michael@0: /* This Source Code Form is subject to the terms of the Mozilla Public michael@0: * License, v. 2.0. If a copy of the MPL was not distributed with this michael@0: * file, You can obtain one at http://mozilla.org/MPL/2.0/. */ michael@0: michael@0: /* michael@0: * Pretty-print some well-known BER or DER encoded data (e.g. certificates, michael@0: * keys, pkcs7) michael@0: */ michael@0: michael@0: #include "secutil.h" michael@0: michael@0: #if defined(__sun) && !defined(SVR4) michael@0: extern int fprintf(FILE *, char *, ...); michael@0: #endif michael@0: michael@0: #include "plgetopt.h" michael@0: michael@0: #include "pk11func.h" michael@0: #include "nspr.h" michael@0: #include "nss.h" michael@0: michael@0: static void Usage(char *progName) michael@0: { michael@0: fprintf(stderr, michael@0: "Usage: %s [-t type] [-a] [-i input] [-o output] [-w] [-u]\n", michael@0: progName); michael@0: fprintf(stderr, "Pretty prints a file containing ASN.1 data in DER or ascii format.\n"); michael@0: fprintf(stderr, "%-14s Specify input and display type: %s (sk),\n", michael@0: "-t type", SEC_CT_PRIVATE_KEY); michael@0: fprintf(stderr, "%-14s %s (pk), %s (c), %s (cr),\n", "", SEC_CT_PUBLIC_KEY, michael@0: SEC_CT_CERTIFICATE, SEC_CT_CERTIFICATE_REQUEST); michael@0: fprintf(stderr, "%-14s %s (ci), %s (p7), %s or %s (n).\n", "", SEC_CT_CERTIFICATE_ID, michael@0: SEC_CT_PKCS7, SEC_CT_CRL, SEC_CT_NAME); michael@0: fprintf(stderr, "%-14s (Use either the long type name or the shortcut.)\n", "", SEC_CT_CERTIFICATE_ID, michael@0: SEC_CT_PKCS7, SEC_CT_CRL, SEC_CT_NAME); michael@0: fprintf(stderr, "%-14s Input is in ascii encoded form (RFC1113)\n", michael@0: "-a"); michael@0: fprintf(stderr, "%-14s Define an input file to use (default is stdin)\n", michael@0: "-i input"); michael@0: fprintf(stderr, "%-14s Define an output file to use (default is stdout)\n", michael@0: "-o output"); michael@0: fprintf(stderr, "%-14s Don't wrap long output lines\n", michael@0: "-w"); michael@0: fprintf(stderr, "%-14s Use UTF-8 (default is to show non-ascii as .)\n", michael@0: "-u"); michael@0: exit(-1); michael@0: } michael@0: michael@0: int main(int argc, char **argv) michael@0: { michael@0: int rv, ascii; michael@0: char *progName; michael@0: FILE *outFile; michael@0: PRFileDesc *inFile; michael@0: SECItem der, data; michael@0: char *typeTag; michael@0: PLOptState *optstate; michael@0: PRBool wrap = PR_TRUE; michael@0: michael@0: progName = strrchr(argv[0], '/'); michael@0: progName = progName ? progName+1 : argv[0]; michael@0: michael@0: ascii = 0; michael@0: inFile = 0; michael@0: outFile = 0; michael@0: typeTag = 0; michael@0: optstate = PL_CreateOptState(argc, argv, "at:i:o:uw"); michael@0: while ( PL_GetNextOpt(optstate) == PL_OPT_OK ) { michael@0: switch (optstate->option) { michael@0: case '?': michael@0: Usage(progName); michael@0: break; michael@0: michael@0: case 'a': michael@0: ascii = 1; michael@0: break; michael@0: michael@0: case 'i': michael@0: inFile = PR_Open(optstate->value, PR_RDONLY, 0); michael@0: if (!inFile) { michael@0: fprintf(stderr, "%s: unable to open \"%s\" for reading\n", michael@0: progName, optstate->value); michael@0: return -1; michael@0: } michael@0: break; michael@0: michael@0: case 'o': michael@0: outFile = fopen(optstate->value, "w"); michael@0: if (!outFile) { michael@0: fprintf(stderr, "%s: unable to open \"%s\" for writing\n", michael@0: progName, optstate->value); michael@0: return -1; michael@0: } michael@0: break; michael@0: michael@0: case 't': michael@0: typeTag = strdup(optstate->value); michael@0: break; michael@0: michael@0: case 'u': michael@0: SECU_EnableUtf8Display(PR_TRUE); michael@0: break; michael@0: michael@0: case 'w': michael@0: wrap = PR_FALSE; michael@0: break; michael@0: } michael@0: } michael@0: PL_DestroyOptState(optstate); michael@0: if (!typeTag) Usage(progName); michael@0: michael@0: if (!inFile) inFile = PR_STDIN; michael@0: if (!outFile) outFile = stdout; michael@0: michael@0: PR_Init(PR_SYSTEM_THREAD, PR_PRIORITY_NORMAL, 1); michael@0: rv = NSS_NoDB_Init(NULL); michael@0: if (rv != SECSuccess) { michael@0: fprintf(stderr, "%s: NSS_NoDB_Init failed (%s)\n", michael@0: progName, SECU_Strerror(PORT_GetError())); michael@0: exit(1); michael@0: } michael@0: SECU_RegisterDynamicOids(); michael@0: michael@0: rv = SECU_ReadDERFromFile(&der, inFile, ascii, PR_FALSE); michael@0: if (rv != SECSuccess) { michael@0: fprintf(stderr, "%s: SECU_ReadDERFromFile failed\n", progName); michael@0: exit(1); michael@0: } michael@0: michael@0: /* Data is untyped, using the specified type */ michael@0: data.data = der.data; michael@0: data.len = der.len; michael@0: michael@0: SECU_EnableWrap(wrap); michael@0: michael@0: /* Pretty print it */ michael@0: if (PORT_Strcmp(typeTag, SEC_CT_CERTIFICATE) == 0 || michael@0: PORT_Strcmp(typeTag, "c") == 0) { michael@0: rv = SECU_PrintSignedData(outFile, &data, "Certificate", 0, michael@0: SECU_PrintCertificate); michael@0: } else if (PORT_Strcmp(typeTag, SEC_CT_CERTIFICATE_ID) == 0 || michael@0: PORT_Strcmp(typeTag, "ci") == 0) { michael@0: rv = SECU_PrintSignedContent(outFile, &data, 0, 0, michael@0: SECU_PrintDumpDerIssuerAndSerial); michael@0: } else if (PORT_Strcmp(typeTag, SEC_CT_CERTIFICATE_REQUEST) == 0 || michael@0: PORT_Strcmp(typeTag, "cr") == 0) { michael@0: rv = SECU_PrintSignedData(outFile, &data, "Certificate Request", 0, michael@0: SECU_PrintCertificateRequest); michael@0: } else if (PORT_Strcmp(typeTag, SEC_CT_CRL) == 0) { michael@0: rv = SECU_PrintSignedData (outFile, &data, "CRL", 0, SECU_PrintCrl); michael@0: #ifdef HAVE_EPV_TEMPLATE michael@0: } else if (PORT_Strcmp(typeTag, SEC_CT_PRIVATE_KEY) == 0 || michael@0: PORT_Strcmp(typeTag, "sk") == 0) { michael@0: rv = SECU_PrintPrivateKey(outFile, &data, "Private Key", 0); michael@0: #endif michael@0: } else if (PORT_Strcmp(typeTag, SEC_CT_PUBLIC_KEY) == 0 || michael@0: PORT_Strcmp (typeTag, "pk") == 0) { michael@0: rv = SECU_PrintSubjectPublicKeyInfo(outFile, &data, "Public Key", 0); michael@0: } else if (PORT_Strcmp(typeTag, SEC_CT_PKCS7) == 0 || michael@0: PORT_Strcmp (typeTag, "p7") == 0) { michael@0: rv = SECU_PrintPKCS7ContentInfo(outFile, &data, michael@0: "PKCS #7 Content Info", 0); michael@0: } else if (PORT_Strcmp(typeTag, SEC_CT_NAME) == 0 || michael@0: PORT_Strcmp (typeTag, "n") == 0) { michael@0: rv = SECU_PrintDERName(outFile, &data, "Name", 0); michael@0: } else { michael@0: fprintf(stderr, "%s: don't know how to print out '%s' files\n", michael@0: progName, typeTag); michael@0: SECU_PrintAny(outFile, &data, "File contains", 0); michael@0: return -1; michael@0: } michael@0: michael@0: if (inFile != PR_STDIN) michael@0: PR_Close(inFile); michael@0: PORT_Free(der.data); michael@0: if (rv) { michael@0: fprintf(stderr, "%s: problem converting data (%s)\n", michael@0: progName, SECU_Strerror(PORT_GetError())); michael@0: } michael@0: if (NSS_Shutdown() != SECSuccess) { michael@0: fprintf(stderr, "%s: NSS_Shutdown failed (%s)\n", michael@0: progName, SECU_Strerror(PORT_GetError())); michael@0: rv = SECFailure; michael@0: } michael@0: PR_Cleanup(); michael@0: return rv; michael@0: }