|
||||
EVP_MAC_CTX_free(ctx2);
|
||||
EVP_MAC_CTX_free(ctx);
|
||||
OPENSSL_free(read_buffer);
|
||||
free_config_and_unload(conf);
|
||||
return ret;
|
||||
}
|
||||
@@ -0,0 +1,13 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <openssl/core.h>
|
||||
|
||||
int print_param_types(const char *thing, const OSSL_PARAM *pdefs, int indent);
|
||||
|
||||
+4
-2
@@ -102,11 +102,9 @@ typedef struct args_st {
|
||||
int wrap_password_callback(char *buf, int bufsiz, int verify, void *cb_data);
|
||||
|
||||
int chopup_args(ARGS *arg, char *buf);
|
||||
# ifdef HEADER_X509_H
|
||||
int dump_cert_text(BIO *out, X509 *x);
|
||||
void print_name(BIO *out, const char *title, X509_NAME *nm,
|
||||
unsigned long lflags);
|
||||
# endif
|
||||
void print_bignum_var(BIO *, const BIGNUM *, const char*,
|
||||
int, unsigned char *);
|
||||
void print_array(BIO *, const char *, int, const unsigned char *);
|
||||
@@ -266,4 +264,8 @@ typedef struct verify_options_st {
|
||||
|
||||
extern VERIFY_CB_ARGS verify_args;
|
||||
|
||||
OSSL_PARAM *app_params_new_from_opts(STACK_OF(OPENSSL_STRING) *opts,
|
||||
const OSSL_PARAM *paramdefs);
|
||||
void app_params_free(OSSL_PARAM *params);
|
||||
|
||||
#endif
|
||||
@@ -0,0 +1,40 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#ifndef APPS_FUNCTION_H
|
||||
# define APPS_FUNCTION_H
|
||||
|
||||
# include <openssl/lhash.h>
|
||||
# include "opt.h"
|
||||
|
||||
typedef enum FUNC_TYPE {
|
||||
FT_none, FT_general, FT_md, FT_cipher, FT_pkey,
|
||||
FT_md_alg, FT_cipher_alg
|
||||
} FUNC_TYPE;
|
||||
|
||||
typedef struct function_st {
|
||||
FUNC_TYPE type;
|
||||
const char *name;
|
||||
int (*func)(int argc, char *argv[]);
|
||||
const OPTIONS *help;
|
||||
} FUNCTION;
|
||||
|
||||
DEFINE_LHASH_OF(FUNCTION);
|
||||
|
||||
/* Structure to hold the number of columns to be displayed and the
|
||||
* field width used to display them.
|
||||
*/
|
||||
typedef struct {
|
||||
int columns;
|
||||
int width;
|
||||
} DISPLAY_COLUMNS;
|
||||
|
||||
void calculate_columns(FUNCTION *functions, DISPLAY_COLUMNS *dc);
|
||||
|
||||
#endif
|
||||
@@ -266,6 +266,7 @@
|
||||
*/
|
||||
extern const char OPT_HELP_STR[];
|
||||
extern const char OPT_MORE_STR[];
|
||||
extern const char OPT_SECTION_STR[];
|
||||
typedef struct options_st {
|
||||
const char *name;
|
||||
int retval;
|
||||
@@ -307,6 +308,9 @@ typedef struct string_int_pair_st {
|
||||
OPT_FMT_ENGINE | OPT_FMT_MSBLOB | OPT_FMT_NSS | \
|
||||
OPT_FMT_TEXT | OPT_FMT_HTTP | OPT_FMT_PVK)
|
||||
|
||||
/* Divide options into sections when displaying usage */
|
||||
#define OPT_SECTION(sec) {OPT_SECTION_STR, 1, '-', sec " options:\n"}
|
||||
|
||||
char *opt_progname(const char *argv0);
|
||||
char *opt_getprog(void);
|
||||
char *opt_init(int ac, char **av, const OPTIONS * o);
|
||||
@@ -338,6 +342,7 @@ int opt_num_rest(void);
|
||||
int opt_verify(int i, X509_VERIFY_PARAM *vpm);
|
||||
int opt_rand(int i);
|
||||
void opt_help(const OPTIONS * list);
|
||||
void opt_print(const OPTIONS * opt, int width);
|
||||
int opt_format_error(const char *s, unsigned long flags);
|
||||
int opt_isdir(const char *name);
|
||||
int opt_printf_stderr(const char *fmt, ...);
|
||||
|
||||
+3
-15
@@ -9,13 +9,7 @@
|
||||
|
||||
#include <openssl/opensslconf.h>
|
||||
|
||||
#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS)
|
||||
# include <conio.h>
|
||||
#endif
|
||||
|
||||
#if defined(OPENSSL_SYS_MSDOS) && !defined(_WIN32)
|
||||
# define _kbhit kbhit
|
||||
#endif
|
||||
#include <openssl/ssl.h>
|
||||
|
||||
#define PORT "4433"
|
||||
#define PROTOCOL "tcp"
|
||||
@@ -24,17 +18,15 @@ typedef int (*do_server_cb)(int s, int stype, int prot, unsigned char *context);
|
||||
int do_server(int *accept_sock, const char *host, const char *port,
|
||||
int family, int type, int protocol, do_server_cb cb,
|
||||
unsigned char *context, int naccept, BIO *bio_s_out);
|
||||
#ifdef HEADER_X509_H
|
||||
|
||||
int verify_callback(int ok, X509_STORE_CTX *ctx);
|
||||
#endif
|
||||
#ifdef HEADER_SSL_H
|
||||
|
||||
int set_cert_stuff(SSL_CTX *ctx, char *cert_file, char *key_file);
|
||||
int set_cert_key_stuff(SSL_CTX *ctx, X509 *cert, EVP_PKEY *key,
|
||||
STACK_OF(X509) *chain, int build_chain);
|
||||
int ssl_print_sigalgs(BIO *out, SSL *s);
|
||||
int ssl_print_point_formats(BIO *out, SSL *s);
|
||||
int ssl_print_groups(BIO *out, SSL *s, int noshared);
|
||||
#endif
|
||||
int ssl_print_tmp_key(BIO *out, SSL *s);
|
||||
int init_client(int *sock, const char *host, const char *port,
|
||||
const char *bindhost, const char *bindport,
|
||||
@@ -44,13 +36,11 @@ int should_retry(int i);
|
||||
long bio_dump_callback(BIO *bio, int cmd, const char *argp,
|
||||
int argi, long argl, long ret);
|
||||
|
||||
#ifdef HEADER_SSL_H
|
||||
void apps_ssl_info_callback(const SSL *s, int where, int ret);
|
||||
void msg_cb(int write_p, int version, int content_type, const void *buf,
|
||||
size_t len, SSL *ssl, void *arg);
|
||||
void tlsext_cb(SSL *s, int client_server, int type, const unsigned char *data,
|
||||
int len, void *arg);
|
||||
#endif
|
||||
|
||||
int generate_cookie_callback(SSL *ssl, unsigned char *cookie,
|
||||
unsigned int *cookie_len);
|
||||
@@ -75,7 +65,6 @@ int args_excert(int option, SSL_EXCERT **pexc);
|
||||
int load_excert(SSL_EXCERT **pexc);
|
||||
void print_verify_detail(SSL *s, BIO *bio);
|
||||
void print_ssl_summary(SSL *s);
|
||||
#ifdef HEADER_SSL_H
|
||||
int config_ctx(SSL_CONF_CTX *cctx, STACK_OF(OPENSSL_STRING) *str, SSL_CTX *ctx);
|
||||
int ssl_ctx_add_crls(SSL_CTX *ctx, STACK_OF(X509_CRL) *crls,
|
||||
int crl_download);
|
||||
@@ -86,4 +75,3 @@ int ssl_load_stores(SSL_CTX *ctx, const char *vfyCApath,
|
||||
void ssl_ctx_security_debug(SSL_CTX *ctx, int verbose);
|
||||
int set_keylog_file(SSL_CTX *ctx, const char *keylog_file);
|
||||
void print_ca_names(BIO *bio, SSL *s);
|
||||
#endif
|
||||
+11
-1
@@ -14,7 +14,7 @@
|
||||
typedef enum OPTION_choice {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP,
|
||||
OPT_CONFIGDIR, OPT_ENGINESDIR, OPT_MODULESDIR, OPT_DSOEXT, OPT_DIRNAMESEP,
|
||||
OPT_LISTSEP
|
||||
OPT_LISTSEP, OPT_SEEDS, OPT_CPUSETTINGS
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS info_options[] = {
|
||||
@@ -30,6 +30,8 @@ const OPTIONS info_options[] = {
|
||||
{"dsoext", OPT_DSOEXT, '-', "Configured extension for modules"},
|
||||
{"dirnamesep", OPT_DIRNAMESEP, '-', "Directory-filename separator"},
|
||||
{"listsep", OPT_LISTSEP, '-', "List separator character"},
|
||||
{"seeds", OPT_SEEDS, '-', "Seed sources"},
|
||||
{"cpusettings", OPT_CPUSETTINGS, '-', "CPU settings info"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
@@ -74,6 +76,14 @@ opthelp:
|
||||
type = OPENSSL_INFO_LIST_SEPARATOR;
|
||||
dirty++;
|
||||
break;
|
||||
case OPT_SEEDS:
|
||||
type = OPENSSL_INFO_SEED_SOURCE;
|
||||
dirty++;
|
||||
break;
|
||||
case OPT_CPUSETTINGS:
|
||||
type = OPENSSL_INFO_CPU_SETTINGS;
|
||||
dirty++;
|
||||
break;
|
||||
}
|
||||
}
|
||||
if (opt_num_rest() != 0) {
|
||||
|
||||
+20
-29
@@ -15,6 +15,7 @@
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/kdf.h>
|
||||
#include <openssl/params.h>
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP,
|
||||
@@ -34,27 +35,9 @@ const OPTIONS kdf_options[] = {
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static int kdf_ctrl_string(EVP_KDF_CTX *ctx, const char *value)
|
||||
{
|
||||
int rv;
|
||||
char *stmp, *vtmp = NULL;
|
||||
|
||||
stmp = OPENSSL_strdup(value);
|
||||
if (stmp == NULL)
|
||||
return -1;
|
||||
vtmp = strchr(stmp, ':');
|
||||
if (vtmp != NULL) {
|
||||
*vtmp = 0;
|
||||
vtmp++;
|
||||
}
|
||||
rv = EVP_KDF_ctrl_str(ctx, stmp, vtmp);
|
||||
OPENSSL_free(stmp);
|
||||
return rv;
|
||||
}
|
||||
|
||||
int kdf_main(int argc, char **argv)
|
||||
{
|
||||
int ret = 1, i, id, out_bin = 0;
|
||||
int ret = 1, out_bin = 0;
|
||||
OPTION_CHOICE o;
|
||||
STACK_OF(OPENSSL_STRING) *opts = NULL;
|
||||
char *prog, *hexout = NULL;
|
||||
@@ -62,6 +45,7 @@ int kdf_main(int argc, char **argv)
|
||||
unsigned char *dkm_bytes = NULL;
|
||||
size_t dkm_len = 0;
|
||||
BIO *out = NULL;
|
||||
EVP_KDF *kdf = NULL;
|
||||
EVP_KDF_CTX *ctx = NULL;
|
||||
|
||||
prog = opt_init(argc, argv, kdf_options);
|
||||
@@ -100,25 +84,31 @@ opthelp:
|
||||
goto opthelp;
|
||||
}
|
||||
|
||||
id = OBJ_sn2nid(argv[0]);
|
||||
if (id == NID_undef) {
|
||||
if ((kdf = EVP_KDF_fetch(NULL, argv[0], NULL)) == NULL) {
|
||||
BIO_printf(bio_err, "Invalid KDF name %s\n", argv[0]);
|
||||
goto opthelp;
|
||||
}
|
||||
|
||||
ctx = EVP_KDF_CTX_new_id(id);
|
||||
ctx = EVP_KDF_CTX_new(kdf);
|
||||
if (ctx == NULL)
|
||||
goto err;
|
||||
|
||||
if (opts != NULL) {
|
||||
for (i = 0; i < sk_OPENSSL_STRING_num(opts); i++) {
|
||||
char *opt = sk_OPENSSL_STRING_value(opts, i);
|
||||
if (kdf_ctrl_string(ctx, opt) <= 0) {
|
||||
BIO_printf(bio_err, "KDF parameter error '%s'\n", opt);
|
||||
ERR_print_errors(bio_err);
|
||||
goto err;
|
||||
}
|
||||
int ok = 1;
|
||||
OSSL_PARAM *params =
|
||||
app_params_new_from_opts(opts, EVP_KDF_CTX_settable_params(kdf));
|
||||
|
||||
if (params == NULL)
|
||||
goto err;
|
||||
|
||||
if (!EVP_KDF_CTX_set_params(ctx, params)) {
|
||||
BIO_printf(bio_err, "KDF parameter error\n");
|
||||
ERR_print_errors(bio_err);
|
||||
ok = 0;
|
||||
}
|
||||
app_params_free(params);
|
||||
if (!ok)
|
||||
goto err;
|
||||
}
|
||||
|
||||
out = bio_open_default(outfile, 'w', out_bin ? FORMAT_BINARY : FORMAT_TEXT);
|
||||
@@ -151,6 +141,7 @@ err:
|
||||
ERR_print_errors(bio_err);
|
||||
OPENSSL_clear_free(dkm_bytes, dkm_len);
|
||||
sk_OPENSSL_STRING_free(opts);
|
||||
EVP_KDF_free(kdf);
|
||||
EVP_KDF_CTX_free(ctx);
|
||||
BIO_free(out);
|
||||
OPENSSL_free(hexout);
|
||||
|
||||
@@ -0,0 +1,96 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include "apps.h"
|
||||
#include "app_params.h"
|
||||
|
||||
static int describe_param_type(char *buf, size_t bufsz, const OSSL_PARAM *param)
|
||||
{
|
||||
const char *type_mod = "";
|
||||
const char *type = NULL;
|
||||
int show_type_number = 0;
|
||||
int printed_len;
|
||||
|
||||
switch (param->data_type) {
|
||||
case OSSL_PARAM_UNSIGNED_INTEGER:
|
||||
type_mod = "unsigned ";
|
||||
/* FALLTHRU */
|
||||
case OSSL_PARAM_INTEGER:
|
||||
type = "integer";
|
||||
break;
|
||||
case OSSL_PARAM_UTF8_PTR:
|
||||
type_mod = "pointer to a ";
|
||||
/* FALLTHRU */
|
||||
case OSSL_PARAM_UTF8_STRING:
|
||||
type = "UTF8 encoded string";
|
||||
break;
|
||||
case OSSL_PARAM_OCTET_PTR:
|
||||
type_mod = "pointer to an ";
|
||||
/* FALLTHRU */
|
||||
case OSSL_PARAM_OCTET_STRING:
|
||||
type = "octet string";
|
||||
break;
|
||||
default:
|
||||
type = "unknown type";
|
||||
show_type_number = 1;
|
||||
break;
|
||||
}
|
||||
|
||||
printed_len = BIO_snprintf(buf, bufsz, "%s: ", param->key);
|
||||
if (printed_len > 0) {
|
||||
buf += printed_len;
|
||||
bufsz -= printed_len;
|
||||
}
|
||||
printed_len = BIO_snprintf(buf, bufsz, "%s%s", type_mod, type);
|
||||
if (printed_len > 0) {
|
||||
buf += printed_len;
|
||||
bufsz -= printed_len;
|
||||
}
|
||||
if (show_type_number) {
|
||||
printed_len = BIO_snprintf(buf, bufsz, " [%d]", param->data_type);
|
||||
if (printed_len > 0) {
|
||||
buf += printed_len;
|
||||
bufsz -= printed_len;
|
||||
}
|
||||
}
|
||||
if (param->data_size == 0)
|
||||
printed_len = BIO_snprintf(buf, bufsz, " (arbitrary size)");
|
||||
else
|
||||
printed_len = BIO_snprintf(buf, bufsz, " (max %zu bytes large)",
|
||||
param->data_size);
|
||||
if (printed_len > 0) {
|
||||
buf += printed_len;
|
||||
bufsz -= printed_len;
|
||||
}
|
||||
*buf = '\0';
|
||||
return 1;
|
||||
}
|
||||
|
||||
int print_param_types(const char *thing, const OSSL_PARAM *pdefs, int indent)
|
||||
{
|
||||
if (pdefs == NULL) {
|
||||
BIO_printf(bio_out, "%*sNo declared %s\n", indent, "", thing);
|
||||
} else if (pdefs->key == NULL) {
|
||||
/*
|
||||
* An empty list? This shouldn't happen, but let's just make sure to
|
||||
* say something if there's a badly written provider...
|
||||
*/
|
||||
BIO_printf(bio_out, "%*sEmpty list of %s (!!!)\n", indent, "", thing);
|
||||
} else {
|
||||
BIO_printf(bio_out, "%*s%s:\n", indent, "", thing);
|
||||
for (; pdefs->key != NULL; pdefs++) {
|
||||
char buf[200]; /* This should be ample space */
|
||||
|
||||
describe_param_type(buf, sizeof(buf), pdefs);
|
||||
BIO_printf(bio_out, "%*s %s\n", indent, "", buf);
|
||||
}
|
||||
}
|
||||
return 1;
|
||||
}
|
||||
|
||||
@@ -40,7 +40,6 @@
|
||||
#endif
|
||||
#include <openssl/bn.h>
|
||||
#include <openssl/ssl.h>
|
||||
#include "s_apps.h"
|
||||
#include "apps.h"
|
||||
|
||||
#ifdef _WIN32
|
||||
@@ -48,6 +47,14 @@ static int WIN32_rename(const char *from, const char *to);
|
||||
# define rename(from,to) WIN32_rename((from),(to))
|
||||
#endif
|
||||
|
||||
#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS)
|
||||
# include <conio.h>
|
||||
#endif
|
||||
|
||||
#if defined(OPENSSL_SYS_MSDOS) && !defined(_WIN32)
|
||||
# define _kbhit kbhit
|
||||
#endif
|
||||
|
||||
#define PASS_SOURCE_SIZE_MAX 4
|
||||
|
||||
typedef struct {
|
||||
@@ -1388,8 +1395,8 @@ CA_DB *load_index(const char *dbfile, DB_ATTR *db_attr)
|
||||
#ifndef OPENSSL_NO_POSIX_IO
|
||||
BIO_get_fp(in, &dbfp);
|
||||
if (fstat(fileno(dbfp), &dbst) == -1) {
|
||||
SYSerr(SYS_F_FSTAT, errno);
|
||||
ERR_add_error_data(3, "fstat('", dbfile, "')");
|
||||
ERR_raise_data(ERR_LIB_SYS, errno,
|
||||
"calling fstat(%s)", dbfile);
|
||||
ERR_print_errors(bio_err);
|
||||
goto err;
|
||||
}
|
||||
@@ -2559,3 +2566,53 @@ int opt_printf_stderr(const char *fmt, ...)
|
||||
va_end(ap);
|
||||
return ret;
|
||||
}
|
||||
|
||||
OSSL_PARAM *app_params_new_from_opts(STACK_OF(OPENSSL_STRING) *opts,
|
||||
const OSSL_PARAM *paramdefs)
|
||||
{
|
||||
OSSL_PARAM *params = NULL;
|
||||
size_t sz = (size_t)sk_OPENSSL_STRING_num(opts);
|
||||
size_t params_n;
|
||||
char *opt = "", *stmp, *vtmp = NULL;
|
||||
|
||||
if (opts == NULL)
|
||||
return NULL;
|
||||
|
||||
params = OPENSSL_zalloc(sizeof(OSSL_PARAM) * (sz + 1));
|
||||
if (params == NULL)
|
||||
return NULL;
|
||||
|
||||
for (params_n = 0; params_n < sz; params_n++) {
|
||||
opt = sk_OPENSSL_STRING_value(opts, (int)params_n);
|
||||
if ((stmp = OPENSSL_strdup(opt)) == NULL
|
||||
|| (vtmp = strchr(stmp, ':')) == NULL)
|
||||
goto err;
|
||||
/* Replace ':' with 0 to terminate the string pointed to by stmp */
|
||||
*vtmp = 0;
|
||||
/* Skip over the separator so that vmtp points to the value */
|
||||
vtmp++;
|
||||
if (!OSSL_PARAM_allocate_from_text(¶ms[params_n], paramdefs,
|
||||
stmp, vtmp, strlen(vtmp)))
|
||||
goto err;
|
||||
OPENSSL_free(stmp);
|
||||
}
|
||||
params[params_n] = OSSL_PARAM_construct_end();
|
||||
return params;
|
||||
err:
|
||||
OPENSSL_free(stmp);
|
||||
BIO_printf(bio_err, "Parameter error '%s'\n", opt);
|
||||
ERR_print_errors(bio_err);
|
||||
app_params_free(params);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
void app_params_free(OSSL_PARAM *params)
|
||||
{
|
||||
int i;
|
||||
|
||||
if (params != NULL) {
|
||||
for (i = 0; params[i].key != NULL; ++i)
|
||||
OPENSSL_free(params[i].data);
|
||||
OPENSSL_free(params);
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,18 @@
|
||||
# Auxilliary program source
|
||||
IF[{- $config{target} =~ /^(?:VC-|mingw)/ -}]
|
||||
# It's called 'init', but doesn't have much 'init' in it...
|
||||
$AUXLIBAPPSSRC=win32_init.c
|
||||
ENDIF
|
||||
IF[{- $config{target} =~ /^vms-/ -}]
|
||||
$AUXLIBAPPSSRC=vms_term_sock.c vms_decc_argv.c
|
||||
ENDIF
|
||||
|
||||
# Source for libapps
|
||||
$LIBAPPSSRC=apps.c apps_ui.c opt.c fmt.c s_cb.c s_socket.c app_rand.c \
|
||||
bf_prefix.c columns.c app_params.c
|
||||
|
||||
IF[{- !$disabled{apps} -}]
|
||||
LIBS{noinst}=../libapps.a
|
||||
SOURCE[../libapps.a]=$LIBAPPSSRC $AUXLIBAPPSSRC
|
||||
INCLUDE[../libapps.a]=../.. ../../include ../include
|
||||
ENDIF
|
||||
@@ -0,0 +1,27 @@
|
||||
/*
|
||||
* Copyright 2017-2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <string.h>
|
||||
#include "apps.h"
|
||||
#include "function.h"
|
||||
|
||||
void calculate_columns(FUNCTION *functions, DISPLAY_COLUMNS *dc)
|
||||
{
|
||||
FUNCTION *f;
|
||||
int len, maxlen = 0;
|
||||
|
||||
for (f = functions; f->name != NULL; ++f)
|
||||
if (f->type == FT_general || f->type == FT_md || f->type == FT_cipher)
|
||||
if ((len = strlen(f->name)) > maxlen)
|
||||
maxlen = len;
|
||||
|
||||
dc->width = maxlen + 2;
|
||||
dc->columns = (80 - 1) / dc->width;
|
||||
}
|
||||
|
||||
+42
-30
@@ -28,6 +28,7 @@
|
||||
#define MAX_OPT_HELP_WIDTH 30
|
||||
const char OPT_HELP_STR[] = "--";
|
||||
const char OPT_MORE_STR[] = "---";
|
||||
const char OPT_SECTION_STR[] = "----";
|
||||
|
||||
/* Our state */
|
||||
static char **argv;
|
||||
@@ -133,7 +134,8 @@ char *opt_init(int ac, char **av, const OPTIONS *o)
|
||||
int duplicated, i;
|
||||
#endif
|
||||
|
||||
if (o->name == OPT_HELP_STR || o->name == OPT_MORE_STR)
|
||||
if (o->name == OPT_HELP_STR || o->name == OPT_MORE_STR ||
|
||||
o->name == OPT_SECTION_STR)
|
||||
continue;
|
||||
#ifndef NDEBUG
|
||||
i = o->valtype;
|
||||
@@ -832,40 +834,16 @@ static const char *valtype2param(const OPTIONS *o)
|
||||
return "parm";
|
||||
}
|
||||
|
||||
void opt_help(const OPTIONS *list)
|
||||
void opt_print(const OPTIONS *o, int width)
|
||||
{
|
||||
const OPTIONS *o;
|
||||
int i;
|
||||
int standard_prolog;
|
||||
int width = 5;
|
||||
const char* help;
|
||||
char start[80 + 1];
|
||||
char *p;
|
||||
const char *help;
|
||||
|
||||
/* Starts with its own help message? */
|
||||
standard_prolog = list[0].name != OPT_HELP_STR;
|
||||
|
||||
/* Find the widest help. */
|
||||
for (o = list; o->name; o++) {
|
||||
if (o->name == OPT_MORE_STR)
|
||||
continue;
|
||||
i = 2 + (int)strlen(o->name);
|
||||
if (o->valtype != '-')
|
||||
i += 1 + strlen(valtype2param(o));
|
||||
if (i < MAX_OPT_HELP_WIDTH && i > width)
|
||||
width = i;
|
||||
OPENSSL_assert(i < (int)sizeof(start));
|
||||
}
|
||||
|
||||
if (standard_prolog)
|
||||
opt_printf_stderr("Usage: %s [options]\nValid options are:\n", prog);
|
||||
|
||||
/* Now let's print. */
|
||||
for (o = list; o->name; o++) {
|
||||
help = o->helpstr ? o->helpstr : "(No additional info)";
|
||||
if (o->name == OPT_HELP_STR) {
|
||||
if (o->name == OPT_HELP_STR || o->name == OPT_SECTION_STR) {
|
||||
opt_printf_stderr(help, prog);
|
||||
continue;
|
||||
return;
|
||||
}
|
||||
|
||||
/* Pad out prefix */
|
||||
@@ -876,7 +854,7 @@ void opt_help(const OPTIONS *list)
|
||||
/* Continuation of previous line; pad and print. */
|
||||
start[width] = '\0';
|
||||
opt_printf_stderr("%s %s\n", start, help);
|
||||
continue;
|
||||
return;
|
||||
}
|
||||
|
||||
/* Build up the "-flag [param]" part. */
|
||||
@@ -899,6 +877,40 @@ void opt_help(const OPTIONS *list)
|
||||
}
|
||||
start[width] = '\0';
|
||||
opt_printf_stderr("%s %s\n", start, help);
|
||||
}
|
||||
|
||||
void opt_help(const OPTIONS *list)
|
||||
{
|
||||
const OPTIONS *o;
|
||||
int i;
|
||||
int standard_prolog;
|
||||
int width = 5;
|
||||
char start[80 + 1];
|
||||
|
||||
/* Starts with its own help message? */
|
||||
standard_prolog = list[0].name != OPT_HELP_STR;
|
||||
|
||||
/* Find the widest help. */
|
||||
for (o = list; o->name; o++) {
|
||||
if (o->name == OPT_MORE_STR)
|
||||
continue;
|
||||
i = 2 + (int)strlen(o->name);
|
||||
if (o->valtype != '-')
|
||||
i += 1 + strlen(valtype2param(o));
|
||||
if (i < MAX_OPT_HELP_WIDTH && i > width)
|
||||
width = i;
|
||||
OPENSSL_assert(i < (int)sizeof(start));
|
||||
}
|
||||
|
||||
if (standard_prolog) {
|
||||
opt_printf_stderr("Usage: %s [options]\n", prog);
|
||||
if (list[0].name != OPT_SECTION_STR)
|
||||
opt_printf_stderr("Valid options are:\n", prog);
|
||||
}
|
||||
|
||||
/* Now let's print. */
|
||||
for (o = list; o->name; o++) {
|
||||
opt_print(o, width);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1508,7 +1508,8 @@ void print_ca_names(BIO *bio, SSL *s)
|
||||
int i;
|
||||
|
||||
if (sk == NULL || sk_X509_NAME_num(sk) == 0) {
|
||||
BIO_printf(bio, "---\nNo %s certificate CA names sent\n", cs);
|
||||
if (!SSL_is_server(s))
|
||||
BIO_printf(bio, "---\nNo %s certificate CA names sent\n", cs);
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -238,8 +238,8 @@ int TerminalSocket (int FunctionCode, int *ReturnSocket)
|
||||
}
|
||||
|
||||
/*
|
||||
** Deassign the terminal channel
|
||||
*/
|
||||
** Deassign the terminal channel
|
||||
*/
|
||||
status = sys$dassgn (TerminalDeviceChan);
|
||||
if (! (status & 1)) {
|
||||
LogMessage ("TerminalSocket: SYS$DASSGN () - %08X", status);
|
||||
@@ -255,15 +255,15 @@ int TerminalSocket (int FunctionCode, int *ReturnSocket)
|
||||
close (TerminalSocketPair[1]);
|
||||
|
||||
/*
|
||||
** Return the initialized socket
|
||||
*/
|
||||
** Return the initialized socket
|
||||
*/
|
||||
*ReturnSocket = 0;
|
||||
break;
|
||||
|
||||
default:
|
||||
/*
|
||||
** Invalid function code
|
||||
*/
|
||||
** Invalid function code
|
||||
*/
|
||||
LogMessage ("TerminalSocket: Invalid Function Code - %d", FunctionCode);
|
||||
return TERM_SOCK_FAILURE;
|
||||
break;
|
||||
+739
@@ -0,0 +1,739 @@
|
||||
/*
|
||||
* Copyright 1995-2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <string.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/provider.h>
|
||||
#include <openssl/safestack.h>
|
||||
#include <openssl/kdf.h>
|
||||
#include "apps.h"
|
||||
#include "app_params.h"
|
||||
#include "progs.h"
|
||||
#include "opt.h"
|
||||
|
||||
static int verbose = 0;
|
||||
|
||||
static void legacy_cipher_fn(const EVP_CIPHER *c,
|
||||
const char *from, const char *to, void *arg)
|
||||
{
|
||||
if (c != NULL) {
|
||||
BIO_printf(arg, " %s\n", EVP_CIPHER_name(c));
|
||||
} else {
|
||||
if (from == NULL)
|
||||
from = "<undefined>";
|
||||
if (to == NULL)
|
||||
to = "<undefined>";
|
||||
BIO_printf(arg, " %s => %s\n", from, to);
|
||||
}
|
||||
}
|
||||
|
||||
DEFINE_STACK_OF(EVP_CIPHER)
|
||||
static int cipher_cmp(const EVP_CIPHER * const *a,
|
||||
const EVP_CIPHER * const *b)
|
||||
{
|
||||
int ret = strcasecmp(EVP_CIPHER_name(*a), EVP_CIPHER_name(*b));
|
||||
|
||||
if (ret == 0)
|
||||
ret = strcmp(OSSL_PROVIDER_name(EVP_CIPHER_provider(*a)),
|
||||
OSSL_PROVIDER_name(EVP_CIPHER_provider(*b)));
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
static void collect_ciphers(EVP_CIPHER *cipher, void *stack)
|
||||
{
|
||||
STACK_OF(EVP_CIPHER) *cipher_stack = stack;
|
||||
|
||||
if (sk_EVP_CIPHER_push(cipher_stack, cipher) > 0)
|
||||
EVP_CIPHER_up_ref(cipher);
|
||||
}
|
||||
|
||||
static void list_ciphers(void)
|
||||
{
|
||||
STACK_OF(EVP_CIPHER) *ciphers = sk_EVP_CIPHER_new(cipher_cmp);
|
||||
int i;
|
||||
|
||||
BIO_printf(bio_out, "Legacy:\n");
|
||||
EVP_CIPHER_do_all_sorted(legacy_cipher_fn, bio_out);
|
||||
|
||||
BIO_printf(bio_out, "Provided:\n");
|
||||
EVP_CIPHER_do_all_ex(NULL, collect_ciphers, ciphers);
|
||||
sk_EVP_CIPHER_sort(ciphers);
|
||||
for (i = 0; i < sk_EVP_CIPHER_num(ciphers); i++) {
|
||||
const EVP_CIPHER *c = sk_EVP_CIPHER_value(ciphers, i);
|
||||
|
||||
BIO_printf(bio_out, " %s", EVP_CIPHER_name(c));
|
||||
BIO_printf(bio_out, " @ %s\n",
|
||||
OSSL_PROVIDER_name(EVP_CIPHER_provider(c)));
|
||||
if (verbose) {
|
||||
print_param_types("retrievable algorithm parameters",
|
||||
EVP_CIPHER_gettable_params(c), 4);
|
||||
print_param_types("retrievable operation parameters",
|
||||
EVP_CIPHER_CTX_gettable_params(c), 4);
|
||||
print_param_types("settable operation parameters",
|
||||
EVP_CIPHER_CTX_settable_params(c), 4);
|
||||
}
|
||||
}
|
||||
sk_EVP_CIPHER_pop_free(ciphers, EVP_CIPHER_free);
|
||||
}
|
||||
|
||||
static void list_md_fn(const EVP_MD *m,
|
||||
const char *from, const char *to, void *arg)
|
||||
{
|
||||
if (m != NULL) {
|
||||
BIO_printf(arg, " %s\n", EVP_MD_name(m));
|
||||
} else {
|
||||
if (from == NULL)
|
||||
from = "<undefined>";
|
||||
if (to == NULL)
|
||||
to = "<undefined>";
|
||||
BIO_printf((BIO *)arg, " %s => %s\n", from, to);
|
||||
}
|
||||
}
|
||||
|
||||
DEFINE_STACK_OF(EVP_MD)
|
||||
static int md_cmp(const EVP_MD * const *a, const EVP_MD * const *b)
|
||||
{
|
||||
int ret = strcasecmp(EVP_MD_name(*a), EVP_MD_name(*b));
|
||||
|
||||
if (ret == 0)
|
||||
ret = strcmp(OSSL_PROVIDER_name(EVP_MD_provider(*a)),
|
||||
OSSL_PROVIDER_name(EVP_MD_provider(*b)));
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
static void collect_digests(EVP_MD *md, void *stack)
|
||||
{
|
||||
STACK_OF(EVP_MD) *digest_stack = stack;
|
||||
|
||||
if (sk_EVP_MD_push(digest_stack, md) > 0)
|
||||
EVP_MD_up_ref(md);
|
||||
}
|
||||
|
||||
static void list_digests(void)
|
||||
{
|
||||
STACK_OF(EVP_MD) *digests = sk_EVP_MD_new(md_cmp);
|
||||
int i;
|
||||
|
||||
BIO_printf(bio_out, "Legacy:\n");
|
||||
EVP_MD_do_all_sorted(list_md_fn, bio_out);
|
||||
|
||||
BIO_printf(bio_out, "Provided:\n");
|
||||
EVP_MD_do_all_ex(NULL, collect_digests, digests);
|
||||
sk_EVP_MD_sort(digests);
|
||||
for (i = 0; i < sk_EVP_MD_num(digests); i++) {
|
||||
const EVP_MD *m = sk_EVP_MD_value(digests, i);
|
||||
|
||||
BIO_printf(bio_out, " %s", EVP_MD_name(m));
|
||||
BIO_printf(bio_out, " @ %s\n",
|
||||
OSSL_PROVIDER_name(EVP_MD_provider(m)));
|
||||
if (verbose) {
|
||||
print_param_types("retrievable algorithm parameters",
|
||||
EVP_MD_gettable_params(m), 4);
|
||||
print_param_types("retrievable operation parameters",
|
||||
EVP_MD_CTX_gettable_params(m), 4);
|
||||
print_param_types("settable operation parameters",
|
||||
EVP_MD_CTX_settable_params(m), 4);
|
||||
}
|
||||
}
|
||||
sk_EVP_MD_pop_free(digests, EVP_MD_free);
|
||||
}
|
||||
|
||||
DEFINE_STACK_OF(EVP_MAC)
|
||||
static int mac_cmp(const EVP_MAC * const *a, const EVP_MAC * const *b)
|
||||
{
|
||||
int ret = strcasecmp(EVP_MAC_name(*a), EVP_MAC_name(*b));
|
||||
|
||||
if (ret == 0)
|
||||
ret = strcmp(OSSL_PROVIDER_name(EVP_MAC_provider(*a)),
|
||||
OSSL_PROVIDER_name(EVP_MAC_provider(*b)));
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
static void collect_macs(EVP_MAC *mac, void *stack)
|
||||
{
|
||||
STACK_OF(EVP_MAC) *mac_stack = stack;
|
||||
|
||||
if (sk_EVP_MAC_push(mac_stack, mac) > 0)
|
||||
EVP_MAC_up_ref(mac);
|
||||
}
|
||||
|
||||
static void list_macs(void)
|
||||
{
|
||||
STACK_OF(EVP_MAC) *macs = sk_EVP_MAC_new(mac_cmp);
|
||||
int i;
|
||||
|
||||
BIO_printf(bio_out, "Provided MACs:\n");
|
||||
EVP_MAC_do_all_ex(NULL, collect_macs, macs);
|
||||
sk_EVP_MAC_sort(macs);
|
||||
for (i = 0; i < sk_EVP_MAC_num(macs); i++) {
|
||||
const EVP_MAC *m = sk_EVP_MAC_value(macs, i);
|
||||
|
||||
BIO_printf(bio_out, " %s", EVP_MAC_name(m));
|
||||
BIO_printf(bio_out, " @ %s\n",
|
||||
OSSL_PROVIDER_name(EVP_MAC_provider(m)));
|
||||
|
||||
if (verbose) {
|
||||
print_param_types("retrievable algorithm parameters",
|
||||
EVP_MAC_gettable_params(m), 4);
|
||||
print_param_types("retrievable operation parameters",
|
||||
EVP_MAC_CTX_gettable_params(m), 4);
|
||||
print_param_types("settable operation parameters",
|
||||
EVP_MAC_CTX_settable_params(m), 4);
|
||||
}
|
||||
}
|
||||
sk_EVP_MAC_pop_free(macs, EVP_MAC_free);
|
||||
}
|
||||
|
||||
/*
|
||||
* KDFs and PRFs
|
||||
*/
|
||||
DEFINE_STACK_OF(EVP_KDF)
|
||||
static int kdf_cmp(const EVP_KDF * const *a, const EVP_KDF * const *b)
|
||||
{
|
||||
int ret = strcasecmp(EVP_KDF_name(*a), EVP_KDF_name(*b));
|
||||
|
||||
if (ret == 0)
|
||||
ret = strcmp(OSSL_PROVIDER_name(EVP_KDF_provider(*a)),
|
||||
OSSL_PROVIDER_name(EVP_KDF_provider(*b)));
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
static void collect_kdfs(EVP_KDF *kdf, void *stack)
|
||||
{
|
||||
STACK_OF(EVP_KDF) *kdf_stack = stack;
|
||||
|
||||
sk_EVP_KDF_push(kdf_stack, kdf);
|
||||
EVP_KDF_up_ref(kdf);
|
||||
}
|
||||
|
||||
static void list_kdfs(void)
|
||||
{
|
||||
STACK_OF(EVP_KDF) *kdfs = sk_EVP_KDF_new(kdf_cmp);
|
||||
int i;
|
||||
|
||||
BIO_printf(bio_out, "Provided KDFs and PDFs:\n");
|
||||
EVP_KDF_do_all_ex(NULL, collect_kdfs, kdfs);
|
||||
sk_EVP_KDF_sort(kdfs);
|
||||
for (i = 0; i < sk_EVP_KDF_num(kdfs); i++) {
|
||||
const EVP_KDF *m = sk_EVP_KDF_value(kdfs, i);
|
||||
|
||||
BIO_printf(bio_out, " %s", EVP_KDF_name(m));
|
||||
BIO_printf(bio_out, " @ %s\n",
|
||||
OSSL_PROVIDER_name(EVP_KDF_provider(m)));
|
||||
|
||||
if (verbose) {
|
||||
print_param_types("retrievable algorithm parameters",
|
||||
EVP_KDF_gettable_params(m), 4);
|
||||
print_param_types("retrievable operation parameters",
|
||||
EVP_KDF_CTX_gettable_params(m), 4);
|
||||
print_param_types("settable operation parameters",
|
||||
EVP_KDF_CTX_settable_params(m), 4);
|
||||
}
|
||||
}
|
||||
sk_EVP_KDF_pop_free(kdfs, EVP_KDF_free);
|
||||
}
|
||||
|
||||
static void list_missing_help(void)
|
||||
{
|
||||
const FUNCTION *fp;
|
||||
const OPTIONS *o;
|
||||
|
||||
for (fp = functions; fp->name != NULL; fp++) {
|
||||
if ((o = fp->help) != NULL) {
|
||||
/* If there is help, list what flags are not documented. */
|
||||
for ( ; o->name != NULL; o++) {
|
||||
if (o->helpstr == NULL)
|
||||
BIO_printf(bio_out, "%s %s\n", fp->name, o->name);
|
||||
}
|
||||
} else if (fp->func != dgst_main) {
|
||||
/* If not aliased to the dgst command, */
|
||||
BIO_printf(bio_out, "%s *\n", fp->name);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
static void list_objects(void)
|
||||
{
|
||||
int max_nid = OBJ_new_nid(0);
|
||||
int i;
|
||||
char *oid_buf = NULL;
|
||||
int oid_size = 0;
|
||||
|
||||
/* Skip 0, since that's NID_undef */
|
||||
for (i = 1; i < max_nid; i++) {
|
||||
const ASN1_OBJECT *obj = OBJ_nid2obj(i);
|
||||
const char *sn = OBJ_nid2sn(i);
|
||||
const char *ln = OBJ_nid2ln(i);
|
||||
int n = 0;
|
||||
|
||||
/*
|
||||
* If one of the retrieved objects somehow generated an error,
|
||||
* we ignore it. The check for NID_undef below will detect the
|
||||
* error and simply skip to the next NID.
|
||||
*/
|
||||
ERR_clear_error();
|
||||
|
||||
if (OBJ_obj2nid(obj) == NID_undef)
|
||||
continue;
|
||||
|
||||
if ((n = OBJ_obj2txt(NULL, 0, obj, 1)) == 0) {
|
||||
BIO_printf(bio_out, "# None-OID object: %s, %s\n", sn, ln);
|
||||
continue;
|
||||
}
|
||||
if (n < 0)
|
||||
break; /* Error */
|
||||
|
||||
if (n > oid_size) {
|
||||
oid_buf = OPENSSL_realloc(oid_buf, n + 1);
|
||||
if (oid_buf == NULL) {
|
||||
BIO_printf(bio_err, "ERROR: Memory allocation\n");
|
||||
break; /* Error */
|
||||
}
|
||||
oid_size = n + 1;
|
||||
}
|
||||
if (OBJ_obj2txt(oid_buf, oid_size, obj, 1) < 0)
|
||||
break; /* Error */
|
||||
if (ln == NULL || strcmp(sn, ln) == 0)
|
||||
BIO_printf(bio_out, "%s = %s\n", sn, oid_buf);
|
||||
else
|
||||
BIO_printf(bio_out, "%s = %s, %s\n", sn, ln, oid_buf);
|
||||
}
|
||||
|
||||
OPENSSL_free(oid_buf);
|
||||
}
|
||||
|
||||
static void list_options_for_command(const char *command)
|
||||
{
|
||||
const FUNCTION *fp;
|
||||
const OPTIONS *o;
|
||||
|
||||
for (fp = functions; fp->name != NULL; fp++)
|
||||
if (strcmp(fp->name, command) == 0)
|
||||
break;
|
||||
if (fp->name == NULL) {
|
||||
BIO_printf(bio_err, "Invalid command '%s'; type \"help\" for a list.\n",
|
||||
command);
|
||||
return;
|
||||
}
|
||||
|
||||
if ((o = fp->help) == NULL)
|
||||
return;
|
||||
|
||||
for ( ; o->name != NULL; o++) {
|
||||
if (o->name == OPT_HELP_STR
|
||||
|| o->name == OPT_MORE_STR
|
||||
|| o->name[0] == '\0')
|
||||
continue;
|
||||
BIO_printf(bio_out, "%s %c\n", o->name, o->valtype);
|
||||
}
|
||||
}
|
||||
|
||||
static void list_type(FUNC_TYPE ft, int one)
|
||||
{
|
||||
FUNCTION *fp;
|
||||
int i = 0;
|
||||
DISPLAY_COLUMNS dc;
|
||||
|
||||
memset(&dc, 0, sizeof(dc));
|
||||
if (!one)
|
||||
calculate_columns(functions, &dc);
|
||||
|
||||
for (fp = functions; fp->name != NULL; fp++) {
|
||||
if (fp->type != ft)
|
||||
continue;
|
||||
if (one) {
|
||||
BIO_printf(bio_out, "%s\n", fp->name);
|
||||
} else {
|
||||
if (i % dc.columns == 0 && i > 0)
|
||||
BIO_printf(bio_out, "\n");
|
||||
BIO_printf(bio_out, "%-*s", dc.width, fp->name);
|
||||
i++;
|
||||
}
|
||||
}
|
||||
if (!one)
|
||||
BIO_printf(bio_out, "\n\n");
|
||||
}
|
||||
|
||||
static void list_pkey(void)
|
||||
{
|
||||
int i;
|
||||
|
||||
for (i = 0; i < EVP_PKEY_asn1_get_count(); i++) {
|
||||
const EVP_PKEY_ASN1_METHOD *ameth;
|
||||
int pkey_id, pkey_base_id, pkey_flags;
|
||||
const char *pinfo, *pem_str;
|
||||
ameth = EVP_PKEY_asn1_get0(i);
|
||||
EVP_PKEY_asn1_get0_info(&pkey_id, &pkey_base_id, &pkey_flags,
|
||||
&pinfo, &pem_str, ameth);
|
||||
if (pkey_flags & ASN1_PKEY_ALIAS) {
|
||||
BIO_printf(bio_out, "Name: %s\n", OBJ_nid2ln(pkey_id));
|
||||
BIO_printf(bio_out, "\tAlias for: %s\n",
|
||||
OBJ_nid2ln(pkey_base_id));
|
||||
} else {
|
||||
BIO_printf(bio_out, "Name: %s\n", pinfo);
|
||||
BIO_printf(bio_out, "\tType: %s Algorithm\n",
|
||||
pkey_flags & ASN1_PKEY_DYNAMIC ?
|
||||
"External" : "Builtin");
|
||||
BIO_printf(bio_out, "\tOID: %s\n", OBJ_nid2ln(pkey_id));
|
||||
if (pem_str == NULL)
|
||||
pem_str = "(none)";
|
||||
BIO_printf(bio_out, "\tPEM string: %s\n", pem_str);
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
static void list_pkey_meth(void)
|
||||
{
|
||||
size_t i;
|
||||
size_t meth_count = EVP_PKEY_meth_get_count();
|
||||
|
||||
for (i = 0; i < meth_count; i++) {
|
||||
const EVP_PKEY_METHOD *pmeth = EVP_PKEY_meth_get0(i);
|
||||
int pkey_id, pkey_flags;
|
||||
|
||||
EVP_PKEY_meth_get0_info(&pkey_id, &pkey_flags, pmeth);
|
||||
BIO_printf(bio_out, "%s\n", OBJ_nid2ln(pkey_id));
|
||||
BIO_printf(bio_out, "\tType: %s Algorithm\n",
|
||||
pkey_flags & ASN1_PKEY_DYNAMIC ? "External" : "Builtin");
|
||||
}
|
||||
}
|
||||
|
||||
static void list_engines(void)
|
||||
{
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
ENGINE *e;
|
||||
|
||||
BIO_puts(bio_out, "Engines:\n");
|
||||
e = ENGINE_get_first();
|
||||
while (e) {
|
||||
BIO_printf(bio_out, "%s\n", ENGINE_get_id(e));
|
||||
e = ENGINE_get_next(e);
|
||||
}
|
||||
#else
|
||||
BIO_puts(bio_out, "Engine support is disabled.\n");
|
||||
#endif
|
||||
}
|
||||
|
||||
static void list_disabled(void)
|
||||
{
|
||||
BIO_puts(bio_out, "Disabled algorithms:\n");
|
||||
#ifdef OPENSSL_NO_ARIA
|
||||
BIO_puts(bio_out, "ARIA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_BF
|
||||
BIO_puts(bio_out, "BF\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_BLAKE2
|
||||
BIO_puts(bio_out, "BLAKE2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CAMELLIA
|
||||
BIO_puts(bio_out, "CAMELLIA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CAST
|
||||
BIO_puts(bio_out, "CAST\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CMAC
|
||||
BIO_puts(bio_out, "CMAC\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CMS
|
||||
BIO_puts(bio_out, "CMS\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_COMP
|
||||
BIO_puts(bio_out, "COMP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DES
|
||||
BIO_puts(bio_out, "DES\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DGRAM
|
||||
BIO_puts(bio_out, "DGRAM\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DH
|
||||
BIO_puts(bio_out, "DH\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DSA
|
||||
BIO_puts(bio_out, "DSA\n");
|
||||
#endif
|
||||
#if defined(OPENSSL_NO_DTLS)
|
||||
BIO_puts(bio_out, "DTLS\n");
|
||||
#endif
|
||||
#if defined(OPENSSL_NO_DTLS1)
|
||||
BIO_puts(bio_out, "DTLS1\n");
|
||||
#endif
|
||||
#if defined(OPENSSL_NO_DTLS1_2)
|
||||
BIO_puts(bio_out, "DTLS1_2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_EC
|
||||
BIO_puts(bio_out, "EC\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_EC2M
|
||||
BIO_puts(bio_out, "EC2M\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_ENGINE
|
||||
BIO_puts(bio_out, "ENGINE\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_GOST
|
||||
BIO_puts(bio_out, "GOST\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_IDEA
|
||||
BIO_puts(bio_out, "IDEA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MD2
|
||||
BIO_puts(bio_out, "MD2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MD4
|
||||
BIO_puts(bio_out, "MD4\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MD5
|
||||
BIO_puts(bio_out, "MD5\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MDC2
|
||||
BIO_puts(bio_out, "MDC2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_OCB
|
||||
BIO_puts(bio_out, "OCB\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_OCSP
|
||||
BIO_puts(bio_out, "OCSP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_PSK
|
||||
BIO_puts(bio_out, "PSK\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RC2
|
||||
BIO_puts(bio_out, "RC2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RC4
|
||||
BIO_puts(bio_out, "RC4\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RC5
|
||||
BIO_puts(bio_out, "RC5\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RMD160
|
||||
BIO_puts(bio_out, "RMD160\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RSA
|
||||
BIO_puts(bio_out, "RSA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SCRYPT
|
||||
BIO_puts(bio_out, "SCRYPT\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SCTP
|
||||
BIO_puts(bio_out, "SCTP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SEED
|
||||
BIO_puts(bio_out, "SEED\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SM2
|
||||
BIO_puts(bio_out, "SM2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SM3
|
||||
BIO_puts(bio_out, "SM3\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SM4
|
||||
BIO_puts(bio_out, "SM4\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SOCK
|
||||
BIO_puts(bio_out, "SOCK\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SRP
|
||||
BIO_puts(bio_out, "SRP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SRTP
|
||||
BIO_puts(bio_out, "SRTP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SSL3
|
||||
BIO_puts(bio_out, "SSL3\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1
|
||||
BIO_puts(bio_out, "TLS1\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1_1
|
||||
BIO_puts(bio_out, "TLS1_1\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1_2
|
||||
BIO_puts(bio_out, "TLS1_2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_WHIRLPOOL
|
||||
BIO_puts(bio_out, "WHIRLPOOL\n");
|
||||
#endif
|
||||
#ifndef ZLIB
|
||||
BIO_puts(bio_out, "ZLIB\n");
|
||||
#endif
|
||||
}
|
||||
|
||||
/* Unified enum for help and list commands. */
|
||||
typedef enum HELPLIST_CHOICE {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP, OPT_ONE, OPT_VERBOSE,
|
||||
OPT_COMMANDS, OPT_DIGEST_COMMANDS, OPT_MAC_ALGORITHMS, OPT_OPTIONS,
|
||||
OPT_DIGEST_ALGORITHMS, OPT_CIPHER_COMMANDS, OPT_CIPHER_ALGORITHMS,
|
||||
OPT_PK_ALGORITHMS, OPT_PK_METHOD, OPT_ENGINES, OPT_DISABLED,
|
||||
OPT_KDF_ALGORITHMS, OPT_MISSING_HELP, OPT_OBJECTS
|
||||
} HELPLIST_CHOICE;
|
||||
|
||||
const OPTIONS list_options[] = {
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"1", OPT_ONE, '-', "List in one column"},
|
||||
{"verbose", OPT_VERBOSE, '-', "Verbose listing"},
|
||||
{"commands", OPT_COMMANDS, '-', "List of standard commands"},
|
||||
{"digest-commands", OPT_DIGEST_COMMANDS, '-',
|
||||
"List of message digest commands"},
|
||||
{"digest-algorithms", OPT_DIGEST_ALGORITHMS, '-',
|
||||
"List of message digest algorithms"},
|
||||
{"kdf-algorithms", OPT_KDF_ALGORITHMS, '-',
|
||||
"List of key derivation and pseudo random function algorithms"},
|
||||
{"mac-algorithms", OPT_MAC_ALGORITHMS, '-',
|
||||
"List of message authentication code algorithms"},
|
||||
{"cipher-commands", OPT_CIPHER_COMMANDS, '-', "List of cipher commands"},
|
||||
{"cipher-algorithms", OPT_CIPHER_ALGORITHMS, '-',
|
||||
"List of cipher algorithms"},
|
||||
{"public-key-algorithms", OPT_PK_ALGORITHMS, '-',
|
||||
"List of public key algorithms"},
|
||||
{"public-key-methods", OPT_PK_METHOD, '-',
|
||||
"List of public key methods"},
|
||||
{"engines", OPT_ENGINES, '-',
|
||||
"List of loaded engines"},
|
||||
{"disabled", OPT_DISABLED, '-',
|
||||
"List of disabled features"},
|
||||
{"missing-help", OPT_MISSING_HELP, '-',
|
||||
"List missing detailed help strings"},
|
||||
{"options", OPT_OPTIONS, 's',
|
||||
"List options for specified command"},
|
||||
{"objects", OPT_OBJECTS, '-',
|
||||
"List built in objects (OID<->name mappings)"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int list_main(int argc, char **argv)
|
||||
{
|
||||
char *prog;
|
||||
HELPLIST_CHOICE o;
|
||||
int one = 0, done = 0;
|
||||
struct {
|
||||
unsigned int commands:1;
|
||||
unsigned int digest_commands:1;
|
||||
unsigned int digest_algorithms:1;
|
||||
unsigned int kdf_algorithms:1;
|
||||
unsigned int mac_algorithms:1;
|
||||
unsigned int cipher_commands:1;
|
||||
unsigned int cipher_algorithms:1;
|
||||
unsigned int pk_algorithms:1;
|
||||
unsigned int pk_method:1;
|
||||
unsigned int engines:1;
|
||||
unsigned int disabled:1;
|
||||
unsigned int missing_help:1;
|
||||
unsigned int objects:1;
|
||||
unsigned int options:1;
|
||||
} todo = { 0, };
|
||||
|
||||
verbose = 0; /* Clear a possible previous call */
|
||||
|
||||
prog = opt_init(argc, argv, list_options);
|
||||
while ((o = opt_next()) != OPT_EOF) {
|
||||
switch (o) {
|
||||
case OPT_EOF: /* Never hit, but suppresses warning */
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
return 1;
|
||||
case OPT_HELP:
|
||||
opt_help(list_options);
|
||||
break;
|
||||
case OPT_ONE:
|
||||
one = 1;
|
||||
break;
|
||||
case OPT_COMMANDS:
|
||||
todo.commands = 1;
|
||||
break;
|
||||
case OPT_DIGEST_COMMANDS:
|
||||
todo.digest_commands = 1;
|
||||
break;
|
||||
case OPT_DIGEST_ALGORITHMS:
|
||||
todo.digest_algorithms = 1;
|
||||
break;
|
||||
case OPT_KDF_ALGORITHMS:
|
||||
todo.kdf_algorithms = 1;
|
||||
break;
|
||||
case OPT_MAC_ALGORITHMS:
|
||||
todo.mac_algorithms = 1;
|
||||
break;
|
||||
case OPT_CIPHER_COMMANDS:
|
||||
todo.cipher_commands = 1;
|
||||
break;
|
||||
case OPT_CIPHER_ALGORITHMS:
|
||||
todo.cipher_algorithms = 1;
|
||||
break;
|
||||
case OPT_PK_ALGORITHMS:
|
||||
todo.pk_algorithms = 1;
|
||||
break;
|
||||
case OPT_PK_METHOD:
|
||||
todo.pk_method = 1;
|
||||
break;
|
||||
case OPT_ENGINES:
|
||||
todo.engines = 1;
|
||||
break;
|
||||
case OPT_DISABLED:
|
||||
todo.disabled = 1;
|
||||
break;
|
||||
case OPT_MISSING_HELP:
|
||||
todo.missing_help = 1;
|
||||
break;
|
||||
case OPT_OBJECTS:
|
||||
todo.objects = 1;
|
||||
break;
|
||||
case OPT_OPTIONS:
|
||||
list_options_for_command(opt_arg());
|
||||
break;
|
||||
case OPT_VERBOSE:
|
||||
verbose = 1;
|
||||
break;
|
||||
}
|
||||
done = 1;
|
||||
}
|
||||
if (opt_num_rest() != 0) {
|
||||
BIO_printf(bio_err, "Extra arguments given.\n");
|
||||
goto opthelp;
|
||||
}
|
||||
|
||||
if (todo.commands)
|
||||
list_type(FT_general, one);
|
||||
if (todo.digest_commands)
|
||||
list_type(FT_md, one);
|
||||
if (todo.digest_algorithms)
|
||||
list_digests();
|
||||
if (todo.kdf_algorithms)
|
||||
list_kdfs();
|
||||
if (todo.mac_algorithms)
|
||||
list_macs();
|
||||
if (todo.cipher_commands)
|
||||
list_type(FT_cipher, one);
|
||||
if (todo.cipher_algorithms)
|
||||
list_ciphers();
|
||||
if (todo.pk_algorithms)
|
||||
list_pkey();
|
||||
if (todo.pk_method)
|
||||
list_pkey_meth();
|
||||
if (todo.engines)
|
||||
list_engines();
|
||||
if (todo.disabled)
|
||||
list_disabled();
|
||||
if (todo.missing_help)
|
||||
list_missing_help();
|
||||
if (todo.objects)
|
||||
list_objects();
|
||||
|
||||
if (!done)
|
||||
goto opthelp;
|
||||
|
||||
return 0;
|
||||
}
|
||||
+22
-32
@@ -14,6 +14,7 @@
|
||||
#include <openssl/bio.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/params.h>
|
||||
|
||||
#undef BUFSIZE
|
||||
#define BUFSIZE 1024*8
|
||||
@@ -28,8 +29,8 @@ const OPTIONS mac_options[] = {
|
||||
{OPT_HELP_STR, 1, '-', "mac_name\t\t MAC algorithm (See list "
|
||||
"-mac-algorithms)"},
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"macopt", OPT_MACOPT, 's', "MAC algorithm control parameters in n:v form. "
|
||||
"See 'Supported Controls' in the EVP_MAC_ docs"},
|
||||
{"macopt", OPT_MACOPT, 's', "MAC algorithm parameters in n:v form. "
|
||||
"See 'PARAMETER NAMES' in the EVP_MAC_ docs"},
|
||||
{"in", OPT_IN, '<', "Input file to MAC (default is stdin)"},
|
||||
{"out", OPT_OUT, '>', "Output to filename rather than stdout"},
|
||||
{"binary", OPT_BIN, '-', "Output in binary format (Default is hexadecimal "
|
||||
@@ -37,29 +38,11 @@ const OPTIONS mac_options[] = {
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static int mac_ctrl_string(EVP_MAC_CTX *ctx, const char *value)
|
||||
{
|
||||
int rv;
|
||||
char *stmp, *vtmp = NULL;
|
||||
|
||||
stmp = OPENSSL_strdup(value);
|
||||
if (stmp == NULL)
|
||||
return -1;
|
||||
vtmp = strchr(stmp, ':');
|
||||
if (vtmp != NULL) {
|
||||
*vtmp = 0;
|
||||
vtmp++;
|
||||
}
|
||||
rv = EVP_MAC_ctrl_str(ctx, stmp, vtmp);
|
||||
OPENSSL_free(stmp);
|
||||
return rv;
|
||||
}
|
||||
|
||||
int mac_main(int argc, char **argv)
|
||||
{
|
||||
int ret = 1;
|
||||
char *prog;
|
||||
const EVP_MAC *mac = NULL;
|
||||
EVP_MAC *mac = NULL;
|
||||
OPTION_CHOICE o;
|
||||
EVP_MAC_CTX *ctx = NULL;
|
||||
STACK_OF(OPENSSL_STRING) *opts = NULL;
|
||||
@@ -109,7 +92,7 @@ opthelp:
|
||||
goto opthelp;
|
||||
}
|
||||
|
||||
mac = EVP_get_macbyname(argv[0]);
|
||||
mac = EVP_MAC_fetch(NULL, argv[0], NULL);
|
||||
if (mac == NULL) {
|
||||
BIO_printf(bio_err, "Invalid MAC name %s\n", argv[0]);
|
||||
goto opthelp;
|
||||
@@ -120,14 +103,21 @@ opthelp:
|
||||
goto err;
|
||||
|
||||
if (opts != NULL) {
|
||||
for (i = 0; i < sk_OPENSSL_STRING_num(opts); i++) {
|
||||
char *opt = sk_OPENSSL_STRING_value(opts, i);
|
||||
if (mac_ctrl_string(ctx, opt) <= 0) {
|
||||
BIO_printf(bio_err, "MAC parameter error '%s'\n", opt);
|
||||
ERR_print_errors(bio_err);
|
||||
goto err;
|
||||
}
|
||||
int ok = 1;
|
||||
OSSL_PARAM *params =
|
||||
app_params_new_from_opts(opts, EVP_MAC_CTX_settable_params(mac));
|
||||
|
||||
if (params == NULL)
|
||||
goto err;
|
||||
|
||||
if (!EVP_MAC_CTX_set_params(ctx, params)) {
|
||||
BIO_printf(bio_err, "MAC parameter error\n");
|
||||
ERR_print_errors(bio_err);
|
||||
ok = 0;
|
||||
}
|
||||
app_params_free(params);
|
||||
if (!ok)
|
||||
goto err;
|
||||
}
|
||||
|
||||
/* Use text mode for stdin */
|
||||
@@ -146,7 +136,6 @@ opthelp:
|
||||
goto err;
|
||||
}
|
||||
|
||||
|
||||
for (;;) {
|
||||
i = BIO_read(in, (char *)buf, BUFSIZE);
|
||||
if (i < 0) {
|
||||
@@ -161,7 +150,7 @@ opthelp:
|
||||
}
|
||||
}
|
||||
|
||||
if (!EVP_MAC_final(ctx, NULL, &len)) {
|
||||
if (!EVP_MAC_final(ctx, NULL, &len, 0)) {
|
||||
BIO_printf(bio_err, "EVP_MAC_final failed\n");
|
||||
goto err;
|
||||
}
|
||||
@@ -170,7 +159,7 @@ opthelp:
|
||||
goto err;
|
||||
}
|
||||
|
||||
if (!EVP_MAC_final(ctx, buf, &len)) {
|
||||
if (!EVP_MAC_final(ctx, buf, &len, BUFSIZE)) {
|
||||
BIO_printf(bio_err, "EVP_MAC_final failed\n");
|
||||
goto err;
|
||||
}
|
||||
@@ -195,5 +184,6 @@ err:
|
||||
BIO_free(in);
|
||||
BIO_free(out);
|
||||
EVP_MAC_CTX_free(ctx);
|
||||
EVP_MAC_free(mac);
|
||||
return ret;
|
||||
}
|
||||
+4
-2
@@ -1436,9 +1436,11 @@ static int do_responder(OCSP_REQUEST **preq, BIO **pcbio, BIO *acbio,
|
||||
*q = '\0';
|
||||
|
||||
/*
|
||||
* Skip "GET / HTTP..." requests often used by load-balancers
|
||||
* Skip "GET / HTTP..." requests often used by load-balancers. Note:
|
||||
* 'p' was incremented above to point to the first byte *after* the
|
||||
* leading slash, so with 'GET / ' it is now an empty string.
|
||||
*/
|
||||
if (p[1] == '\0')
|
||||
if (p[0] == '\0')
|
||||
goto out;
|
||||
|
||||
len = urldecode(p);
|
||||
|
||||
+1
-513
@@ -23,23 +23,13 @@
|
||||
# include <openssl/engine.h>
|
||||
#endif
|
||||
#include <openssl/err.h>
|
||||
#include "s_apps.h"
|
||||
/* Needed to get the other O_xxx flags. */
|
||||
#ifdef OPENSSL_SYS_VMS
|
||||
# include <unixio.h>
|
||||
#endif
|
||||
#include "apps.h"
|
||||
#define INCLUDE_FUNCTION_TABLE
|
||||
#include "progs.h"
|
||||
|
||||
/* Structure to hold the number of columns to be displayed and the
|
||||
* field width used to display them.
|
||||
*/
|
||||
typedef struct {
|
||||
int columns;
|
||||
int width;
|
||||
} DISPLAY_COLUMNS;
|
||||
|
||||
/* Special sentinel to exit the program. */
|
||||
#define EXIT_THE_PROGRAM (-1)
|
||||
|
||||
@@ -51,31 +41,12 @@ typedef struct {
|
||||
*/
|
||||
static LHASH_OF(FUNCTION) *prog_init(void);
|
||||
static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[]);
|
||||
static void list_pkey(void);
|
||||
static void list_pkey_meth(void);
|
||||
static void list_type(FUNC_TYPE ft, int one);
|
||||
static void list_engines(void);
|
||||
static void list_disabled(void);
|
||||
char *default_config_file = NULL;
|
||||
|
||||
BIO *bio_in = NULL;
|
||||
BIO *bio_out = NULL;
|
||||
BIO *bio_err = NULL;
|
||||
|
||||
static void calculate_columns(DISPLAY_COLUMNS *dc)
|
||||
{
|
||||
FUNCTION *f;
|
||||
int len, maxlen = 0;
|
||||
|
||||
for (f = functions; f->name != NULL; ++f)
|
||||
if (f->type == FT_general || f->type == FT_md || f->type == FT_cipher)
|
||||
if ((len = strlen(f->name)) > maxlen)
|
||||
maxlen = len;
|
||||
|
||||
dc->width = maxlen + 2;
|
||||
dc->columns = (80 - 1) / dc->width;
|
||||
}
|
||||
|
||||
static int apps_startup(void)
|
||||
{
|
||||
#ifdef SIGPIPE
|
||||
@@ -408,256 +379,6 @@ int main(int argc, char *argv[])
|
||||
EXIT(ret);
|
||||
}
|
||||
|
||||
static void list_cipher_fn(const EVP_CIPHER *c,
|
||||
const char *from, const char *to, void *arg)
|
||||
{
|
||||
if (c != NULL) {
|
||||
BIO_printf(arg, "%s\n", EVP_CIPHER_name(c));
|
||||
} else {
|
||||
if (from == NULL)
|
||||
from = "<undefined>";
|
||||
if (to == NULL)
|
||||
to = "<undefined>";
|
||||
BIO_printf(arg, "%s => %s\n", from, to);
|
||||
}
|
||||
}
|
||||
|
||||
static void list_md_fn(const EVP_MD *m,
|
||||
const char *from, const char *to, void *arg)
|
||||
{
|
||||
if (m != NULL) {
|
||||
BIO_printf(arg, "%s\n", EVP_MD_name(m));
|
||||
} else {
|
||||
if (from == NULL)
|
||||
from = "<undefined>";
|
||||
if (to == NULL)
|
||||
to = "<undefined>";
|
||||
BIO_printf((BIO *)arg, "%s => %s\n", from, to);
|
||||
}
|
||||
}
|
||||
|
||||
static void list_mac_fn(const EVP_MAC *m,
|
||||
const char *from, const char *to, void *arg)
|
||||
{
|
||||
if (m != NULL) {
|
||||
BIO_printf(arg, "%s\n", EVP_MAC_name(m));
|
||||
} else {
|
||||
if (from == NULL)
|
||||
from = "<undefined>";
|
||||
if (to == NULL)
|
||||
to = "<undefined>";
|
||||
BIO_printf(arg, "%s => %s\n", from, to);
|
||||
}
|
||||
}
|
||||
|
||||
static void list_missing_help(void)
|
||||
{
|
||||
const FUNCTION *fp;
|
||||
const OPTIONS *o;
|
||||
|
||||
for (fp = functions; fp->name != NULL; fp++) {
|
||||
if ((o = fp->help) != NULL) {
|
||||
/* If there is help, list what flags are not documented. */
|
||||
for ( ; o->name != NULL; o++) {
|
||||
if (o->helpstr == NULL)
|
||||
BIO_printf(bio_out, "%s %s\n", fp->name, o->name);
|
||||
}
|
||||
} else if (fp->func != dgst_main) {
|
||||
/* If not aliased to the dgst command, */
|
||||
BIO_printf(bio_out, "%s *\n", fp->name);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
static void list_objects(void)
|
||||
{
|
||||
int max_nid = OBJ_new_nid(0);
|
||||
int i;
|
||||
char *oid_buf = NULL;
|
||||
int oid_size = 0;
|
||||
|
||||
/* Skip 0, since that's NID_undef */
|
||||
for (i = 1; i < max_nid; i++) {
|
||||
const ASN1_OBJECT *obj = OBJ_nid2obj(i);
|
||||
const char *sn = OBJ_nid2sn(i);
|
||||
const char *ln = OBJ_nid2ln(i);
|
||||
int n = 0;
|
||||
|
||||
/*
|
||||
* If one of the retrieved objects somehow generated an error,
|
||||
* we ignore it. The check for NID_undef below will detect the
|
||||
* error and simply skip to the next NID.
|
||||
*/
|
||||
ERR_clear_error();
|
||||
|
||||
if (OBJ_obj2nid(obj) == NID_undef)
|
||||
continue;
|
||||
|
||||
if ((n = OBJ_obj2txt(NULL, 0, obj, 1)) == 0) {
|
||||
BIO_printf(bio_out, "# None-OID object: %s, %s\n", sn, ln);
|
||||
continue;
|
||||
}
|
||||
if (n < 0)
|
||||
break; /* Error */
|
||||
|
||||
if (n > oid_size) {
|
||||
oid_buf = OPENSSL_realloc(oid_buf, n + 1);
|
||||
if (oid_buf == NULL) {
|
||||
BIO_printf(bio_err, "ERROR: Memory allocation\n");
|
||||
break; /* Error */
|
||||
}
|
||||
oid_size = n + 1;
|
||||
}
|
||||
if (OBJ_obj2txt(oid_buf, oid_size, obj, 1) < 0)
|
||||
break; /* Error */
|
||||
if (ln == NULL || strcmp(sn, ln) == 0)
|
||||
BIO_printf(bio_out, "%s = %s\n", sn, oid_buf);
|
||||
else
|
||||
BIO_printf(bio_out, "%s = %s, %s\n", sn, ln, oid_buf);
|
||||
}
|
||||
|
||||
OPENSSL_free(oid_buf);
|
||||
}
|
||||
|
||||
static void list_options_for_command(const char *command)
|
||||
{
|
||||
const FUNCTION *fp;
|
||||
const OPTIONS *o;
|
||||
|
||||
for (fp = functions; fp->name != NULL; fp++)
|
||||
if (strcmp(fp->name, command) == 0)
|
||||
break;
|
||||
if (fp->name == NULL) {
|
||||
BIO_printf(bio_err, "Invalid command '%s'; type \"help\" for a list.\n",
|
||||
command);
|
||||
return;
|
||||
}
|
||||
|
||||
if ((o = fp->help) == NULL)
|
||||
return;
|
||||
|
||||
for ( ; o->name != NULL; o++) {
|
||||
if (o->name == OPT_HELP_STR
|
||||
|| o->name == OPT_MORE_STR
|
||||
|| o->name[0] == '\0')
|
||||
continue;
|
||||
BIO_printf(bio_out, "%s %c\n", o->name, o->valtype);
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
/* Unified enum for help and list commands. */
|
||||
typedef enum HELPLIST_CHOICE {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP, OPT_ONE,
|
||||
OPT_COMMANDS, OPT_DIGEST_COMMANDS, OPT_MAC_ALGORITHMS, OPT_OPTIONS,
|
||||
OPT_DIGEST_ALGORITHMS, OPT_CIPHER_COMMANDS, OPT_CIPHER_ALGORITHMS,
|
||||
OPT_PK_ALGORITHMS, OPT_PK_METHOD, OPT_ENGINES, OPT_DISABLED,
|
||||
OPT_MISSING_HELP, OPT_OBJECTS
|
||||
} HELPLIST_CHOICE;
|
||||
|
||||
const OPTIONS list_options[] = {
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"1", OPT_ONE, '-', "List in one column"},
|
||||
{"commands", OPT_COMMANDS, '-', "List of standard commands"},
|
||||
{"digest-commands", OPT_DIGEST_COMMANDS, '-',
|
||||
"List of message digest commands"},
|
||||
{"digest-algorithms", OPT_DIGEST_ALGORITHMS, '-',
|
||||
"List of message digest algorithms"},
|
||||
{"mac-algorithms", OPT_MAC_ALGORITHMS, '-',
|
||||
"List of message authentication code algorithms"},
|
||||
{"cipher-commands", OPT_CIPHER_COMMANDS, '-', "List of cipher commands"},
|
||||
{"cipher-algorithms", OPT_CIPHER_ALGORITHMS, '-',
|
||||
"List of cipher algorithms"},
|
||||
{"public-key-algorithms", OPT_PK_ALGORITHMS, '-',
|
||||
"List of public key algorithms"},
|
||||
{"public-key-methods", OPT_PK_METHOD, '-',
|
||||
"List of public key methods"},
|
||||
{"engines", OPT_ENGINES, '-',
|
||||
"List of loaded engines"},
|
||||
{"disabled", OPT_DISABLED, '-',
|
||||
"List of disabled features"},
|
||||
{"missing-help", OPT_MISSING_HELP, '-',
|
||||
"List missing detailed help strings"},
|
||||
{"options", OPT_OPTIONS, 's',
|
||||
"List options for specified command"},
|
||||
{"objects", OPT_OBJECTS, '-',
|
||||
"List built in objects (OID<->name mappings)"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int list_main(int argc, char **argv)
|
||||
{
|
||||
char *prog;
|
||||
HELPLIST_CHOICE o;
|
||||
int one = 0, done = 0;
|
||||
|
||||
prog = opt_init(argc, argv, list_options);
|
||||
while ((o = opt_next()) != OPT_EOF) {
|
||||
switch (o) {
|
||||
case OPT_EOF: /* Never hit, but suppresses warning */
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
return 1;
|
||||
case OPT_HELP:
|
||||
opt_help(list_options);
|
||||
break;
|
||||
case OPT_ONE:
|
||||
one = 1;
|
||||
break;
|
||||
case OPT_COMMANDS:
|
||||
list_type(FT_general, one);
|
||||
break;
|
||||
case OPT_DIGEST_COMMANDS:
|
||||
list_type(FT_md, one);
|
||||
break;
|
||||
case OPT_DIGEST_ALGORITHMS:
|
||||
EVP_MD_do_all_sorted(list_md_fn, bio_out);
|
||||
break;
|
||||
case OPT_MAC_ALGORITHMS:
|
||||
EVP_MAC_do_all_sorted(list_mac_fn, bio_out);
|
||||
break;
|
||||
case OPT_CIPHER_COMMANDS:
|
||||
list_type(FT_cipher, one);
|
||||
break;
|
||||
case OPT_CIPHER_ALGORITHMS:
|
||||
EVP_CIPHER_do_all_sorted(list_cipher_fn, bio_out);
|
||||
break;
|
||||
case OPT_PK_ALGORITHMS:
|
||||
list_pkey();
|
||||
break;
|
||||
case OPT_PK_METHOD:
|
||||
list_pkey_meth();
|
||||
break;
|
||||
case OPT_ENGINES:
|
||||
list_engines();
|
||||
break;
|
||||
case OPT_DISABLED:
|
||||
list_disabled();
|
||||
break;
|
||||
case OPT_MISSING_HELP:
|
||||
list_missing_help();
|
||||
break;
|
||||
case OPT_OBJECTS:
|
||||
list_objects();
|
||||
break;
|
||||
case OPT_OPTIONS:
|
||||
list_options_for_command(opt_arg());
|
||||
break;
|
||||
}
|
||||
done = 1;
|
||||
}
|
||||
if (opt_num_rest() != 0) {
|
||||
BIO_printf(bio_err, "Extra arguments given.\n");
|
||||
goto opthelp;
|
||||
}
|
||||
|
||||
if (!done)
|
||||
goto opthelp;
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
typedef enum HELP_CHOICE {
|
||||
OPT_hERR = -1, OPT_hEOF = 0, OPT_hHELP
|
||||
} HELP_CHOICE;
|
||||
@@ -705,7 +426,7 @@ int help_main(int argc, char **argv)
|
||||
return 1;
|
||||
}
|
||||
|
||||
calculate_columns(&dc);
|
||||
calculate_columns(functions, &dc);
|
||||
BIO_printf(bio_err, "Standard commands");
|
||||
i = 0;
|
||||
tp = FT_none;
|
||||
@@ -735,32 +456,6 @@ int help_main(int argc, char **argv)
|
||||
return 0;
|
||||
}
|
||||
|
||||
static void list_type(FUNC_TYPE ft, int one)
|
||||
{
|
||||
FUNCTION *fp;
|
||||
int i = 0;
|
||||
DISPLAY_COLUMNS dc;
|
||||
|
||||
memset(&dc, 0, sizeof(dc));
|
||||
if (!one)
|
||||
calculate_columns(&dc);
|
||||
|
||||
for (fp = functions; fp->name != NULL; fp++) {
|
||||
if (fp->type != ft)
|
||||
continue;
|
||||
if (one) {
|
||||
BIO_printf(bio_out, "%s\n", fp->name);
|
||||
} else {
|
||||
if (i % dc.columns == 0 && i > 0)
|
||||
BIO_printf(bio_out, "\n");
|
||||
BIO_printf(bio_out, "%-*s", dc.width, fp->name);
|
||||
i++;
|
||||
}
|
||||
}
|
||||
if (!one)
|
||||
BIO_printf(bio_out, "\n\n");
|
||||
}
|
||||
|
||||
static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
|
||||
{
|
||||
FUNCTION f, *fp;
|
||||
@@ -806,51 +501,6 @@ static int do_cmd(LHASH_OF(FUNCTION) *prog, int argc, char *argv[])
|
||||
return 1;
|
||||
}
|
||||
|
||||
static void list_pkey(void)
|
||||
{
|
||||
int i;
|
||||
|
||||
for (i = 0; i < EVP_PKEY_asn1_get_count(); i++) {
|
||||
const EVP_PKEY_ASN1_METHOD *ameth;
|
||||
int pkey_id, pkey_base_id, pkey_flags;
|
||||
const char *pinfo, *pem_str;
|
||||
ameth = EVP_PKEY_asn1_get0(i);
|
||||
EVP_PKEY_asn1_get0_info(&pkey_id, &pkey_base_id, &pkey_flags,
|
||||
&pinfo, &pem_str, ameth);
|
||||
if (pkey_flags & ASN1_PKEY_ALIAS) {
|
||||
BIO_printf(bio_out, "Name: %s\n", OBJ_nid2ln(pkey_id));
|
||||
BIO_printf(bio_out, "\tAlias for: %s\n",
|
||||
OBJ_nid2ln(pkey_base_id));
|
||||
} else {
|
||||
BIO_printf(bio_out, "Name: %s\n", pinfo);
|
||||
BIO_printf(bio_out, "\tType: %s Algorithm\n",
|
||||
pkey_flags & ASN1_PKEY_DYNAMIC ?
|
||||
"External" : "Builtin");
|
||||
BIO_printf(bio_out, "\tOID: %s\n", OBJ_nid2ln(pkey_id));
|
||||
if (pem_str == NULL)
|
||||
pem_str = "(none)";
|
||||
BIO_printf(bio_out, "\tPEM string: %s\n", pem_str);
|
||||
}
|
||||
|
||||
}
|
||||
}
|
||||
|
||||
static void list_pkey_meth(void)
|
||||
{
|
||||
size_t i;
|
||||
size_t meth_count = EVP_PKEY_meth_get_count();
|
||||
|
||||
for (i = 0; i < meth_count; i++) {
|
||||
const EVP_PKEY_METHOD *pmeth = EVP_PKEY_meth_get0(i);
|
||||
int pkey_id, pkey_flags;
|
||||
|
||||
EVP_PKEY_meth_get0_info(&pkey_id, &pkey_flags, pmeth);
|
||||
BIO_printf(bio_out, "%s\n", OBJ_nid2ln(pkey_id));
|
||||
BIO_printf(bio_out, "\tType: %s Algorithm\n",
|
||||
pkey_flags & ASN1_PKEY_DYNAMIC ? "External" : "Builtin");
|
||||
}
|
||||
}
|
||||
|
||||
static int function_cmp(const FUNCTION * a, const FUNCTION * b)
|
||||
{
|
||||
return strncmp(a->name, b->name, 8);
|
||||
@@ -871,168 +521,6 @@ static int SortFnByName(const void *_f1, const void *_f2)
|
||||
return strcmp(f1->name, f2->name);
|
||||
}
|
||||
|
||||
static void list_engines(void)
|
||||
{
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
ENGINE *e;
|
||||
|
||||
BIO_puts(bio_out, "Engines:\n");
|
||||
e = ENGINE_get_first();
|
||||
while (e) {
|
||||
BIO_printf(bio_out, "%s\n", ENGINE_get_id(e));
|
||||
e = ENGINE_get_next(e);
|
||||
}
|
||||
#else
|
||||
BIO_puts(bio_out, "Engine support is disabled.\n");
|
||||
#endif
|
||||
}
|
||||
|
||||
static void list_disabled(void)
|
||||
{
|
||||
BIO_puts(bio_out, "Disabled algorithms:\n");
|
||||
#ifdef OPENSSL_NO_ARIA
|
||||
BIO_puts(bio_out, "ARIA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_BF
|
||||
BIO_puts(bio_out, "BF\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_BLAKE2
|
||||
BIO_puts(bio_out, "BLAKE2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CAMELLIA
|
||||
BIO_puts(bio_out, "CAMELLIA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CAST
|
||||
BIO_puts(bio_out, "CAST\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CMAC
|
||||
BIO_puts(bio_out, "CMAC\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_CMS
|
||||
BIO_puts(bio_out, "CMS\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_COMP
|
||||
BIO_puts(bio_out, "COMP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DES
|
||||
BIO_puts(bio_out, "DES\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DGRAM
|
||||
BIO_puts(bio_out, "DGRAM\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DH
|
||||
BIO_puts(bio_out, "DH\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_DSA
|
||||
BIO_puts(bio_out, "DSA\n");
|
||||
#endif
|
||||
#if defined(OPENSSL_NO_DTLS)
|
||||
BIO_puts(bio_out, "DTLS\n");
|
||||
#endif
|
||||
#if defined(OPENSSL_NO_DTLS1)
|
||||
BIO_puts(bio_out, "DTLS1\n");
|
||||
#endif
|
||||
#if defined(OPENSSL_NO_DTLS1_2)
|
||||
BIO_puts(bio_out, "DTLS1_2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_EC
|
||||
BIO_puts(bio_out, "EC\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_EC2M
|
||||
BIO_puts(bio_out, "EC2M\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_ENGINE
|
||||
BIO_puts(bio_out, "ENGINE\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_GOST
|
||||
BIO_puts(bio_out, "GOST\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_IDEA
|
||||
BIO_puts(bio_out, "IDEA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MD2
|
||||
BIO_puts(bio_out, "MD2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MD4
|
||||
BIO_puts(bio_out, "MD4\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MD5
|
||||
BIO_puts(bio_out, "MD5\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_MDC2
|
||||
BIO_puts(bio_out, "MDC2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_OCB
|
||||
BIO_puts(bio_out, "OCB\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_OCSP
|
||||
BIO_puts(bio_out, "OCSP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_PSK
|
||||
BIO_puts(bio_out, "PSK\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RC2
|
||||
BIO_puts(bio_out, "RC2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RC4
|
||||
BIO_puts(bio_out, "RC4\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RC5
|
||||
BIO_puts(bio_out, "RC5\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RMD160
|
||||
BIO_puts(bio_out, "RMD160\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_RSA
|
||||
BIO_puts(bio_out, "RSA\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SCRYPT
|
||||
BIO_puts(bio_out, "SCRYPT\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SCTP
|
||||
BIO_puts(bio_out, "SCTP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SEED
|
||||
BIO_puts(bio_out, "SEED\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SM2
|
||||
BIO_puts(bio_out, "SM2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SM3
|
||||
BIO_puts(bio_out, "SM3\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SM4
|
||||
BIO_puts(bio_out, "SM4\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SOCK
|
||||
BIO_puts(bio_out, "SOCK\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SRP
|
||||
BIO_puts(bio_out, "SRP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SRTP
|
||||
BIO_puts(bio_out, "SRTP\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_SSL3
|
||||
BIO_puts(bio_out, "SSL3\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1
|
||||
BIO_puts(bio_out, "TLS1\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1_1
|
||||
BIO_puts(bio_out, "TLS1_1\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_TLS1_2
|
||||
BIO_puts(bio_out, "TLS1_2\n");
|
||||
#endif
|
||||
#ifdef OPENSSL_NO_WHIRLPOOL
|
||||
BIO_puts(bio_out, "WHIRLPOOL\n");
|
||||
#endif
|
||||
#ifndef ZLIB
|
||||
BIO_puts(bio_out, "ZLIB\n");
|
||||
#endif
|
||||
}
|
||||
|
||||
static LHASH_OF(FUNCTION) *prog_init(void)
|
||||
{
|
||||
static LHASH_OF(FUNCTION) *ret = NULL;
|
||||
|
||||
+38
-26
@@ -41,6 +41,7 @@ int dump_certs_pkeys_bags(BIO *out, const STACK_OF(PKCS12_SAFEBAG) *bags,
|
||||
int dump_certs_pkeys_bag(BIO *out, const PKCS12_SAFEBAG *bags,
|
||||
const char *pass, int passlen,
|
||||
int options, char *pempass, const EVP_CIPHER *enc);
|
||||
void print_attribute(BIO *out, const ASN1_TYPE *av);
|
||||
int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst,
|
||||
const char *name);
|
||||
void hex_prin(BIO *out, unsigned char *buf, int len);
|
||||
@@ -878,6 +879,38 @@ int cert_load(BIO *in, STACK_OF(X509) *sk)
|
||||
return ret;
|
||||
}
|
||||
|
||||
/* Generalised x509 attribute value print */
|
||||
|
||||
void print_attribute(BIO *out, const ASN1_TYPE *av)
|
||||
{
|
||||
char *value;
|
||||
|
||||
switch (av->type) {
|
||||
case V_ASN1_BMPSTRING:
|
||||
value = OPENSSL_uni2asc(av->value.bmpstring->data,
|
||||
av->value.bmpstring->length);
|
||||
BIO_printf(out, "%s\n", value);
|
||||
OPENSSL_free(value);
|
||||
break;
|
||||
|
||||
case V_ASN1_OCTET_STRING:
|
||||
hex_prin(out, av->value.octet_string->data,
|
||||
av->value.octet_string->length);
|
||||
BIO_printf(out, "\n");
|
||||
break;
|
||||
|
||||
case V_ASN1_BIT_STRING:
|
||||
hex_prin(out, av->value.bit_string->data,
|
||||
av->value.bit_string->length);
|
||||
BIO_printf(out, "\n");
|
||||
break;
|
||||
|
||||
default:
|
||||
BIO_printf(out, "<Unsupported tag %d>\n", av->type);
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/* Generalised attribute print: handle PKCS#8 and bag attributes */
|
||||
|
||||
int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst,
|
||||
@@ -885,8 +918,7 @@ int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst,
|
||||
{
|
||||
X509_ATTRIBUTE *attr;
|
||||
ASN1_TYPE *av;
|
||||
char *value;
|
||||
int i, attr_nid;
|
||||
int i, j, attr_nid;
|
||||
if (!attrlst) {
|
||||
BIO_printf(out, "%s: <No Attributes>\n", name);
|
||||
return 1;
|
||||
@@ -910,30 +942,10 @@ int print_attribs(BIO *out, const STACK_OF(X509_ATTRIBUTE) *attrlst,
|
||||
}
|
||||
|
||||
if (X509_ATTRIBUTE_count(attr)) {
|
||||
av = X509_ATTRIBUTE_get0_type(attr, 0);
|
||||
switch (av->type) {
|
||||
case V_ASN1_BMPSTRING:
|
||||
value = OPENSSL_uni2asc(av->value.bmpstring->data,
|
||||
av->value.bmpstring->length);
|
||||
BIO_printf(out, "%s\n", value);
|
||||
OPENSSL_free(value);
|
||||
break;
|
||||
|
||||
case V_ASN1_OCTET_STRING:
|
||||
hex_prin(out, av->value.octet_string->data,
|
||||
av->value.octet_string->length);
|
||||
BIO_printf(out, "\n");
|
||||
break;
|
||||
|
||||
case V_ASN1_BIT_STRING:
|
||||
hex_prin(out, av->value.bit_string->data,
|
||||
av->value.bit_string->length);
|
||||
BIO_printf(out, "\n");
|
||||
break;
|
||||
|
||||
default:
|
||||
BIO_printf(out, "<Unsupported tag %d>\n", av->type);
|
||||
break;
|
||||
for (j = 0; j < X509_ATTRIBUTE_count(attr); j++)
|
||||
{
|
||||
av = X509_ATTRIBUTE_get0_type(attr, j);
|
||||
print_attribute(out, av);
|
||||
}
|
||||
} else {
|
||||
BIO_printf(out, "<No Values>\n");
|
||||
|
||||
+1
-2
@@ -398,8 +398,7 @@ int pkeyutl_main(int argc, char **argv)
|
||||
if (!rawin
|
||||
&& buf_inlen > EVP_MAX_MD_SIZE
|
||||
&& (pkey_op == EVP_PKEY_OP_SIGN
|
||||
|| pkey_op == EVP_PKEY_OP_VERIFY
|
||||
|| pkey_op == EVP_PKEY_OP_VERIFYRECOVER)) {
|
||||
|| pkey_op == EVP_PKEY_OP_VERIFY)) {
|
||||
BIO_printf(bio_err,
|
||||
"Error: The input data looks too long to be a hash\n");
|
||||
goto end;
|
||||
|
||||
+400
@@ -0,0 +1,400 @@
|
||||
/*
|
||||
* WARNING: do not edit!
|
||||
* Generated by apps/progs.pl
|
||||
*
|
||||
* Copyright 1995-2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include "progs.h"
|
||||
|
||||
FUNCTION functions[] = {
|
||||
{FT_general, "asn1parse", asn1parse_main, asn1parse_options},
|
||||
{FT_general, "ca", ca_main, ca_options},
|
||||
#ifndef OPENSSL_NO_SOCK
|
||||
{FT_general, "ciphers", ciphers_main, ciphers_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CMS
|
||||
{FT_general, "cms", cms_main, cms_options},
|
||||
#endif
|
||||
{FT_general, "crl", crl_main, crl_options},
|
||||
{FT_general, "crl2pkcs7", crl2pkcs7_main, crl2pkcs7_options},
|
||||
{FT_general, "dgst", dgst_main, dgst_options},
|
||||
#ifndef OPENSSL_NO_DH
|
||||
{FT_general, "dhparam", dhparam_main, dhparam_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DSA
|
||||
{FT_general, "dsa", dsa_main, dsa_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DSA
|
||||
{FT_general, "dsaparam", dsaparam_main, dsaparam_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_EC
|
||||
{FT_general, "ec", ec_main, ec_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_EC
|
||||
{FT_general, "ecparam", ecparam_main, ecparam_options},
|
||||
#endif
|
||||
{FT_general, "enc", enc_main, enc_options},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{FT_general, "engine", engine_main, engine_options},
|
||||
#endif
|
||||
{FT_general, "errstr", errstr_main, errstr_options},
|
||||
{FT_general, "fipsinstall", fipsinstall_main, fipsinstall_options},
|
||||
#ifndef OPENSSL_NO_DSA
|
||||
{FT_general, "gendsa", gendsa_main, gendsa_options},
|
||||
#endif
|
||||
{FT_general, "genpkey", genpkey_main, genpkey_options},
|
||||
#ifndef OPENSSL_NO_RSA
|
||||
{FT_general, "genrsa", genrsa_main, genrsa_options},
|
||||
#endif
|
||||
{FT_general, "help", help_main, help_options},
|
||||
{FT_general, "info", info_main, info_options},
|
||||
{FT_general, "kdf", kdf_main, kdf_options},
|
||||
{FT_general, "list", list_main, list_options},
|
||||
{FT_general, "mac", mac_main, mac_options},
|
||||
{FT_general, "nseq", nseq_main, nseq_options},
|
||||
#ifndef OPENSSL_NO_OCSP
|
||||
{FT_general, "ocsp", ocsp_main, ocsp_options},
|
||||
#endif
|
||||
{FT_general, "passwd", passwd_main, passwd_options},
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_general, "pkcs12", pkcs12_main, pkcs12_options},
|
||||
#endif
|
||||
{FT_general, "pkcs7", pkcs7_main, pkcs7_options},
|
||||
{FT_general, "pkcs8", pkcs8_main, pkcs8_options},
|
||||
{FT_general, "pkey", pkey_main, pkey_options},
|
||||
{FT_general, "pkeyparam", pkeyparam_main, pkeyparam_options},
|
||||
{FT_general, "pkeyutl", pkeyutl_main, pkeyutl_options},
|
||||
{FT_general, "prime", prime_main, prime_options},
|
||||
{FT_general, "provider", provider_main, provider_options},
|
||||
{FT_general, "rand", rand_main, rand_options},
|
||||
{FT_general, "rehash", rehash_main, rehash_options},
|
||||
{FT_general, "req", req_main, req_options},
|
||||
{FT_general, "rsa", rsa_main, rsa_options},
|
||||
#ifndef OPENSSL_NO_RSA
|
||||
{FT_general, "rsautl", rsautl_main, rsautl_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SOCK
|
||||
{FT_general, "s_client", s_client_main, s_client_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SOCK
|
||||
{FT_general, "s_server", s_server_main, s_server_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SOCK
|
||||
{FT_general, "s_time", s_time_main, s_time_options},
|
||||
#endif
|
||||
{FT_general, "sess_id", sess_id_main, sess_id_options},
|
||||
{FT_general, "smime", smime_main, smime_options},
|
||||
{FT_general, "speed", speed_main, speed_options},
|
||||
{FT_general, "spkac", spkac_main, spkac_options},
|
||||
#ifndef OPENSSL_NO_SRP
|
||||
{FT_general, "srp", srp_main, srp_options},
|
||||
#endif
|
||||
{FT_general, "storeutl", storeutl_main, storeutl_options},
|
||||
#ifndef OPENSSL_NO_TS
|
||||
{FT_general, "ts", ts_main, ts_options},
|
||||
#endif
|
||||
{FT_general, "verify", verify_main, verify_options},
|
||||
{FT_general, "version", version_main, version_options},
|
||||
{FT_general, "x509", x509_main, x509_options},
|
||||
#ifndef OPENSSL_NO_MD2
|
||||
{FT_md, "md2", dgst_main},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_MD4
|
||||
{FT_md, "md4", dgst_main},
|
||||
#endif
|
||||
{FT_md, "md5", dgst_main},
|
||||
#ifndef OPENSSL_NO_GOST
|
||||
{FT_md, "gost", dgst_main},
|
||||
#endif
|
||||
{FT_md, "sha1", dgst_main},
|
||||
{FT_md, "sha224", dgst_main},
|
||||
{FT_md, "sha256", dgst_main},
|
||||
{FT_md, "sha384", dgst_main},
|
||||
{FT_md, "sha512", dgst_main},
|
||||
{FT_md, "sha512-224", dgst_main},
|
||||
{FT_md, "sha512-256", dgst_main},
|
||||
{FT_md, "sha3-224", dgst_main},
|
||||
{FT_md, "sha3-256", dgst_main},
|
||||
{FT_md, "sha3-384", dgst_main},
|
||||
{FT_md, "sha3-512", dgst_main},
|
||||
{FT_md, "shake128", dgst_main},
|
||||
{FT_md, "shake256", dgst_main},
|
||||
#ifndef OPENSSL_NO_MDC2
|
||||
{FT_md, "mdc2", dgst_main},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RMD160
|
||||
{FT_md, "rmd160", dgst_main},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_BLAKE2
|
||||
{FT_md, "blake2b512", dgst_main},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_BLAKE2
|
||||
{FT_md, "blake2s256", dgst_main},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SM3
|
||||
{FT_md, "sm3", dgst_main},
|
||||
#endif
|
||||
{FT_cipher, "aes-128-cbc", enc_main, enc_options},
|
||||
{FT_cipher, "aes-128-ecb", enc_main, enc_options},
|
||||
{FT_cipher, "aes-192-cbc", enc_main, enc_options},
|
||||
{FT_cipher, "aes-192-ecb", enc_main, enc_options},
|
||||
{FT_cipher, "aes-256-cbc", enc_main, enc_options},
|
||||
{FT_cipher, "aes-256-ecb", enc_main, enc_options},
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-128-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-128-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-128-ctr", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-128-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-128-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-128-cfb1", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-128-cfb8", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-192-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-192-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-192-ctr", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-192-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-192-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-192-cfb1", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-192-cfb8", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-256-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-256-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-256-ctr", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-256-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-256-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-256-cfb1", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ARIA
|
||||
{FT_cipher, "aria-256-cfb8", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAMELLIA
|
||||
{FT_cipher, "camellia-128-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAMELLIA
|
||||
{FT_cipher, "camellia-128-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAMELLIA
|
||||
{FT_cipher, "camellia-192-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAMELLIA
|
||||
{FT_cipher, "camellia-192-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAMELLIA
|
||||
{FT_cipher, "camellia-256-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAMELLIA
|
||||
{FT_cipher, "camellia-256-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
{FT_cipher, "base64", enc_main, enc_options},
|
||||
#ifdef ZLIB
|
||||
{FT_cipher, "zlib", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des3", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "desx", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_IDEA
|
||||
{FT_cipher, "idea", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SEED
|
||||
{FT_cipher, "seed", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC4
|
||||
{FT_cipher, "rc4", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC4
|
||||
{FT_cipher, "rc4-40", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC2
|
||||
{FT_cipher, "rc2", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_BF
|
||||
{FT_cipher, "bf", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAST
|
||||
{FT_cipher, "cast", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC5
|
||||
{FT_cipher, "rc5", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede3", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede3-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede3-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_DES
|
||||
{FT_cipher, "des-ede3-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_IDEA
|
||||
{FT_cipher, "idea-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_IDEA
|
||||
{FT_cipher, "idea-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_IDEA
|
||||
{FT_cipher, "idea-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_IDEA
|
||||
{FT_cipher, "idea-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SEED
|
||||
{FT_cipher, "seed-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SEED
|
||||
{FT_cipher, "seed-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SEED
|
||||
{FT_cipher, "seed-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SEED
|
||||
{FT_cipher, "seed-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC2
|
||||
{FT_cipher, "rc2-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC2
|
||||
{FT_cipher, "rc2-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC2
|
||||
{FT_cipher, "rc2-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC2
|
||||
{FT_cipher, "rc2-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC2
|
||||
{FT_cipher, "rc2-64-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC2
|
||||
{FT_cipher, "rc2-40-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_BF
|
||||
{FT_cipher, "bf-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_BF
|
||||
{FT_cipher, "bf-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_BF
|
||||
{FT_cipher, "bf-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_BF
|
||||
{FT_cipher, "bf-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAST
|
||||
{FT_cipher, "cast5-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAST
|
||||
{FT_cipher, "cast5-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAST
|
||||
{FT_cipher, "cast5-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAST
|
||||
{FT_cipher, "cast5-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_CAST
|
||||
{FT_cipher, "cast-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC5
|
||||
{FT_cipher, "rc5-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC5
|
||||
{FT_cipher, "rc5-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC5
|
||||
{FT_cipher, "rc5-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_RC5
|
||||
{FT_cipher, "rc5-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SM4
|
||||
{FT_cipher, "sm4-cbc", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SM4
|
||||
{FT_cipher, "sm4-ecb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SM4
|
||||
{FT_cipher, "sm4-cfb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SM4
|
||||
{FT_cipher, "sm4-ofb", enc_main, enc_options},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SM4
|
||||
{FT_cipher, "sm4-ctr", enc_main, enc_options},
|
||||
#endif
|
||||
{0, NULL, NULL}
|
||||
};
|
||||
+132
-122
@@ -14,6 +14,10 @@ use warnings;
|
||||
use lib '.';
|
||||
use configdata qw/@disablables %unified_info/;
|
||||
|
||||
my $opt = shift @ARGV;
|
||||
die "Unrecognised option, must be -C or -H\n"
|
||||
unless ($opt eq '-H' || $opt eq '-C');
|
||||
|
||||
my %commands = ();
|
||||
my $cmdre = qr/^\s*int\s+([a-z_][a-z0-9_]*)_main\(\s*int\s+argc\s*,/;
|
||||
my $apps_openssl = shift @ARGV;
|
||||
@@ -38,7 +42,8 @@ foreach my $filename (@openssl_source) {
|
||||
|
||||
@ARGV = sort keys %commands;
|
||||
|
||||
print <<"EOF";
|
||||
if ($opt eq '-H') {
|
||||
print <<"EOF";
|
||||
/*
|
||||
* WARNING: do not edit!
|
||||
* Generated by apps/progs.pl
|
||||
@@ -51,134 +56,139 @@ print <<"EOF";
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <openssl/lhash.h>
|
||||
#include "opt.h"
|
||||
|
||||
typedef enum FUNC_TYPE {
|
||||
FT_none, FT_general, FT_md, FT_cipher, FT_pkey,
|
||||
FT_md_alg, FT_cipher_alg
|
||||
} FUNC_TYPE;
|
||||
|
||||
typedef struct function_st {
|
||||
FUNC_TYPE type;
|
||||
const char *name;
|
||||
int (*func)(int argc, char *argv[]);
|
||||
const OPTIONS *help;
|
||||
} FUNCTION;
|
||||
|
||||
DEFINE_LHASH_OF(FUNCTION);
|
||||
#include "function.h"
|
||||
|
||||
EOF
|
||||
|
||||
foreach (@ARGV) {
|
||||
printf "extern int %s_main(int argc, char *argv[]);\n", $_;
|
||||
}
|
||||
print "\n";
|
||||
|
||||
foreach (@ARGV) {
|
||||
printf "extern const OPTIONS %s_options[];\n", $_;
|
||||
}
|
||||
print "\n";
|
||||
|
||||
my %cmd_disabler = (
|
||||
ciphers => "sock",
|
||||
genrsa => "rsa",
|
||||
rsautl => "rsa",
|
||||
gendsa => "dsa",
|
||||
dsaparam => "dsa",
|
||||
gendh => "dh",
|
||||
dhparam => "dh",
|
||||
ecparam => "ec",
|
||||
pkcs12 => "des",
|
||||
);
|
||||
|
||||
print "#ifdef INCLUDE_FUNCTION_TABLE\n";
|
||||
print "static FUNCTION functions[] = {\n";
|
||||
foreach my $cmd ( @ARGV ) {
|
||||
my $str = " {FT_general, \"$cmd\", ${cmd}_main, ${cmd}_options},\n";
|
||||
if ($cmd =~ /^s_/) {
|
||||
print "#ifndef OPENSSL_NO_SOCK\n${str}#endif\n";
|
||||
} elsif (grep { $cmd eq $_ } @disablables) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n";
|
||||
} elsif (my $disabler = $cmd_disabler{$cmd}) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($disabler) . "\n${str}#endif\n";
|
||||
} else {
|
||||
print $str;
|
||||
foreach (@ARGV) {
|
||||
printf "extern int %s_main(int argc, char *argv[]);\n", $_;
|
||||
}
|
||||
}
|
||||
print "\n";
|
||||
|
||||
my %md_disabler = (
|
||||
blake2b512 => "blake2",
|
||||
blake2s256 => "blake2",
|
||||
);
|
||||
foreach my $cmd (
|
||||
"md2", "md4", "md5",
|
||||
"gost",
|
||||
"sha1", "sha224", "sha256", "sha384",
|
||||
"sha512", "sha512-224", "sha512-256",
|
||||
"sha3-224", "sha3-256", "sha3-384", "sha3-512",
|
||||
"shake128", "shake256",
|
||||
"mdc2", "rmd160", "blake2b512", "blake2s256",
|
||||
"sm3"
|
||||
) {
|
||||
my $str = " {FT_md, \"$cmd\", dgst_main},\n";
|
||||
if (grep { $cmd eq $_ } @disablables) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n";
|
||||
} elsif (my $disabler = $md_disabler{$cmd}) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($disabler) . "\n${str}#endif\n";
|
||||
} else {
|
||||
print $str;
|
||||
foreach (@ARGV) {
|
||||
printf "extern const OPTIONS %s_options[];\n", $_;
|
||||
}
|
||||
print "\n";
|
||||
print "extern FUNCTION functions[];\n";
|
||||
}
|
||||
|
||||
my %cipher_disabler = (
|
||||
des3 => "des",
|
||||
desx => "des",
|
||||
cast5 => "cast",
|
||||
);
|
||||
foreach my $cmd (
|
||||
"aes-128-cbc", "aes-128-ecb",
|
||||
"aes-192-cbc", "aes-192-ecb",
|
||||
"aes-256-cbc", "aes-256-ecb",
|
||||
"aria-128-cbc", "aria-128-cfb",
|
||||
"aria-128-ctr", "aria-128-ecb", "aria-128-ofb",
|
||||
"aria-128-cfb1", "aria-128-cfb8",
|
||||
"aria-192-cbc", "aria-192-cfb",
|
||||
"aria-192-ctr", "aria-192-ecb", "aria-192-ofb",
|
||||
"aria-192-cfb1", "aria-192-cfb8",
|
||||
"aria-256-cbc", "aria-256-cfb",
|
||||
"aria-256-ctr", "aria-256-ecb", "aria-256-ofb",
|
||||
"aria-256-cfb1", "aria-256-cfb8",
|
||||
"camellia-128-cbc", "camellia-128-ecb",
|
||||
"camellia-192-cbc", "camellia-192-ecb",
|
||||
"camellia-256-cbc", "camellia-256-ecb",
|
||||
"base64", "zlib",
|
||||
"des", "des3", "desx", "idea", "seed", "rc4", "rc4-40",
|
||||
"rc2", "bf", "cast", "rc5",
|
||||
"des-ecb", "des-ede", "des-ede3",
|
||||
"des-cbc", "des-ede-cbc","des-ede3-cbc",
|
||||
"des-cfb", "des-ede-cfb","des-ede3-cfb",
|
||||
"des-ofb", "des-ede-ofb","des-ede3-ofb",
|
||||
"idea-cbc","idea-ecb", "idea-cfb", "idea-ofb",
|
||||
"seed-cbc","seed-ecb", "seed-cfb", "seed-ofb",
|
||||
"rc2-cbc", "rc2-ecb", "rc2-cfb","rc2-ofb", "rc2-64-cbc", "rc2-40-cbc",
|
||||
"bf-cbc", "bf-ecb", "bf-cfb", "bf-ofb",
|
||||
"cast5-cbc","cast5-ecb", "cast5-cfb","cast5-ofb",
|
||||
"cast-cbc", "rc5-cbc", "rc5-ecb", "rc5-cfb", "rc5-ofb",
|
||||
"sm4-cbc", "sm4-ecb", "sm4-cfb", "sm4-ofb", "sm4-ctr"
|
||||
) {
|
||||
my $str = " {FT_cipher, \"$cmd\", enc_main, enc_options},\n";
|
||||
(my $algo = $cmd) =~ s/-.*//g;
|
||||
if ($cmd eq "zlib") {
|
||||
print "#ifdef ZLIB\n${str}#endif\n";
|
||||
} elsif (grep { $algo eq $_ } @disablables) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($algo) . "\n${str}#endif\n";
|
||||
} elsif (my $disabler = $cipher_disabler{$algo}) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($disabler) . "\n${str}#endif\n";
|
||||
} else {
|
||||
print $str;
|
||||
if ($opt eq '-C') {
|
||||
print <<"EOF";
|
||||
/*
|
||||
* WARNING: do not edit!
|
||||
* Generated by apps/progs.pl
|
||||
*
|
||||
* Copyright 1995-$YEAR The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include "progs.h"
|
||||
|
||||
EOF
|
||||
|
||||
my %cmd_disabler = (
|
||||
ciphers => "sock",
|
||||
genrsa => "rsa",
|
||||
rsautl => "rsa",
|
||||
gendsa => "dsa",
|
||||
dsaparam => "dsa",
|
||||
gendh => "dh",
|
||||
dhparam => "dh",
|
||||
ecparam => "ec",
|
||||
pkcs12 => "des",
|
||||
);
|
||||
|
||||
print "FUNCTION functions[] = {\n";
|
||||
foreach my $cmd ( @ARGV ) {
|
||||
my $str =
|
||||
" {FT_general, \"$cmd\", ${cmd}_main, ${cmd}_options},\n";
|
||||
if ($cmd =~ /^s_/) {
|
||||
print "#ifndef OPENSSL_NO_SOCK\n${str}#endif\n";
|
||||
} elsif (grep { $cmd eq $_ } @disablables) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n";
|
||||
} elsif (my $disabler = $cmd_disabler{$cmd}) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($disabler) . "\n${str}#endif\n";
|
||||
} else {
|
||||
print $str;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
print " {0, NULL, NULL}\n};\n";
|
||||
print "#endif\n";
|
||||
my %md_disabler = (
|
||||
blake2b512 => "blake2",
|
||||
blake2s256 => "blake2",
|
||||
);
|
||||
foreach my $cmd (
|
||||
"md2", "md4", "md5",
|
||||
"gost",
|
||||
"sha1", "sha224", "sha256", "sha384",
|
||||
"sha512", "sha512-224", "sha512-256",
|
||||
"sha3-224", "sha3-256", "sha3-384", "sha3-512",
|
||||
"shake128", "shake256",
|
||||
"mdc2", "rmd160", "blake2b512", "blake2s256",
|
||||
"sm3"
|
||||
) {
|
||||
my $str = " {FT_md, \"$cmd\", dgst_main},\n";
|
||||
if (grep { $cmd eq $_ } @disablables) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($cmd) . "\n${str}#endif\n";
|
||||
} elsif (my $disabler = $md_disabler{$cmd}) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($disabler) . "\n${str}#endif\n";
|
||||
} else {
|
||||
print $str;
|
||||
}
|
||||
}
|
||||
|
||||
my %cipher_disabler = (
|
||||
des3 => "des",
|
||||
desx => "des",
|
||||
cast5 => "cast",
|
||||
);
|
||||
foreach my $cmd (
|
||||
"aes-128-cbc", "aes-128-ecb",
|
||||
"aes-192-cbc", "aes-192-ecb",
|
||||
"aes-256-cbc", "aes-256-ecb",
|
||||
"aria-128-cbc", "aria-128-cfb",
|
||||
"aria-128-ctr", "aria-128-ecb", "aria-128-ofb",
|
||||
"aria-128-cfb1", "aria-128-cfb8",
|
||||
"aria-192-cbc", "aria-192-cfb",
|
||||
"aria-192-ctr", "aria-192-ecb", "aria-192-ofb",
|
||||
"aria-192-cfb1", "aria-192-cfb8",
|
||||
"aria-256-cbc", "aria-256-cfb",
|
||||
"aria-256-ctr", "aria-256-ecb", "aria-256-ofb",
|
||||
"aria-256-cfb1", "aria-256-cfb8",
|
||||
"camellia-128-cbc", "camellia-128-ecb",
|
||||
"camellia-192-cbc", "camellia-192-ecb",
|
||||
"camellia-256-cbc", "camellia-256-ecb",
|
||||
"base64", "zlib",
|
||||
"des", "des3", "desx", "idea", "seed", "rc4", "rc4-40",
|
||||
"rc2", "bf", "cast", "rc5",
|
||||
"des-ecb", "des-ede", "des-ede3",
|
||||
"des-cbc", "des-ede-cbc","des-ede3-cbc",
|
||||
"des-cfb", "des-ede-cfb","des-ede3-cfb",
|
||||
"des-ofb", "des-ede-ofb","des-ede3-ofb",
|
||||
"idea-cbc","idea-ecb", "idea-cfb", "idea-ofb",
|
||||
"seed-cbc","seed-ecb", "seed-cfb", "seed-ofb",
|
||||
"rc2-cbc", "rc2-ecb", "rc2-cfb","rc2-ofb", "rc2-64-cbc", "rc2-40-cbc",
|
||||
"bf-cbc", "bf-ecb", "bf-cfb", "bf-ofb",
|
||||
"cast5-cbc","cast5-ecb", "cast5-cfb","cast5-ofb",
|
||||
"cast-cbc", "rc5-cbc", "rc5-ecb", "rc5-cfb", "rc5-ofb",
|
||||
"sm4-cbc", "sm4-ecb", "sm4-cfb", "sm4-ofb", "sm4-ctr"
|
||||
) {
|
||||
my $str = " {FT_cipher, \"$cmd\", enc_main, enc_options},\n";
|
||||
(my $algo = $cmd) =~ s/-.*//g;
|
||||
if ($cmd eq "zlib") {
|
||||
print "#ifdef ZLIB\n${str}#endif\n";
|
||||
} elsif (grep { $algo eq $_ } @disablables) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($algo) . "\n${str}#endif\n";
|
||||
} elsif (my $disabler = $cipher_disabler{$algo}) {
|
||||
print "#ifndef OPENSSL_NO_" . uc($disabler) . "\n${str}#endif\n";
|
||||
} else {
|
||||
print $str;
|
||||
}
|
||||
}
|
||||
|
||||
print " {0, NULL, NULL}\n};\n";
|
||||
}
|
||||
+287
@@ -0,0 +1,287 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <openssl/opensslconf.h>
|
||||
|
||||
#include "apps.h"
|
||||
#include "app_params.h"
|
||||
#include "progs.h"
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/safestack.h>
|
||||
#include <openssl/provider.h>
|
||||
#include <openssl/core.h>
|
||||
#include <openssl/core_numbers.h>
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP,
|
||||
OPT_V = 100, OPT_VV, OPT_VVV
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS provider_options[] = {
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] provider...\n"},
|
||||
{OPT_HELP_STR, 1, '-', " provider... Providers to load\n"},
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"v", OPT_V, '-', "List the algorithm names of specified provider"},
|
||||
{"vv", OPT_VV, '-', "List the algorithm names of specified providers,"},
|
||||
{OPT_MORE_STR, 0, '-', "categorised by operation type"},
|
||||
{"vvv", OPT_VVV, '-', "List the algorithm names of specified provider"},
|
||||
{OPT_MORE_STR, 0, '-', "one at a time, and list all known parameters"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
typedef struct info_st INFO;
|
||||
typedef struct meta_st META;
|
||||
|
||||
struct info_st {
|
||||
const char *name;
|
||||
void *method;
|
||||
const OSSL_PARAM *gettable_params;
|
||||
const OSSL_PARAM *gettable_ctx_params;
|
||||
const OSSL_PARAM *settable_ctx_params;
|
||||
};
|
||||
|
||||
struct meta_st {
|
||||
int first; /* For prints */
|
||||
int total;
|
||||
int indent;
|
||||
int subindent;
|
||||
int verbose;
|
||||
const char *label;
|
||||
OSSL_PROVIDER *prov;
|
||||
void (*fn)(META *meta, INFO *info);
|
||||
};
|
||||
|
||||
static void print_caps(META *meta, INFO *info)
|
||||
{
|
||||
switch (meta->verbose) {
|
||||
case 1:
|
||||
BIO_printf(bio_out, meta->first ? "%s" : " %s", info->name);
|
||||
break;
|
||||
case 2:
|
||||
if (meta->first) {
|
||||
if (meta->total > 0)
|
||||
BIO_printf(bio_out, "\n");
|
||||
BIO_printf(bio_out, "%*s%ss:", meta->indent, "", meta->label);
|
||||
}
|
||||
BIO_printf(bio_out, " %s", info->name);
|
||||
break;
|
||||
case 3:
|
||||
default:
|
||||
BIO_printf(bio_out, "%*s%s %s\n", meta->indent, "", meta->label,
|
||||
info->name);
|
||||
print_param_types("retrievable algorithm parameters",
|
||||
info->gettable_params, meta->subindent);
|
||||
print_param_types("retrievable operation parameters",
|
||||
info->gettable_ctx_params, meta->subindent);
|
||||
print_param_types("settable operation parameters",
|
||||
info->settable_ctx_params, meta->subindent);
|
||||
break;
|
||||
}
|
||||
meta->first = 0;
|
||||
}
|
||||
|
||||
static void do_method(void *method, const char *name,
|
||||
const OSSL_PARAM *gettable_params,
|
||||
const OSSL_PARAM *gettable_ctx_params,
|
||||
const OSSL_PARAM *settable_ctx_params,
|
||||
META *meta)
|
||||
{
|
||||
INFO info;
|
||||
|
||||
info.name = name;
|
||||
info.method = method;
|
||||
info.gettable_params = gettable_params;
|
||||
info.gettable_ctx_params = gettable_ctx_params;
|
||||
info.settable_ctx_params = settable_ctx_params;
|
||||
meta->fn(meta, &info);
|
||||
meta->total++;
|
||||
}
|
||||
|
||||
static void do_cipher(EVP_CIPHER *cipher, void *meta)
|
||||
{
|
||||
do_method(cipher, EVP_CIPHER_name(cipher),
|
||||
EVP_CIPHER_gettable_params(cipher),
|
||||
EVP_CIPHER_CTX_gettable_params(cipher),
|
||||
EVP_CIPHER_CTX_settable_params(cipher),
|
||||
meta);
|
||||
}
|
||||
|
||||
static void do_digest(EVP_MD *digest, void *meta)
|
||||
{
|
||||
do_method(digest, EVP_MD_name(digest),
|
||||
EVP_MD_gettable_params(digest),
|
||||
EVP_MD_CTX_gettable_params(digest),
|
||||
EVP_MD_CTX_settable_params(digest),
|
||||
meta);
|
||||
}
|
||||
|
||||
static void do_mac(EVP_MAC *mac, void *meta)
|
||||
{
|
||||
do_method(mac, EVP_MAC_name(mac),
|
||||
EVP_MAC_gettable_params(mac),
|
||||
EVP_MAC_CTX_gettable_params(mac),
|
||||
EVP_MAC_CTX_settable_params(mac),
|
||||
meta);
|
||||
}
|
||||
|
||||
/*
|
||||
* TODO(3.0) Enable when KEYMGMT and KEYEXCH have gettables and settables
|
||||
*/
|
||||
#if 0
|
||||
static void do_keymgmt(EVP_KEYMGMT *keymgmt, void *meta)
|
||||
{
|
||||
do_method(keymgmt, EVP_KEYMGMT_name(keymgmt),
|
||||
EVP_KEYMGMT_gettable_params(keymgmt),
|
||||
EVP_KEYMGMT_gettable_ctx_params(keymgmt),
|
||||
EVP_KEYMGMT_settable_ctx_params(keymgmt),
|
||||
meta);
|
||||
}
|
||||
|
||||
static void do_keyexch(EVP_KEYEXCH *keyexch, void *meta)
|
||||
{
|
||||
do_method(keyexch, EVP_KEYEXCH_name(keyexch),
|
||||
EVP_KEYEXCH_gettable_params(keyexch),
|
||||
EVP_KEYEXCH_gettable_ctx_params(keyexch),
|
||||
EVP_KEYEXCH_settable_ctx_params(keyexch),
|
||||
meta);
|
||||
}
|
||||
#endif
|
||||
|
||||
int provider_main(int argc, char **argv)
|
||||
{
|
||||
int ret = 1, i;
|
||||
int verbose = 0;
|
||||
STACK_OF(OPENSSL_CSTRING) *providers = sk_OPENSSL_CSTRING_new_null();
|
||||
OPTION_CHOICE o;
|
||||
char *prog;
|
||||
|
||||
prog = opt_init(argc, argv, provider_options);
|
||||
while ((o = opt_next()) != OPT_EOF) {
|
||||
switch (o) {
|
||||
default: /* Catching OPT_ERR & covering OPT_EOF which isn't possible */
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
opt_help(provider_options);
|
||||
ret = 0;
|
||||
goto end;
|
||||
case OPT_VVV:
|
||||
case OPT_VV:
|
||||
case OPT_V:
|
||||
/* Convert to an integer from one to four. */
|
||||
i = (int)(o - OPT_V) + 1;
|
||||
if (verbose < i)
|
||||
verbose = i;
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/* Allow any trailing parameters as provider names. */
|
||||
argc = opt_num_rest();
|
||||
argv = opt_rest();
|
||||
for ( ; *argv; argv++) {
|
||||
if (**argv == '-') {
|
||||
BIO_printf(bio_err, "%s: Cannot mix flags and provider names.\n",
|
||||
prog);
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
}
|
||||
sk_OPENSSL_CSTRING_push(providers, *argv);
|
||||
}
|
||||
|
||||
ret = 0;
|
||||
for (i = 0; i < sk_OPENSSL_CSTRING_num(providers); i++) {
|
||||
const char *name = sk_OPENSSL_CSTRING_value(providers, i);
|
||||
OSSL_PROVIDER *prov = OSSL_PROVIDER_load(NULL, name);
|
||||
|
||||
if (prov != NULL) {
|
||||
BIO_printf(bio_out, verbose == 0 ? "%s\n" : "[ %s ]\n", name);
|
||||
|
||||
if (verbose > 0) {
|
||||
META data;
|
||||
|
||||
data.total = 0;
|
||||
data.first = 1;
|
||||
data.verbose = verbose;
|
||||
data.prov = prov;
|
||||
data.fn = print_caps;
|
||||
|
||||
switch (verbose) {
|
||||
case 1:
|
||||
BIO_printf(bio_out, " ");
|
||||
break;
|
||||
case 2:
|
||||
data.indent = 4;
|
||||
break;
|
||||
case 3:
|
||||
default:
|
||||
data.indent = 4;
|
||||
data.subindent = 10;
|
||||
break;
|
||||
}
|
||||
|
||||
if (verbose > 1) {
|
||||
data.first = 1;
|
||||
data.label = "Cipher";
|
||||
}
|
||||
EVP_CIPHER_do_all_ex(NULL, do_cipher, &data);
|
||||
if (verbose > 1) {
|
||||
data.first = 1;
|
||||
data.label = "Digest";
|
||||
}
|
||||
EVP_MD_do_all_ex(NULL, do_digest, &data);
|
||||
if (verbose > 1) {
|
||||
data.first = 1;
|
||||
data.label = "MAC";
|
||||
}
|
||||
EVP_MAC_do_all_ex(NULL, do_mac, &data);
|
||||
|
||||
/*
|
||||
* TODO(3.0) Enable when KEYMGMT and KEYEXCH have do_all_ex functions
|
||||
*/
|
||||
#if 0
|
||||
if (verbose > 1) {
|
||||
data.first = 1;
|
||||
data.label = "Key manager";
|
||||
}
|
||||
EVP_KEYMGMT_do_all_ex(NULL, do_keymgmt, &data);
|
||||
if (verbose > 1) {
|
||||
data.first = 1;
|
||||
data.label = "Key exchange";
|
||||
}
|
||||
EVP_KEYEXCH_do_all_ex(NULL, do_keyexch, &data);
|
||||
#endif
|
||||
|
||||
switch (verbose) {
|
||||
default:
|
||||
break;
|
||||
case 2:
|
||||
case 1:
|
||||
BIO_printf(bio_out, "\n");
|
||||
break;
|
||||
}
|
||||
}
|
||||
OSSL_PROVIDER_unload(prov);
|
||||
} else {
|
||||
ERR_print_errors(bio_err);
|
||||
ret = 1;
|
||||
/*
|
||||
* Just because one provider module failed, there's no reason to
|
||||
* stop, if there are more to try.
|
||||
*/
|
||||
}
|
||||
}
|
||||
|
||||
end:
|
||||
|
||||
ERR_print_errors(bio_err);
|
||||
sk_OPENSSL_CSTRING_free(providers);
|
||||
return ret;
|
||||
}
|
||||
@@ -227,7 +227,6 @@ int rsa_main(int argc, char **argv)
|
||||
|
||||
while ((err = ERR_peek_error()) != 0 &&
|
||||
ERR_GET_LIB(err) == ERR_LIB_RSA &&
|
||||
ERR_GET_FUNC(err) == RSA_F_RSA_CHECK_KEY_EX &&
|
||||
ERR_GET_REASON(err) != ERR_R_MALLOC_FAILURE) {
|
||||
BIO_printf(out, "RSA key error: %s\n",
|
||||
ERR_reason_error_string(err));
|
||||
|
||||
+3
-3
@@ -2017,7 +2017,7 @@ int s_client_main(int argc, char **argv)
|
||||
|
||||
if (!noservername && (servername != NULL || dane_tlsa_domain == NULL)) {
|
||||
if (servername == NULL) {
|
||||
if(host == NULL || is_dNS_name(host))
|
||||
if(host == NULL || is_dNS_name(host))
|
||||
servername = (host == NULL) ? "localhost" : host;
|
||||
}
|
||||
if (servername != NULL && !SSL_set_tlsext_host_name(con, servername)) {
|
||||
@@ -3104,7 +3104,7 @@ int s_client_main(int argc, char **argv)
|
||||
BIO_printf(bio_err, "RENEGOTIATING\n");
|
||||
SSL_renegotiate(con);
|
||||
cbuf_len = 0;
|
||||
} else if (!c_ign_eof && (cbuf[0] == 'K' || cbuf[0] == 'k' )
|
||||
} else if (!c_ign_eof && (cbuf[0] == 'K' || cbuf[0] == 'k' )
|
||||
&& cmdletters) {
|
||||
BIO_printf(bio_err, "KEYUPDATE\n");
|
||||
SSL_key_update(con,
|
||||
@@ -3552,7 +3552,7 @@ static char *base64encode (const void *buf, size_t len)
|
||||
}
|
||||
|
||||
/*
|
||||
* Host dNS Name verifier: used for checking that the hostname is in dNS format
|
||||
* Host dNS Name verifier: used for checking that the hostname is in dNS format
|
||||
* before setting it as SNI
|
||||
*/
|
||||
static int is_dNS_name(const char *host)
|
||||
|
||||
+1
-1
@@ -470,7 +470,7 @@ static int ssl_servername_cb(SSL *s, int *ad, void *arg)
|
||||
BIO_printf(p->biodebug, "Hostname in TLS extension: \"");
|
||||
while ((uc = *cp++) != 0)
|
||||
BIO_printf(p->biodebug,
|
||||
isascii(uc) && isprint(uc) ? "%c" : "\\x%02x", uc);
|
||||
(((uc) & ~127) == 0) && isprint(uc) ? "%c" : "\\x%02x", uc);
|
||||
BIO_printf(p->biodebug, "\"\n");
|
||||
}
|
||||
|
||||
|
||||
+3
-3
@@ -3114,7 +3114,6 @@ int speed_main(int argc, char **argv)
|
||||
if (error == ERR_peek_last_error() && /* oldest and latest errors match */
|
||||
/* check that the error origin matches */
|
||||
ERR_GET_LIB(error) == ERR_LIB_EVP &&
|
||||
ERR_GET_FUNC(error) == EVP_F_INT_CTX_NEW &&
|
||||
ERR_GET_REASON(error) == EVP_R_UNSUPPORTED_ALGORITHM)
|
||||
ERR_get_error(); /* pop error from queue */
|
||||
if (ERR_peek_error()) {
|
||||
@@ -3364,6 +3363,7 @@ int speed_main(int argc, char **argv)
|
||||
printf("%s ", BF_options());
|
||||
#endif
|
||||
printf("\n%s\n", OpenSSL_version(OPENSSL_CFLAGS));
|
||||
printf("%s\n", OpenSSL_version(OPENSSL_CPU_INFO));
|
||||
}
|
||||
|
||||
if (pr_header) {
|
||||
@@ -3638,7 +3638,7 @@ static int do_multi(int multi, int size_num)
|
||||
close(fd[1]);
|
||||
mr = 1;
|
||||
usertime = 0;
|
||||
free(fds);
|
||||
OPENSSL_free(fds);
|
||||
return 0;
|
||||
}
|
||||
printf("Forked child %d\n", n);
|
||||
@@ -3750,7 +3750,7 @@ static int do_multi(int multi, int size_num)
|
||||
|
||||
fclose(f);
|
||||
}
|
||||
free(fds);
|
||||
OPENSSL_free(fds);
|
||||
return 1;
|
||||
}
|
||||
#endif
|
||||
|
||||
+11
-45
@@ -33,7 +33,7 @@
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP,
|
||||
OPT_B, OPT_D, OPT_E, OPT_M, OPT_F, OPT_O, OPT_P, OPT_V, OPT_A, OPT_R
|
||||
OPT_B, OPT_D, OPT_E, OPT_M, OPT_F, OPT_O, OPT_P, OPT_V, OPT_A, OPT_R, OPT_C
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS version_options[] = {
|
||||
@@ -48,24 +48,15 @@ const OPTIONS version_options[] = {
|
||||
{"p", OPT_P, '-', "Show target build platform"},
|
||||
{"r", OPT_R, '-', "Show random seeding options"},
|
||||
{"v", OPT_V, '-', "Show library version"},
|
||||
{"c", OPT_C, '-', "Show CPU settings info"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
#if defined(OPENSSL_RAND_SEED_DEVRANDOM) || defined(OPENSSL_RAND_SEED_EGD)
|
||||
static void printlist(const char *prefix, const char **dev)
|
||||
{
|
||||
printf("%s (", prefix);
|
||||
for ( ; *dev != NULL; dev++)
|
||||
printf(" \"%s\"", *dev);
|
||||
printf(" )");
|
||||
}
|
||||
#endif
|
||||
|
||||
int version_main(int argc, char **argv)
|
||||
{
|
||||
int ret = 1, dirty = 0, seed = 0;
|
||||
int cflags = 0, version = 0, date = 0, options = 0, platform = 0, dir = 0;
|
||||
int engdir = 0, moddir = 0;
|
||||
int engdir = 0, moddir = 0, cpuinfo = 0;
|
||||
char *prog;
|
||||
OPTION_CHOICE o;
|
||||
|
||||
@@ -108,9 +99,12 @@ opthelp:
|
||||
case OPT_V:
|
||||
dirty = version = 1;
|
||||
break;
|
||||
case OPT_C:
|
||||
dirty = cpuinfo = 1;
|
||||
break;
|
||||
case OPT_A:
|
||||
seed = options = cflags = version = date = platform
|
||||
= dir = engdir = moddir
|
||||
= dir = engdir = moddir = cpuinfo
|
||||
= 1;
|
||||
break;
|
||||
}
|
||||
@@ -158,39 +152,11 @@ opthelp:
|
||||
if (moddir)
|
||||
printf("%s\n", OpenSSL_version(OPENSSL_MODULES_DIR));
|
||||
if (seed) {
|
||||
printf("Seeding source:");
|
||||
#ifdef OPENSSL_RAND_SEED_RTDSC
|
||||
printf(" rtdsc");
|
||||
#endif
|
||||
#ifdef OPENSSL_RAND_SEED_RDCPU
|
||||
printf(" rdrand ( rdseed rdrand )");
|
||||
#endif
|
||||
#ifdef OPENSSL_RAND_SEED_LIBRANDOM
|
||||
printf(" C-library-random");
|
||||
#endif
|
||||
#ifdef OPENSSL_RAND_SEED_GETRANDOM
|
||||
printf(" getrandom-syscall");
|
||||
#endif
|
||||
#ifdef OPENSSL_RAND_SEED_DEVRANDOM
|
||||
{
|
||||
static const char *dev[] = { DEVRANDOM, NULL };
|
||||
printlist(" random-device", dev);
|
||||
}
|
||||
#endif
|
||||
#ifdef OPENSSL_RAND_SEED_EGD
|
||||
{
|
||||
static const char *dev[] = { DEVRANDOM_EGD, NULL };
|
||||
printlist(" EGD", dev);
|
||||
}
|
||||
#endif
|
||||
#ifdef OPENSSL_RAND_SEED_NONE
|
||||
printf(" none");
|
||||
#endif
|
||||
#ifdef OPENSSL_RAND_SEED_OS
|
||||
printf(" os-specific");
|
||||
#endif
|
||||
printf("\n");
|
||||
const char *src = OPENSSL_info(OPENSSL_INFO_SEED_SOURCE);
|
||||
printf("Seeding source: %s\n", src ? src : "N/A");
|
||||
}
|
||||
if (cpuinfo)
|
||||
printf("%s\n", OpenSSL_version(OPENSSL_CPU_INFO));
|
||||
ret = 0;
|
||||
end:
|
||||
return ret;
|
||||
|
||||
Reference in New Issue
Block a user