vici: Add support to load certificates from file paths
Probably not that useful via swanctl.conf but could be when used via VICI.
This commit is contained in:
@@ -254,6 +254,7 @@ typedef struct {
|
|||||||
char *handle;
|
char *handle;
|
||||||
uint32_t slot;
|
uint32_t slot;
|
||||||
char *module;
|
char *module;
|
||||||
|
char *file;
|
||||||
} cert_data_t;
|
} cert_data_t;
|
||||||
|
|
||||||
/**
|
/**
|
||||||
@@ -263,6 +264,7 @@ static void free_cert_data(cert_data_t *data)
|
|||||||
{
|
{
|
||||||
free(data->handle);
|
free(data->handle);
|
||||||
free(data->module);
|
free(data->module);
|
||||||
|
free(data->file);
|
||||||
free(data);
|
free(data);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1402,6 +1404,7 @@ CALLBACK(cert_kv, bool,
|
|||||||
{ "handle", parse_string, &cert->handle },
|
{ "handle", parse_string, &cert->handle },
|
||||||
{ "slot", parse_uint32, &cert->slot },
|
{ "slot", parse_uint32, &cert->slot },
|
||||||
{ "module", parse_string, &cert->module },
|
{ "module", parse_string, &cert->module },
|
||||||
|
{ "file", parse_string, &cert->file },
|
||||||
};
|
};
|
||||||
|
|
||||||
return parse_rules(rules, countof(rules), name, value,
|
return parse_rules(rules, countof(rules), name, value,
|
||||||
@@ -1556,30 +1559,46 @@ CALLBACK(auth_sn, bool,
|
|||||||
free_cert_data(data);
|
free_cert_data(data);
|
||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
if (!data->handle)
|
if (!data->handle && !data->file)
|
||||||
{
|
{
|
||||||
auth->request->reply = create_reply("CKA_ID missing: %s", name);
|
auth->request->reply = create_reply("handle or file path missing: "
|
||||||
|
"%s", name);
|
||||||
|
free_cert_data(data);
|
||||||
|
return FALSE;
|
||||||
|
}
|
||||||
|
else if (data->handle && data->file)
|
||||||
|
{
|
||||||
|
auth->request->reply = create_reply("handle and file path given: "
|
||||||
|
"%s", name);
|
||||||
free_cert_data(data);
|
free_cert_data(data);
|
||||||
return FALSE;
|
return FALSE;
|
||||||
}
|
}
|
||||||
|
|
||||||
handle = chunk_from_hex(chunk_from_str(data->handle), NULL);
|
if (data->file)
|
||||||
if (data->slot != -1)
|
|
||||||
{
|
{
|
||||||
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509,
|
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509,
|
||||||
BUILD_PKCS11_KEYID, handle,
|
BUILD_FROM_FILE, data->file, BUILD_END);
|
||||||
BUILD_PKCS11_SLOT, data->slot,
|
|
||||||
data->module ? BUILD_PKCS11_MODULE : BUILD_END,
|
|
||||||
data->module, BUILD_END);
|
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE, CERT_X509,
|
handle = chunk_from_hex(chunk_from_str(data->handle), NULL);
|
||||||
BUILD_PKCS11_KEYID, handle,
|
if (data->slot != -1)
|
||||||
data->module ? BUILD_PKCS11_MODULE : BUILD_END,
|
{
|
||||||
data->module, BUILD_END);
|
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE,
|
||||||
|
CERT_X509, BUILD_PKCS11_KEYID, handle,
|
||||||
|
BUILD_PKCS11_SLOT, data->slot,
|
||||||
|
data->module ? BUILD_PKCS11_MODULE : BUILD_END,
|
||||||
|
data->module, BUILD_END);
|
||||||
|
}
|
||||||
|
else
|
||||||
|
{
|
||||||
|
cert = lib->creds->create(lib->creds, CRED_CERTIFICATE,
|
||||||
|
CERT_X509, BUILD_PKCS11_KEYID, handle,
|
||||||
|
data->module ? BUILD_PKCS11_MODULE : BUILD_END,
|
||||||
|
data->module, BUILD_END);
|
||||||
|
}
|
||||||
|
chunk_free(&handle);
|
||||||
}
|
}
|
||||||
chunk_free(&handle);
|
|
||||||
free_cert_data(data);
|
free_cert_data(data);
|
||||||
if (!cert)
|
if (!cert)
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -299,9 +299,21 @@ connections.<conn>.local<suffix>.cert<suffix> =
|
|||||||
in _certs_ are transmitted as binary blobs, these sections offer more
|
in _certs_ are transmitted as binary blobs, these sections offer more
|
||||||
flexibility.
|
flexibility.
|
||||||
|
|
||||||
|
connections.<conn>.local<suffix>.cert<suffix>.file =
|
||||||
|
Absolute path to the certificate to load.
|
||||||
|
|
||||||
|
Absolute path to the certificate to load. Passed as-is to the daemon, so it
|
||||||
|
must be readable by it.
|
||||||
|
|
||||||
|
Configure either this or _handle_, but not both, in one section.
|
||||||
|
|
||||||
connections.<conn>.local<suffix>.cert<suffix>.handle =
|
connections.<conn>.local<suffix>.cert<suffix>.handle =
|
||||||
Hex-encoded CKA_ID of the certificate on a token.
|
Hex-encoded CKA_ID of the certificate on a token.
|
||||||
|
|
||||||
|
Hex-encoded CKA_ID of the certificate on a token.
|
||||||
|
|
||||||
|
Configure either this or _file_, but not both, in one section.
|
||||||
|
|
||||||
connections.<conn>.local<suffix>.cert<suffix>.slot =
|
connections.<conn>.local<suffix>.cert<suffix>.slot =
|
||||||
Optional slot number of the token that stores the certificate.
|
Optional slot number of the token that stores the certificate.
|
||||||
|
|
||||||
@@ -442,9 +454,21 @@ connections.<conn>.remote<suffix>.cert<suffix> =
|
|||||||
in _certs_ are transmitted as binary blobs, these sections offer more
|
in _certs_ are transmitted as binary blobs, these sections offer more
|
||||||
flexibility.
|
flexibility.
|
||||||
|
|
||||||
|
connections.<conn>.remote<suffix>.cert<suffix>.file =
|
||||||
|
Absolute path to the certificate to load.
|
||||||
|
|
||||||
|
Absolute path to the certificate to load. Passed as-is to the daemon, so it
|
||||||
|
must be readable by it.
|
||||||
|
|
||||||
|
Configure either this or _handle_, but not both, in one section.
|
||||||
|
|
||||||
connections.<conn>.remote<suffix>.cert<suffix>.handle =
|
connections.<conn>.remote<suffix>.cert<suffix>.handle =
|
||||||
Hex-encoded CKA_ID of the certificate on a token.
|
Hex-encoded CKA_ID of the certificate on a token.
|
||||||
|
|
||||||
|
Hex-encoded CKA_ID of the certificate on a token.
|
||||||
|
|
||||||
|
Configure either this or _file_, but not both, in one section.
|
||||||
|
|
||||||
connections.<conn>.remote<suffix>.cert<suffix>.slot =
|
connections.<conn>.remote<suffix>.cert<suffix>.slot =
|
||||||
Optional slot number of the token that stores the certificate.
|
Optional slot number of the token that stores the certificate.
|
||||||
|
|
||||||
@@ -465,9 +489,21 @@ connections.<conn>.remote<suffix>.cacert<suffix> =
|
|||||||
in _cacerts_ are transmitted as binary blobs, these sections offer more
|
in _cacerts_ are transmitted as binary blobs, these sections offer more
|
||||||
flexibility.
|
flexibility.
|
||||||
|
|
||||||
|
connections.<conn>.remote<suffix>.cacert<suffix>.file =
|
||||||
|
Absolute path to the certificate to load.
|
||||||
|
|
||||||
|
Absolute path to the certificate to load. Passed as-is to the daemon, so it
|
||||||
|
must be readable by it.
|
||||||
|
|
||||||
|
Configure either this or _handle_, but not both, in one section.
|
||||||
|
|
||||||
connections.<conn>.remote<suffix>.cacert<suffix>.handle =
|
connections.<conn>.remote<suffix>.cacert<suffix>.handle =
|
||||||
Hex-encoded CKA_ID of the CA certificate on a token.
|
Hex-encoded CKA_ID of the CA certificate on a token.
|
||||||
|
|
||||||
|
Hex-encoded CKA_ID of the CA certificate on a token.
|
||||||
|
|
||||||
|
Configure either this or _file_, but not both, in one section.
|
||||||
|
|
||||||
connections.<conn>.remote<suffix>.cacert<suffix>.slot =
|
connections.<conn>.remote<suffix>.cacert<suffix>.slot =
|
||||||
Optional slot number of the token that stores the CA certificate.
|
Optional slot number of the token that stores the CA certificate.
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user