pki: Optionally extract public key from given private key in --issue

Fixes #618.
This commit is contained in:
Tobias Brunner
2015-08-10 12:33:02 +02:00
parent 99b1a1a1d8
commit 1bc2549914
2 changed files with 30 additions and 6 deletions
+27 -4
View File
@@ -64,6 +64,8 @@ static int issue()
certificate_t *cert_req = NULL, *cert = NULL, *ca =NULL; certificate_t *cert_req = NULL, *cert = NULL, *ca =NULL;
private_key_t *private = NULL; private_key_t *private = NULL;
public_key_t *public = NULL; public_key_t *public = NULL;
credential_type_t type = CRED_PUBLIC_KEY;
key_type_t subtype = KEY_ANY;
bool pkcs10 = FALSE; bool pkcs10 = FALSE;
char *file = NULL, *dn = NULL, *hex = NULL, *cacert = NULL, *cakey = NULL; char *file = NULL, *dn = NULL, *hex = NULL, *cacert = NULL, *cakey = NULL;
char *error = NULL, *keyid = NULL; char *error = NULL, *keyid = NULL;
@@ -100,6 +102,21 @@ static int issue()
{ {
pkcs10 = TRUE; pkcs10 = TRUE;
} }
else if (streq(arg, "rsa"))
{
type = CRED_PRIVATE_KEY;
subtype = KEY_RSA;
}
else if (streq(arg, "ecdsa"))
{
type = CRED_PRIVATE_KEY;
subtype = KEY_ECDSA;
}
else if (streq(arg, "bliss"))
{
type = CRED_PRIVATE_KEY;
subtype = KEY_BLISS;
}
else if (!streq(arg, "pub")) else if (!streq(arg, "pub"))
{ {
error = "invalid input type"; error = "invalid input type";
@@ -447,10 +464,10 @@ static int issue()
} }
else else
{ {
DBG2(DBG_LIB, "Reading public key:"); DBG2(DBG_LIB, "Reading key:");
if (file) if (file)
{ {
public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, public = lib->creds->create(lib->creds, type, subtype,
BUILD_FROM_FILE, file, BUILD_END); BUILD_FROM_FILE, file, BUILD_END);
} }
else else
@@ -460,13 +477,19 @@ static int issue()
if (!chunk_from_fd(0, &chunk)) if (!chunk_from_fd(0, &chunk))
{ {
fprintf(stderr, "%s: ", strerror(errno)); fprintf(stderr, "%s: ", strerror(errno));
error = "reading public key failed"; error = "reading key failed";
goto end; goto end;
} }
public = lib->creds->create(lib->creds, CRED_PUBLIC_KEY, KEY_ANY, public = lib->creds->create(lib->creds, type, subtype,
BUILD_BLOB, chunk, BUILD_END); BUILD_BLOB, chunk, BUILD_END);
free(chunk.ptr); free(chunk.ptr);
} }
if (public && type == CRED_PRIVATE_KEY)
{
private_key_t *priv = (private_key_t*)public;
public = priv->get_public_key(priv);
priv->destroy(priv);
}
} }
if (!public) if (!public)
{ {
+3 -2
View File
@@ -67,8 +67,9 @@ Public key or PKCS#10 certificate request file to issue. If not given the
key/request is read from \fISTDIN\fR. key/request is read from \fISTDIN\fR.
.TP .TP
.BI "\-t, \-\-type " type .BI "\-t, \-\-type " type
Type of the input. Either \fIpub\fR for a public key, or \fIpkcs10\fR for a Type of the input. One of \fIpub\fR (public key), \fIrsa\fR (RSA private key),
PKCS#10 certificate request, defaults to \fIpub\fR. \fIecdsa\fR (ECDSA private key), or \fIpkcs10\fR (PKCS#10 certificate request),
defaults to \fIpub\fR.
.TP .TP
.BI "\-k, \-\-cakey " file .BI "\-k, \-\-cakey " file
CA private key file. Either this or CA private key file. Either this or