vici: Add support to load certificates from file paths

Probably not that useful via swanctl.conf but could be when used via VICI.
This commit is contained in:
Tobias Brunner
2017-02-16 19:24:08 +01:00
parent 00bf6a2a49
commit 2f8354ca6c
2 changed files with 68 additions and 13 deletions
+32 -13
View File
@@ -254,6 +254,7 @@ typedef struct {
char *handle; char *handle;
uint32_t slot; uint32_t slot;
char *module; char *module;
char *file;
} cert_data_t; } cert_data_t;
/** /**
@@ -263,6 +264,7 @@ static void free_cert_data(cert_data_t *data)
{ {
free(data->handle); free(data->handle);
free(data->module); free(data->module);
free(data->file);
free(data); free(data);
} }
@@ -1402,6 +1404,7 @@ CALLBACK(cert_kv, bool,
{ "handle", parse_string, &cert->handle }, { "handle", parse_string, &cert->handle },
{ "slot", parse_uint32, &cert->slot }, { "slot", parse_uint32, &cert->slot },
{ "module", parse_string, &cert->module }, { "module", parse_string, &cert->module },
{ "file", parse_string, &cert->file },
}; };
return parse_rules(rules, countof(rules), name, value, return parse_rules(rules, countof(rules), name, value,
@@ -1556,30 +1559,46 @@ CALLBACK(auth_sn, bool,
free_cert_data(data); free_cert_data(data);
return FALSE; return FALSE;
} }
if (!data->handle) if (!data->handle && !data->file)
{ {
auth->request->reply = create_reply("CKA_ID missing: %s", name); auth->request->reply = create_reply("handle or file path missing: "
"%s", name);
free_cert_data(data);
return FALSE;
}
else if (data->handle && data->file)
{
auth->request->reply = create_reply("handle and file path given: "
"%s", name);
free_cert_data(data); free_cert_data(data);
return FALSE; return FALSE;
} }
handle = chunk_from_hex(chunk_from_str(data->handle), NULL); if (data->file)
if (data->slot != -1)
{ {
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509, cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509,
BUILD_PKCS11_KEYID, handle, BUILD_FROM_FILE, data->file, BUILD_END);
BUILD_PKCS11_SLOT, data->slot,
data->module ? BUILD_PKCS11_MODULE : BUILD_END,
data->module, BUILD_END);
} }
else else
{ {
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509, handle = chunk_from_hex(chunk_from_str(data->handle), NULL);
BUILD_PKCS11_KEYID, handle, if (data->slot != -1)
data->module ? BUILD_PKCS11_MODULE : BUILD_END, {
data->module, BUILD_END); cert = lib->creds->create(lib->creds, CRED_CERTIFICATE,
CERT_X509, BUILD_PKCS11_KEYID, handle,
BUILD_PKCS11_SLOT, data->slot,
data->module ? BUILD_PKCS11_MODULE : BUILD_END,
data->module, BUILD_END);
}
else
{
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE,
CERT_X509, BUILD_PKCS11_KEYID, handle,
data->module ? BUILD_PKCS11_MODULE : BUILD_END,
data->module, BUILD_END);
}
chunk_free(&handle);
} }
chunk_free(&handle);
free_cert_data(data); free_cert_data(data);
if (!cert) if (!cert)
{ {
+36
View File
@@ -299,9 +299,21 @@ connections.<conn>.local<suffix>.cert<suffix> =
in _certs_ are transmitted as binary blobs, these sections offer more in _certs_ are transmitted as binary blobs, these sections offer more
flexibility. flexibility.
connections.<conn>.local<suffix>.cert<suffix>.file =
Absolute path to the certificate to load.
Absolute path to the certificate to load. Passed as-is to the daemon, so it
must be readable by it.
Configure either this or _handle_, but not both, in one section.
connections.<conn>.local<suffix>.cert<suffix>.handle = connections.<conn>.local<suffix>.cert<suffix>.handle =
Hex-encoded CKA_ID of the certificate on a token. Hex-encoded CKA_ID of the certificate on a token.
Hex-encoded CKA_ID of the certificate on a token.
Configure either this or _file_, but not both, in one section.
connections.<conn>.local<suffix>.cert<suffix>.slot = connections.<conn>.local<suffix>.cert<suffix>.slot =
Optional slot number of the token that stores the certificate. Optional slot number of the token that stores the certificate.
@@ -442,9 +454,21 @@ connections.<conn>.remote<suffix>.cert<suffix> =
in _certs_ are transmitted as binary blobs, these sections offer more in _certs_ are transmitted as binary blobs, these sections offer more
flexibility. flexibility.
connections.<conn>.remote<suffix>.cert<suffix>.file =
Absolute path to the certificate to load.
Absolute path to the certificate to load. Passed as-is to the daemon, so it
must be readable by it.
Configure either this or _handle_, but not both, in one section.
connections.<conn>.remote<suffix>.cert<suffix>.handle = connections.<conn>.remote<suffix>.cert<suffix>.handle =
Hex-encoded CKA_ID of the certificate on a token. Hex-encoded CKA_ID of the certificate on a token.
Hex-encoded CKA_ID of the certificate on a token.
Configure either this or _file_, but not both, in one section.
connections.<conn>.remote<suffix>.cert<suffix>.slot = connections.<conn>.remote<suffix>.cert<suffix>.slot =
Optional slot number of the token that stores the certificate. Optional slot number of the token that stores the certificate.
@@ -465,9 +489,21 @@ connections.<conn>.remote<suffix>.cacert<suffix> =
in _cacerts_ are transmitted as binary blobs, these sections offer more in _cacerts_ are transmitted as binary blobs, these sections offer more
flexibility. flexibility.
connections.<conn>.remote<suffix>.cacert<suffix>.file =
Absolute path to the certificate to load.
Absolute path to the certificate to load. Passed as-is to the daemon, so it
must be readable by it.
Configure either this or _handle_, but not both, in one section.
connections.<conn>.remote<suffix>.cacert<suffix>.handle = connections.<conn>.remote<suffix>.cacert<suffix>.handle =
Hex-encoded CKA_ID of the CA certificate on a token. Hex-encoded CKA_ID of the CA certificate on a token.
Hex-encoded CKA_ID of the CA certificate on a token.
Configure either this or _file_, but not both, in one section.
connections.<conn>.remote<suffix>.cacert<suffix>.slot = connections.<conn>.remote<suffix>.cacert<suffix>.slot =
Optional slot number of the token that stores the CA certificate. Optional slot number of the token that stores the CA certificate.