17c478bd9Sstevel@tonic-gate /*
27c478bd9Sstevel@tonic-gate * CDDL HEADER START
37c478bd9Sstevel@tonic-gate *
47c478bd9Sstevel@tonic-gate * The contents of this file are subject to the terms of the
599ebb4caSwyllys * Common Development and Distribution License (the "License").
699ebb4caSwyllys * You may not use this file except in compliance with the License.
77c478bd9Sstevel@tonic-gate *
87c478bd9Sstevel@tonic-gate * You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
97c478bd9Sstevel@tonic-gate * or http://www.opensolaris.org/os/licensing.
107c478bd9Sstevel@tonic-gate * See the License for the specific language governing permissions
117c478bd9Sstevel@tonic-gate * and limitations under the License.
127c478bd9Sstevel@tonic-gate *
137c478bd9Sstevel@tonic-gate * When distributing Covered Code, include this CDDL HEADER in each
147c478bd9Sstevel@tonic-gate * file and include the License file at usr/src/OPENSOLARIS.LICENSE.
157c478bd9Sstevel@tonic-gate * If applicable, add the following below this CDDL HEADER, with the
167c478bd9Sstevel@tonic-gate * fields enclosed by brackets "[]" replaced with your own identifying
177c478bd9Sstevel@tonic-gate * information: Portions Copyright [yyyy] [name of copyright owner]
187c478bd9Sstevel@tonic-gate *
197c478bd9Sstevel@tonic-gate * CDDL HEADER END
207c478bd9Sstevel@tonic-gate */
217c478bd9Sstevel@tonic-gate /*
22*2c9a247fSWyllys Ingersoll * Copyright (c) 2004, 2010, Oracle and/or its affiliates. All rights reserved.
237c478bd9Sstevel@tonic-gate */
247c478bd9Sstevel@tonic-gate
257c478bd9Sstevel@tonic-gate /*
267c478bd9Sstevel@tonic-gate * This file comprises the main driver for this tool.
277711facfSdinak * Upon parsing the command verbs from user input, it
287711facfSdinak * branches to the appropriate modules to perform the
297711facfSdinak * requested task.
307c478bd9Sstevel@tonic-gate */
317c478bd9Sstevel@tonic-gate
327c478bd9Sstevel@tonic-gate #include <stdio.h>
337c478bd9Sstevel@tonic-gate #include <string.h>
347c478bd9Sstevel@tonic-gate #include <ctype.h>
357c478bd9Sstevel@tonic-gate #include <malloc.h>
36d00756ccSwyllys #include <libintl.h>
377c478bd9Sstevel@tonic-gate #include <libgen.h>
387c478bd9Sstevel@tonic-gate #include <errno.h>
397c478bd9Sstevel@tonic-gate #include <cryptoutil.h>
407c478bd9Sstevel@tonic-gate #include <security/cryptoki.h>
417c478bd9Sstevel@tonic-gate #include "common.h"
427c478bd9Sstevel@tonic-gate
437c478bd9Sstevel@tonic-gate /*
447c478bd9Sstevel@tonic-gate * The verbcmd construct allows genericizing information about a verb so
457c478bd9Sstevel@tonic-gate * that it is easier to manipulate. Makes parsing code easier to read,
467c478bd9Sstevel@tonic-gate * fix, and extend with new verbs.
477c478bd9Sstevel@tonic-gate */
487c478bd9Sstevel@tonic-gate typedef struct verbcmd_s {
497c478bd9Sstevel@tonic-gate char *verb;
507c478bd9Sstevel@tonic-gate int (*action)(int, char *[]);
517711facfSdinak int mode;
52985be8f1Swyllys char *summary;
537711facfSdinak char *synopsis;
547c478bd9Sstevel@tonic-gate } verbcmd;
557c478bd9Sstevel@tonic-gate
567c478bd9Sstevel@tonic-gate /* External declarations for supported verb actions. */
577c478bd9Sstevel@tonic-gate extern int pk_setpin(int argc, char *argv[]);
587711facfSdinak extern int pk_list(int argc, char *argv[]);
597711facfSdinak extern int pk_delete(int argc, char *argv[]);
607711facfSdinak extern int pk_import(int argc, char *argv[]);
617711facfSdinak extern int pk_export(int argc, char *argv[]);
627711facfSdinak extern int pk_tokens(int argc, char *argv[]);
6399ebb4caSwyllys extern int pk_gencert(int argc, char *argv[]);
6499ebb4caSwyllys extern int pk_gencsr(int argc, char *argv[]);
6599ebb4caSwyllys extern int pk_download(int argc, char *argv[]);
6699ebb4caSwyllys extern int pk_genkey(int argc, char *argv[]);
67d00756ccSwyllys extern int pk_signcsr(int argc, char *argv[]);
6847e946e7SWyllys Ingersoll extern int pk_inittoken(int argc, char *argv[]);
69e65e5c2dSWyllys Ingersoll extern int pk_genkeypair(int argc, char *argv[]);
707711facfSdinak
717711facfSdinak /* Forward declarations for "built-in" verb actions. */
727711facfSdinak static int pk_help(int argc, char *argv[]);
737c478bd9Sstevel@tonic-gate
74d00756ccSwyllys #define TOKEN_IDX 0
75fa60c371Swyllys #define TOKEN_VERB "tokens"
76d00756ccSwyllys #define TOKEN_SUMM gettext("lists all visible PKCS#11 tokens")
77fa60c371Swyllys #define TOKEN_SYN "tokens"
78d00756ccSwyllys
79d00756ccSwyllys #define SETPIN_IDX 1
80fa60c371Swyllys #define SETPIN_VERB "setpin"
81d00756ccSwyllys #define SETPIN_SUMM gettext("changes user authentication passphrase "\
82d00756ccSwyllys "for keystore access")
83fa60c371Swyllys #define SETPIN_SYN \
84d00756ccSwyllys "setpin [ keystore=pkcs11 ]\n\t\t" \
8547e946e7SWyllys Ingersoll "[ token=token[:manuf[:serial]]]\n\t\t" \
8647e946e7SWyllys Ingersoll "[ usertype=so|user ]\n\t" \
8747e946e7SWyllys Ingersoll \
88d00756ccSwyllys "setpin keystore=nss\n\t\t" \
89d00756ccSwyllys "[ token=token ]\n\t\t" \
90d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
91fa60c371Swyllys "[ prefix=DBprefix ]\n\t"
92d00756ccSwyllys
93d00756ccSwyllys #define LIST_IDX 2
94fa60c371Swyllys #define LIST_VERB "list"
95d00756ccSwyllys #define LIST_SUMM gettext("lists a summary of objects in the keystore")
96fa60c371Swyllys #define LIST_SYN \
97d00756ccSwyllys "list [ token=token[:manuf[:serial]]]\n\t\t" \
98d00756ccSwyllys "[ objtype=private|public|both ]\n\t\t" \
99d00756ccSwyllys "[ label=label ]\n\t" \
100d00756ccSwyllys \
101d00756ccSwyllys "list objtype=cert[:[public | private | both ]]\n\t\t" \
102d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
103d00756ccSwyllys "[ keystore=pkcs11 ]\n\t\t" \
104d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
105d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
106d00756ccSwyllys "[ label=cert-label ]\n\t\t" \
107d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
108d00756ccSwyllys "[ criteria=valid|expired|both ]\n\t" \
109d00756ccSwyllys \
110d00756ccSwyllys "list objtype=key[:[public | private | both ]]\n\t\t" \
111d00756ccSwyllys "[ keystore=pkcs11 ]\n\t\t" \
112d00756ccSwyllys "[ label=key-label ]\n\t\t" \
113d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t" \
114d00756ccSwyllys \
115d00756ccSwyllys "list keystore=pkcs11 objtype=crl\n\t\t" \
116448b8615Swyllys "infile=crl-fn\n\t" \
117d00756ccSwyllys \
118d00756ccSwyllys "list keystore=nss objtype=cert\n\t\t" \
119d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
120d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
121d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
122d00756ccSwyllys "[ nickname=cert-nickname ]\n\t\t" \
123d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
124d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
125d00756ccSwyllys "[ prefix=DBprefix ]\n\t\t" \
126d00756ccSwyllys "[ criteria=valid|expired|both ]\n\t" \
127d00756ccSwyllys \
128d00756ccSwyllys "list keystore=nss objtype=key\n\t\t" \
129d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
130d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
131d00756ccSwyllys "[ prefix=DBprefix ]\n\t\t" \
132d00756ccSwyllys "[ nickname=key-nickname ]\n\t" \
133d00756ccSwyllys \
134d00756ccSwyllys "list keystore=file objtype=cert\n\t\t" \
135d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
136d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
137d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
138d00756ccSwyllys "[ infile=cert-fn ]\n\t\t" \
139d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
140d00756ccSwyllys "[ criteria=valid|expired|both ]\n\t" \
141d00756ccSwyllys \
142d00756ccSwyllys "list keystore=file objtype=key\n\t\t" \
143d00756ccSwyllys "[ infile=key-fn ]\n\t\t" \
144d00756ccSwyllys "[ dir=directory-path ]\n\t" \
145d00756ccSwyllys \
146d00756ccSwyllys "list keystore=file objtype=crl\n\t\t" \
147448b8615Swyllys "infile=crl-fn\n\t"
148d00756ccSwyllys
149d00756ccSwyllys #define DELETE_IDX 3
150fa60c371Swyllys #define DELETE_VERB "delete"
151d00756ccSwyllys #define DELETE_SUMM gettext("deletes objects in the keystore")
152fa60c371Swyllys #define DELETE_SYN \
153d00756ccSwyllys "delete [ token=token[:manuf[:serial]]]\n\t\t" \
154d00756ccSwyllys "[ objtype=private|public|both ]\n\t\t" \
155d00756ccSwyllys "[ label=object-label ]\n\t" \
156d00756ccSwyllys \
157d00756ccSwyllys "delete keystore=nss objtype=cert\n\t\t" \
158d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
159d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
160d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
161d00756ccSwyllys "[ label=cert-label ]\n\t\t" \
162d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
163d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
164d00756ccSwyllys "[ prefix=DBprefix ]\n\t\t" \
165d00756ccSwyllys "[ criteria=valid|expired|both ]\n\t" \
166d00756ccSwyllys \
167d00756ccSwyllys "delete keystore=nss objtype=key\n\t\t" \
168d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
169d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
170d00756ccSwyllys "[ prefix=DBprefix ]\n\t\t" \
171d00756ccSwyllys "[ nickname=key-nickname ]\n\t\t" \
172d00756ccSwyllys \
173d00756ccSwyllys "delete keystore=nss objtype=crl\n\t\t" \
174d00756ccSwyllys "[ nickname=issuer-nickname ]\n\t\t" \
175d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
176d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
177d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
178d00756ccSwyllys "[ prefix=DBprefix ]\n\t" \
179d00756ccSwyllys \
180d00756ccSwyllys "delete keystore=pkcs11 " \
181d00756ccSwyllys "objtype=cert[:[public | private | both]]\n\t\t" \
182d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
183d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
184d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
185d00756ccSwyllys "[ label=cert-label ]\n\t\t" \
186d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
187d00756ccSwyllys "[ criteria=valid|expired|both ]\n\t" \
188d00756ccSwyllys \
189d00756ccSwyllys "delete keystore=pkcs11 " \
190d00756ccSwyllys "objtype=key[:[public | private | both]]\n\t\t" \
191d00756ccSwyllys "[ label=key-label ]\n\t\t" \
192d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t" \
193d00756ccSwyllys \
194d00756ccSwyllys "delete keystore=pkcs11 objtype=crl\n\t\t" \
195448b8615Swyllys "infile=crl-fn\n\t" \
196d00756ccSwyllys \
197d00756ccSwyllys "delete keystore=file objtype=cert\n\t\t" \
198d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
199d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
200d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
201d00756ccSwyllys "[ infile=cert-fn ]\n\t\t" \
202d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
203d00756ccSwyllys "[ criteria=valid|expired|both ]\n\t" \
204d00756ccSwyllys \
205d00756ccSwyllys "delete keystore=file objtype=key\n\t\t" \
206d00756ccSwyllys "[ infile=key-fn ]\n\t\t" \
207d00756ccSwyllys "[ dir=directory-path ]\n\t" \
208d00756ccSwyllys \
209d00756ccSwyllys "delete keystore=file objtype=crl\n\t\t" \
210448b8615Swyllys "infile=crl-fn\n\t"
211d00756ccSwyllys
212d00756ccSwyllys #define IMPORT_IDX 4
213fa60c371Swyllys #define IMPORT_VERB "import"
214d00756ccSwyllys #define IMPORT_SUMM gettext("imports objects from an external source")
215fa60c371Swyllys #define IMPORT_SYN \
216d00756ccSwyllys "import [token=token[:manuf[:serial]]]\n\t\t" \
217d00756ccSwyllys "infile=input-fn\n\t" \
218d00756ccSwyllys \
219d00756ccSwyllys "import keystore=nss objtype=cert\n\t\t" \
220d00756ccSwyllys "infile=input-fn\n\t\t" \
221d00756ccSwyllys "label=cert-label\n\t\t" \
222d00756ccSwyllys "[ trust=trust-value ]\n\t\t" \
223d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
224d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
225d00756ccSwyllys "[ prefix=DBprefix ]\n\t" \
226d00756ccSwyllys \
227d00756ccSwyllys "import keystore=nss objtype=crl\n\t\t" \
228d00756ccSwyllys "infile=input-fn\n\t\t" \
229d00756ccSwyllys "[ verifycrl=y|n ]\n\t\t" \
230d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
231d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
232d00756ccSwyllys "[ prefix=DBprefix ]\n\t" \
233d00756ccSwyllys \
234d00756ccSwyllys "import keystore=pkcs11\n\t\t" \
235d00756ccSwyllys "infile=input-fn\n\t\t" \
236d00756ccSwyllys "label=label\n\t\t" \
237d00756ccSwyllys "[ objtype=cert|key ]\n\t\t" \
238d00756ccSwyllys "[ keytype=aes|arcfour|des|3des|generic ]\n\t\t" \
239d00756ccSwyllys "[ sensitive=y|n ]\n\t\t" \
240d00756ccSwyllys "[ extractable=y|n ]\n\t\t" \
241d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t" \
242d00756ccSwyllys \
243d00756ccSwyllys "import keystore=pkcs11 objtype=crl\n\t\t" \
244d00756ccSwyllys "infile=input-crl-fn\n\t\t" \
245d00756ccSwyllys "outcrl=output-crl-fn\n\t\t" \
246448b8615Swyllys "outformat=pem|der\n\t" \
247d00756ccSwyllys \
248d00756ccSwyllys "import keystore=file\n\t\t" \
249d00756ccSwyllys "infile=input-fn\n\t\t" \
250d00756ccSwyllys "outkey=output-key-fn\n\t\t" \
251d00756ccSwyllys "outcert=output-cert-fn\n\t\t" \
252d00756ccSwyllys "[ outformat=pem|der|pkcs12 ]\n\t" \
253d00756ccSwyllys \
254d00756ccSwyllys "import keystore=file objtype=crl\n\t\t" \
255d00756ccSwyllys "infile=input-crl-fn\n\t\t" \
256d00756ccSwyllys "outcrl=output-crl-fn\n\t\t" \
257448b8615Swyllys "outformat=pem|der\n\t"
258d00756ccSwyllys
259d00756ccSwyllys #define EXPORT_IDX 5
260fa60c371Swyllys #define EXPORT_VERB "export"
261d00756ccSwyllys #define EXPORT_SUMM gettext("exports objects from the keystore to a file")
262fa60c371Swyllys #define EXPORT_SYN \
263d00756ccSwyllys "export [token=token[:manuf[:serial]]]\n\t\t" \
264d00756ccSwyllys "outfile=output-fn\n\t" \
265d00756ccSwyllys \
266d00756ccSwyllys "export keystore=nss\n\t\t" \
267d00756ccSwyllys "outfile=output-fn\n\t\t" \
268d00756ccSwyllys "[ objtype=cert|key ]\n\t\t" \
269d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
270d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
271d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
272d00756ccSwyllys "[ nickname=cert-nickname ]\n\t\t" \
273d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
274d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
275d00756ccSwyllys "[ prefix=DBPrefix ]\n\t\t" \
276d00756ccSwyllys "[ outformat=pem|der|pkcs12 ]\n\t" \
277d00756ccSwyllys \
278d00756ccSwyllys "export keystore=pkcs11\n\t\t" \
279d00756ccSwyllys "outfile=output-fn\n\t\t" \
280d00756ccSwyllys "[ objtype=cert|key ]\n\t\t" \
281d00756ccSwyllys "[ label=label ]\n\t\t" \
282d00756ccSwyllys "[ subject=subject-DN ]\n\t\t" \
283d00756ccSwyllys "[ issuer=issuer-DN ]\n\t\t" \
284d00756ccSwyllys "[ serial=serial number ]\n\t\t" \
285d00756ccSwyllys "[ outformat=pem|der|pkcs12|raw ]\n\t\t" \
286d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t" \
287d00756ccSwyllys \
288d00756ccSwyllys "export keystore=file\n\t\t" \
289d00756ccSwyllys "certfile=cert-input-fn\n\t\t" \
290d00756ccSwyllys "keyfile=key-input-fn\n\t\t" \
291448b8615Swyllys "outfile=output-pkcs12-fn\n\t"
292d00756ccSwyllys
293d00756ccSwyllys #define GENCERT_IDX 6
294fa60c371Swyllys #define GENCERT_VERB "gencert"
295d00756ccSwyllys #define GENCERT_SUMM gettext("creates a self-signed X.509v3 certificate")
296fa60c371Swyllys #define GENCERT_SYN \
297e65e5c2dSWyllys Ingersoll "gencert listcurves\n\t" \
298e65e5c2dSWyllys Ingersoll \
299592106a2SWyllys Ingersoll "gencert keystore=nss\n\t\t" \
300d00756ccSwyllys "label=cert-nickname\n\t\t" \
301e65e5c2dSWyllys Ingersoll "serial=serial number hex string\n\t\t" \
302592106a2SWyllys Ingersoll "[ -i ] | [subject=subject-DN]\n\t\t" \
303d00756ccSwyllys "[ altname=[critical:]SubjectAltName ]\n\t\t" \
304d00756ccSwyllys "[ keyusage=[critical:]usage,usage,...]\n\t\t" \
305d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
306d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
307d00756ccSwyllys "[ prefix=DBprefix ]\n\t\t" \
308e65e5c2dSWyllys Ingersoll "[ keytype=rsa | ec [curve=ECC Curve Name] " \
309e65e5c2dSWyllys Ingersoll "[hash=md5 | sha1 | sha256 | sha384 | sha512]]\n\t\t" \
310e65e5c2dSWyllys Ingersoll "[ keytype=dsa [hash=sha1]]\n\t\t" \
311d00756ccSwyllys "[ keylen=key-size ]\n\t\t" \
312d00756ccSwyllys "[ trust=trust-value ]\n\t\t" \
313d00756ccSwyllys "[ eku=[critical:]EKU name,...]\n\t\t" \
314d00756ccSwyllys "[ lifetime=number-hour|number-day|number-year ]\n\t" \
315d00756ccSwyllys \
316592106a2SWyllys Ingersoll "gencert [ keystore=pkcs11 ]\n\t\t" \
317d00756ccSwyllys "label=key/cert-label\n\t\t" \
318d00756ccSwyllys "serial=serial number hex string\n\t\t" \
319592106a2SWyllys Ingersoll "[ -i ] | [subject=subject-DN]\n\t\t" \
320d00756ccSwyllys "[ altname=[critical:]SubjectAltName ]\n\t\t" \
321d00756ccSwyllys "[ keyusage=[critical:]usage,usage,...]\n\t\t" \
322d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
323e65e5c2dSWyllys Ingersoll "[ keytype=rsa | ec [curve=ECC Curve Name] " \
324e65e5c2dSWyllys Ingersoll "[hash=md5 | sha1 | sha256 | sha384 | sha512]]\n\t\t" \
325e65e5c2dSWyllys Ingersoll "[ keytype=dsa [hash=sha1 | sha256 ]]\n\t\t" \
326d00756ccSwyllys "[ keylen=key-size ]\n\t\t" \
327d00756ccSwyllys "[ eku=[critical:]EKU name,...]\n\t\t" \
328d00756ccSwyllys "[ lifetime=number-hour|number-day|number-year ]\n\t" \
329d00756ccSwyllys \
330592106a2SWyllys Ingersoll "gencert keystore=file\n\t\t" \
331d00756ccSwyllys "outcert=cert_filename\n\t\t" \
332d00756ccSwyllys "outkey=key_filename\n\t\t" \
333d00756ccSwyllys "serial=serial number hex string\n\t\t" \
334592106a2SWyllys Ingersoll "[ -i ] | [subject=subject-DN]\n\t\t" \
335d00756ccSwyllys "[ altname=[critical:]SubjectAltName ]\n\t\t" \
336d00756ccSwyllys "[ keyusage=[critical:]usage,usage,...]\n\t\t" \
337d00756ccSwyllys "[ format=der|pem ]\n\t\t" \
338e65e5c2dSWyllys Ingersoll "[ keytype=rsa [hash=md5 | sha1 | sha256 | sha384 | sha512]]\n\t\t" \
339e65e5c2dSWyllys Ingersoll "[ keytype=dsa [hash=sha1 | sha256 ]]\n\t\t" \
340d00756ccSwyllys "[ keylen=key-size ]\n\t\t" \
341d00756ccSwyllys "[ eku=[critical:]EKU name,...]\n\t\t" \
342fa60c371Swyllys "[ lifetime=number-hour|number-day|number-year ]\n\t"
343d00756ccSwyllys
344d00756ccSwyllys #define GENCSR_IDX 7
345fa60c371Swyllys #define GENCSR_VERB "gencsr"
346d00756ccSwyllys #define GENCSR_SUMM gettext("creates a PKCS#10 certificate signing " \
347d00756ccSwyllys "request file")
348d00756ccSwyllys
349fa60c371Swyllys #define GENCSR_SYN \
350e65e5c2dSWyllys Ingersoll "gencsr listcurves\n\t" \
351e65e5c2dSWyllys Ingersoll \
352592106a2SWyllys Ingersoll "gencsr keystore=nss \n\t\t" \
353d00756ccSwyllys "nickname=cert-nickname\n\t\t" \
354d00756ccSwyllys "outcsr=csr-fn\n\t\t" \
355592106a2SWyllys Ingersoll "[ -i ] | [subject=subject-DN]\n\t\t" \
356d00756ccSwyllys "[ altname=[critical:]SubjectAltName ]\n\t\t" \
357d00756ccSwyllys "[ keyusage=[critical:]usage,usage,...]\n\t\t" \
358d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
359d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
360d00756ccSwyllys "[ prefix=DBprefix ]\n\t\t" \
361e65e5c2dSWyllys Ingersoll "[ keytype=rsa | ec [curve=ECC Curve Name] " \
362e65e5c2dSWyllys Ingersoll "[hash=md5 | sha1 | sha256 | sha384 | sha512]]\n\t\t" \
363e65e5c2dSWyllys Ingersoll "[ keytype=dsa [hash=sha1]]\n\t\t" \
364d00756ccSwyllys "[ keylen=key-size ]\n\t\t" \
365d00756ccSwyllys "[ eku=[critical:]EKU name,...]\n\t\t" \
366d00756ccSwyllys "[ format=pem|der ]\n\t" \
367d00756ccSwyllys \
368592106a2SWyllys Ingersoll "gencsr [ keystore=pkcs11 ]\n\t\t" \
369d00756ccSwyllys "label=key-label\n\t\t" \
370d00756ccSwyllys "outcsr=csr-fn\n\t\t" \
371592106a2SWyllys Ingersoll "[ -i ] | [subject=subject-DN]\n\t\t" \
372d00756ccSwyllys "[ altname=[critical:]SubjectAltName ]\n\t\t" \
373d00756ccSwyllys "[ keyusage=[critical:]usage,usage,...]\n\t\t" \
374d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
375e65e5c2dSWyllys Ingersoll "[ keytype=rsa | ec [curve=ECC Curve Name] " \
376e65e5c2dSWyllys Ingersoll "[hash=md5 | sha1 | sha256 | sha384 | sha512]]\n\t\t" \
377e65e5c2dSWyllys Ingersoll "[ keytype=dsa [hash=sha1 | sha256 ]]\n\t\t" \
378d00756ccSwyllys "[ keylen=key-size ]\n\t\t" \
379d00756ccSwyllys "[ eku=[critical:]EKU name,...]\n\t\t" \
380d00756ccSwyllys "[ format=pem|der ]]\n\t" \
381d00756ccSwyllys \
382592106a2SWyllys Ingersoll "gencsr keystore=file\n\t\t" \
383d00756ccSwyllys "outcsr=csr-fn\n\t\t" \
384d00756ccSwyllys "outkey=key-fn\n\t\t" \
385592106a2SWyllys Ingersoll "[ -i ] | [subject=subject-DN]\n\t\t" \
386d00756ccSwyllys "[ altname=[critical:]SubjectAltName ]\n\t\t" \
387d00756ccSwyllys "[ keyusage=[critical:]usage,usage,...]\n\t\t" \
388e65e5c2dSWyllys Ingersoll "[ keytype=rsa [hash=md5 | sha1 | sha256 | sha384 | sha512]]\n\t\t" \
389e65e5c2dSWyllys Ingersoll "[ keytype=dsa [hash=sha1 | sha256 ]]\n\t\t" \
390d00756ccSwyllys "[ keylen=key-size ]\n\t\t" \
391d00756ccSwyllys "[ eku=[critical:]EKU name,...]\n\t\t" \
392fa60c371Swyllys "[ format=pem|der ]\n\t"
393d00756ccSwyllys
394d00756ccSwyllys #define DOWNLOAD_IDX 8
395fa60c371Swyllys #define DOWNLOAD_VERB "download"
396d00756ccSwyllys #define DOWNLOAD_SUMM gettext("downloads a CRL or certificate file " \
397d00756ccSwyllys "from an external source")
398fa60c371Swyllys #define DOWNLOAD_SYN \
399d00756ccSwyllys "download url=url_str\n\t\t" \
400d00756ccSwyllys "[ objtype=crl|cert ]\n\t\t" \
401d00756ccSwyllys "[ http_proxy=proxy_str ]\n\t\t" \
402fa60c371Swyllys "[ outfile = outfile ]\n\t"
403d00756ccSwyllys
404d00756ccSwyllys #define GENKEY_IDX 9
405fa60c371Swyllys #define GENKEY_VERB "genkey"
406d00756ccSwyllys #define GENKEY_SUMM gettext("creates a symmetric key in the keystore")
407fa60c371Swyllys #define GENKEY_SYN \
408d00756ccSwyllys "genkey [ keystore=pkcs11 ]\n\t\t" \
409d00756ccSwyllys "label=key-label\n\t\t" \
410d00756ccSwyllys "[ keytype=aes|arcfour|des|3des|generic ]\n\t\t" \
411d00756ccSwyllys "[ keylen=key-size (AES, ARCFOUR or GENERIC only)]\n\t\t" \
412d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
413d00756ccSwyllys "[ sensitive=y|n ]\n\t\t" \
414d00756ccSwyllys "[ extractable=y|n ]\n\t\t" \
415d00756ccSwyllys "[ print=y|n ]\n\t" \
416d00756ccSwyllys \
417d00756ccSwyllys "genkey keystore=nss\n\t\t" \
418d00756ccSwyllys "label=key-label\n\t\t" \
419d00756ccSwyllys "[ keytype=aes|arcfour|des|3des|generic ]\n\t\t" \
420d00756ccSwyllys "[ keylen=key-size (AES, ARCFOUR or GENERIC only)]\n\t\t" \
421d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
422d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
423d00756ccSwyllys "[ prefix=DBprefix ]\n\t" \
424d00756ccSwyllys \
425d00756ccSwyllys "genkey keystore=file\n\t\t" \
426d00756ccSwyllys "outkey=key-fn\n\t\t" \
427d00756ccSwyllys "[ keytype=aes|arcfour|des|3des|generic ]\n\t\t" \
428d00756ccSwyllys "[ keylen=key-size (AES, ARCFOUR or GENERIC only)]\n\t\t" \
429fa60c371Swyllys "[ print=y|n ]\n\t"
430d00756ccSwyllys
431d00756ccSwyllys #define SIGNCSR_IDX 10
432fa60c371Swyllys #define SIGNCSR_VERB "signcsr"
433d00756ccSwyllys #define SIGNCSR_SUMM gettext("Sign a PKCS#10 Certificate Signing Request")
434fa60c371Swyllys #define SIGNCSR_SYN \
435d00756ccSwyllys "signcsr keystore=pkcs11\n\t\t" \
436d00756ccSwyllys "signkey=label (label of signing key)\n\t\t" \
437d00756ccSwyllys "csr=CSR filename\n\t\t" \
438d00756ccSwyllys "serial=serial number hex string\n\t\t" \
439d00756ccSwyllys "outcert=filename for final certificate\n\t\t" \
440d00756ccSwyllys "issuer=issuer-DN\n\t\t" \
441*2c9a247fSWyllys Ingersoll "[ store=y|n ] (store the new cert on the token, default=n)\n\t\t" \
442d00756ccSwyllys "[ outlabel=certificate label ]\n\t\t" \
443d00756ccSwyllys "[ format=pem|der ] (output format)\n\t\t" \
444d00756ccSwyllys "[ subject=subject-DN ] (new subject name)\n\t\t" \
445d00756ccSwyllys "[ altname=subjectAltName ]\n\t\t" \
446d00756ccSwyllys "[ keyusage=[critical:]usage,...]\n\t\t" \
447d00756ccSwyllys "[ eku=[critical:]EKU Name,...]\n\t\t" \
448d00756ccSwyllys "[ lifetime=number-hour|number-day|number-year ]\n\t\t" \
449d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t" \
450d00756ccSwyllys \
451d00756ccSwyllys "signcsr keystore=file\n\t\t" \
452d00756ccSwyllys "signkey=filename\n\t\t" \
453d00756ccSwyllys "csr=CSR filename\n\t\t" \
454d00756ccSwyllys "serial=serial number hex string\n\t\t" \
455d00756ccSwyllys "outcert=filename for final certificate\n\t\t" \
456d00756ccSwyllys "issuer=issuer-DN\n\t\t" \
457d00756ccSwyllys "[ format=pem|der ] (output format)\n\t\t" \
458d00756ccSwyllys "[ subject=subject-DN ] (new subject name)\n\t\t" \
459d00756ccSwyllys "[ altname=subjectAltName ]\n\t\t" \
460d00756ccSwyllys "[ keyusage=[critical:]usage,...]\n\t\t" \
461d00756ccSwyllys "[ lifetime=number-hour|number-day|number-year ]\n\t\t" \
462d00756ccSwyllys "[ eku=[critical:]EKU Name,...]\n\t" \
463d00756ccSwyllys \
464d00756ccSwyllys "signcsr keystore=nss\n\t\t" \
465d00756ccSwyllys "signkey=label (label of signing key)\n\t\t" \
466d00756ccSwyllys "csr=CSR filename\n\t\t" \
467d00756ccSwyllys "serial=serial number hex string\n\t\t" \
468d00756ccSwyllys "outcert=filename for final certificate\n\t\t" \
469d00756ccSwyllys "issuer=issuer-DN\n\t\t" \
470d00756ccSwyllys "[ store=y|n ] (store the new cert in NSS DB, default=n)\n\t\t" \
471d00756ccSwyllys "[ outlabel=certificate label ]\n\t\t" \
472d00756ccSwyllys "[ format=pem|der ] (output format)\n\t\t" \
473d00756ccSwyllys "[ subject=subject-DN ] (new subject name)\n\t\t" \
474d00756ccSwyllys "[ altname=subjectAltName ]\n\t\t" \
475d00756ccSwyllys "[ keyusage=[critical:]usage,...]\n\t\t" \
476d00756ccSwyllys "[ eku=[critical:]EKU Name,...]\n\t\t" \
477d00756ccSwyllys "[ lifetime=number-hour|number-day|number-year ]\n\t\t" \
478d00756ccSwyllys "[ token=token[:manuf[:serial]]]\n\t\t" \
479d00756ccSwyllys "[ dir=directory-path ]\n\t\t" \
480fa60c371Swyllys "[ prefix=DBprefix ]\n\t"
481d00756ccSwyllys
48247e946e7SWyllys Ingersoll #define INITTOKEN_IDX 11
48347e946e7SWyllys Ingersoll #define INITTOKEN_VERB "inittoken"
48447e946e7SWyllys Ingersoll #define INITTOKEN_SUMM gettext("Initialize a PKCS11 token")
48547e946e7SWyllys Ingersoll #define INITTOKEN_SYN \
48647e946e7SWyllys Ingersoll "inittoken \n\t\t" \
48747e946e7SWyllys Ingersoll "[ currlabel=token[:manuf[:serial]]]\n\t\t" \
48847e946e7SWyllys Ingersoll "[ newlabel=new token label ]\n\t"
48947e946e7SWyllys Ingersoll
490e65e5c2dSWyllys Ingersoll #define GENKEYPAIR_IDX 12
491e65e5c2dSWyllys Ingersoll #define GENKEYPAIR_VERB "genkeypair"
492e65e5c2dSWyllys Ingersoll #define GENKEYPAIR_SUMM gettext("creates an asymmetric keypair")
493e65e5c2dSWyllys Ingersoll #define GENKEYPAIR_SYN \
494e65e5c2dSWyllys Ingersoll "genkeypair listcurves\n\t" \
495e65e5c2dSWyllys Ingersoll \
496e65e5c2dSWyllys Ingersoll "genkeypair keystore=nss\n\t\t" \
497e65e5c2dSWyllys Ingersoll "label=key-nickname\n\t\t" \
498e65e5c2dSWyllys Ingersoll "[ token=token[:manuf[:serial]]]\n\t\t" \
499e65e5c2dSWyllys Ingersoll "[ dir=directory-path ]\n\t\t" \
500e65e5c2dSWyllys Ingersoll "[ prefix=DBprefix ]\n\t\t" \
501e65e5c2dSWyllys Ingersoll "[ keytype=rsa | dsa | ec [curve=ECC Curve Name]]\n\t\t" \
502e65e5c2dSWyllys Ingersoll "[ keylen=key-size ]\n\t" \
503e65e5c2dSWyllys Ingersoll \
504e65e5c2dSWyllys Ingersoll "genkeypair [ keystore=pkcs11 ]\n\t\t" \
505e65e5c2dSWyllys Ingersoll "label=key-label\n\t\t" \
506e65e5c2dSWyllys Ingersoll "[ token=token[:manuf[:serial]]]\n\t\t" \
507e65e5c2dSWyllys Ingersoll "[ keytype=rsa | dsa | ec [curve=ECC Curve Name]]\n\t\t" \
508e65e5c2dSWyllys Ingersoll "[ keylen=key-size ]\n\t" \
509e65e5c2dSWyllys Ingersoll \
510e65e5c2dSWyllys Ingersoll "genkeypair keystore=file\n\t\t" \
511e65e5c2dSWyllys Ingersoll "outkey=key_filename\n\t\t" \
512e65e5c2dSWyllys Ingersoll "[ format=der|pem ]\n\t\t" \
513e65e5c2dSWyllys Ingersoll "[ keytype=rsa|dsa ]\n\t\t" \
514e65e5c2dSWyllys Ingersoll "[ keylen=key-size ]\n\t"
515e65e5c2dSWyllys Ingersoll
516e65e5c2dSWyllys Ingersoll #define HELP_IDX 13
517fa60c371Swyllys #define HELP_VERB "help"
518d00756ccSwyllys #define HELP_SUMM gettext("displays help message")
519fa60c371Swyllys #define HELP_SYN "help\t(help and usage)"
520d00756ccSwyllys
5217c478bd9Sstevel@tonic-gate /* Command structure for verbs and their actions. Do NOT i18n/l10n. */
5227c478bd9Sstevel@tonic-gate static verbcmd cmds[] = {
523d00756ccSwyllys { NULL, pk_tokens, 0, NULL, NULL },
524d00756ccSwyllys { NULL, pk_setpin, 0, NULL, NULL },
525d00756ccSwyllys { NULL, pk_list, 0, NULL, NULL },
526d00756ccSwyllys { NULL, pk_delete, 0, NULL, NULL },
527d00756ccSwyllys { NULL, pk_import, 0, NULL, NULL },
528d00756ccSwyllys { NULL, pk_export, 0, NULL, NULL },
529d00756ccSwyllys { NULL, pk_gencert, 0, NULL, NULL },
530d00756ccSwyllys { NULL, pk_gencsr, 0, NULL, NULL },
531d00756ccSwyllys { NULL, pk_download, 0, NULL, NULL },
532d00756ccSwyllys { NULL, pk_genkey, 0, NULL, NULL },
533d00756ccSwyllys { NULL, pk_signcsr, 0, NULL, NULL },
53447e946e7SWyllys Ingersoll { NULL, pk_inittoken, 0, NULL, NULL },
535e65e5c2dSWyllys Ingersoll { NULL, pk_genkeypair, 0, NULL, NULL },
536d00756ccSwyllys { NULL, pk_help, 0, NULL, NULL }
5377c478bd9Sstevel@tonic-gate };
538985be8f1Swyllys
5397c478bd9Sstevel@tonic-gate static int num_cmds = sizeof (cmds) / sizeof (verbcmd);
5407c478bd9Sstevel@tonic-gate
5417c478bd9Sstevel@tonic-gate static char *prog;
54299ebb4caSwyllys static void usage(int);
5437c478bd9Sstevel@tonic-gate
544d00756ccSwyllys static void
init_command_list()545d00756ccSwyllys init_command_list()
546d00756ccSwyllys {
547d00756ccSwyllys cmds[TOKEN_IDX].verb = TOKEN_VERB;
548d00756ccSwyllys cmds[TOKEN_IDX].summary = TOKEN_SUMM;
549d00756ccSwyllys cmds[TOKEN_IDX].synopsis = TOKEN_SYN;
550d00756ccSwyllys
551d00756ccSwyllys cmds[SETPIN_IDX].verb = SETPIN_VERB;
552d00756ccSwyllys cmds[SETPIN_IDX].summary = SETPIN_SUMM;
553d00756ccSwyllys cmds[SETPIN_IDX].synopsis = SETPIN_SYN;
554d00756ccSwyllys
555d00756ccSwyllys cmds[LIST_IDX].verb = LIST_VERB;
556d00756ccSwyllys cmds[LIST_IDX].summary = LIST_SUMM;
557d00756ccSwyllys cmds[LIST_IDX].synopsis = LIST_SYN;
558d00756ccSwyllys
559d00756ccSwyllys cmds[DELETE_IDX].verb = DELETE_VERB;
560d00756ccSwyllys cmds[DELETE_IDX].summary = DELETE_SUMM;
561d00756ccSwyllys cmds[DELETE_IDX].synopsis = DELETE_SYN;
562d00756ccSwyllys
563d00756ccSwyllys cmds[IMPORT_IDX].verb = IMPORT_VERB;
564d00756ccSwyllys cmds[IMPORT_IDX].summary = IMPORT_SUMM;
565d00756ccSwyllys cmds[IMPORT_IDX].synopsis = IMPORT_SYN;
566d00756ccSwyllys
567d00756ccSwyllys cmds[EXPORT_IDX].verb = EXPORT_VERB;
568d00756ccSwyllys cmds[EXPORT_IDX].summary = EXPORT_SUMM;
569d00756ccSwyllys cmds[EXPORT_IDX].synopsis = EXPORT_SYN;
570d00756ccSwyllys
571d00756ccSwyllys cmds[GENCERT_IDX].verb = GENCERT_VERB;
572d00756ccSwyllys cmds[GENCERT_IDX].summary = GENCERT_SUMM;
573d00756ccSwyllys cmds[GENCERT_IDX].synopsis = GENCERT_SYN;
574d00756ccSwyllys
575d00756ccSwyllys cmds[GENCSR_IDX].verb = GENCSR_VERB;
576d00756ccSwyllys cmds[GENCSR_IDX].summary = GENCSR_SUMM;
577d00756ccSwyllys cmds[GENCSR_IDX].synopsis = GENCSR_SYN;
578d00756ccSwyllys
579d00756ccSwyllys cmds[DOWNLOAD_IDX].verb = DOWNLOAD_VERB;
580d00756ccSwyllys cmds[DOWNLOAD_IDX].summary = DOWNLOAD_SUMM;
581d00756ccSwyllys cmds[DOWNLOAD_IDX].synopsis = DOWNLOAD_SYN;
582d00756ccSwyllys
583d00756ccSwyllys cmds[GENKEY_IDX].verb = GENKEY_VERB;
584d00756ccSwyllys cmds[GENKEY_IDX].summary = GENKEY_SUMM;
585d00756ccSwyllys cmds[GENKEY_IDX].synopsis = GENKEY_SYN;
586d00756ccSwyllys
587d00756ccSwyllys cmds[SIGNCSR_IDX].verb = SIGNCSR_VERB;
588d00756ccSwyllys cmds[SIGNCSR_IDX].summary = SIGNCSR_SUMM;
589d00756ccSwyllys cmds[SIGNCSR_IDX].synopsis = SIGNCSR_SYN;
590d00756ccSwyllys
59147e946e7SWyllys Ingersoll cmds[INITTOKEN_IDX].verb = INITTOKEN_VERB;
59247e946e7SWyllys Ingersoll cmds[INITTOKEN_IDX].summary = INITTOKEN_SUMM;
59347e946e7SWyllys Ingersoll cmds[INITTOKEN_IDX].synopsis = INITTOKEN_SYN;
59447e946e7SWyllys Ingersoll
595e65e5c2dSWyllys Ingersoll cmds[GENKEYPAIR_IDX].verb = GENKEYPAIR_VERB;
596e65e5c2dSWyllys Ingersoll cmds[GENKEYPAIR_IDX].summary = GENKEYPAIR_SUMM;
597e65e5c2dSWyllys Ingersoll cmds[GENKEYPAIR_IDX].synopsis = GENKEYPAIR_SYN;
598e65e5c2dSWyllys Ingersoll
599d00756ccSwyllys cmds[HELP_IDX].verb = HELP_VERB;
600d00756ccSwyllys cmds[HELP_IDX].summary = HELP_SUMM;
601d00756ccSwyllys cmds[HELP_IDX].synopsis = HELP_SYN;
602d00756ccSwyllys }
603d00756ccSwyllys
6047c478bd9Sstevel@tonic-gate /*
6057c478bd9Sstevel@tonic-gate * Usage information. This function must be updated when new verbs or
6067c478bd9Sstevel@tonic-gate * options are added.
6077c478bd9Sstevel@tonic-gate */
6087c478bd9Sstevel@tonic-gate static void
usage(int idx)60999ebb4caSwyllys usage(int idx)
6107c478bd9Sstevel@tonic-gate {
6117711facfSdinak int i;
6127711facfSdinak
6137711facfSdinak /* Display this block only in command-line mode. */
6147711facfSdinak (void) fprintf(stdout, gettext("Usage:\n"));
615985be8f1Swyllys (void) fprintf(stdout, gettext(" %s -?\t(help and usage)\n"),
616985be8f1Swyllys prog);
617985be8f1Swyllys (void) fprintf(stdout, gettext(" %s -f option_file\n"), prog);
618985be8f1Swyllys (void) fprintf(stdout, gettext(" %s subcommand [options...]\n"),
619985be8f1Swyllys prog);
6207711facfSdinak (void) fprintf(stdout, gettext("where subcommands may be:\n"));
6217711facfSdinak
6227711facfSdinak /* Display only those verbs that match the current tool mode. */
62399ebb4caSwyllys if (idx == -1) {
6247711facfSdinak for (i = 0; i < num_cmds; i++) {
6257711facfSdinak /* Do NOT i18n/l10n. */
626985be8f1Swyllys (void) fprintf(stdout, " %-8s - %s\n",
627985be8f1Swyllys cmds[i].verb, cmds[i].summary);
6287711facfSdinak }
629fa60c371Swyllys (void) fprintf(stdout, "%s \'help\'.\n"
630fa60c371Swyllys "Ex: pktool gencert help\n\n",
631fa60c371Swyllys gettext("\nFurther details on the "
632fa60c371Swyllys "subcommands can be found by adding"));
63399ebb4caSwyllys } else {
63499ebb4caSwyllys (void) fprintf(stdout, "\t%s\n", cmds[idx].synopsis);
63599ebb4caSwyllys }
6367711facfSdinak }
6377711facfSdinak
6387711facfSdinak /*
6397711facfSdinak * Provide help, in the form of displaying the usage.
6407711facfSdinak */
6417711facfSdinak static int
pk_help(int argc,char * argv[])6427711facfSdinak pk_help(int argc, char *argv[])
6437711facfSdinak /* ARGSUSED */
6447711facfSdinak {
64599ebb4caSwyllys usage(-1);
64699ebb4caSwyllys return (0);
64799ebb4caSwyllys }
6487711facfSdinak
64999ebb4caSwyllys /*
65099ebb4caSwyllys * Process arguments from the argfile and create a new
65199ebb4caSwyllys * argv/argc list to be processed later.
65299ebb4caSwyllys */
65399ebb4caSwyllys static int
process_arg_file(char * argfile,char *** argv,int * argc)65499ebb4caSwyllys process_arg_file(char *argfile, char ***argv, int *argc)
65599ebb4caSwyllys {
65699ebb4caSwyllys FILE *fp;
65799ebb4caSwyllys char argline[2 * BUFSIZ]; /* 2048 bytes should be plenty */
65899ebb4caSwyllys char *p;
65999ebb4caSwyllys int nargs = 0;
66099ebb4caSwyllys
66199ebb4caSwyllys if ((fp = fopen(argfile, "rF")) == NULL) {
66299ebb4caSwyllys (void) fprintf(stderr,
66399ebb4caSwyllys gettext("Cannot read argfile %s: %s\n"),
66499ebb4caSwyllys argfile, strerror(errno));
66599ebb4caSwyllys return (errno);
66699ebb4caSwyllys }
66799ebb4caSwyllys
66899ebb4caSwyllys while (fgets(argline, sizeof (argline), fp) != NULL) {
66999ebb4caSwyllys int j;
67099ebb4caSwyllys /* remove trailing whitespace */
67199ebb4caSwyllys j = strlen(argline) - 1;
67299ebb4caSwyllys while (j >= 0 && isspace(argline[j])) {
67399ebb4caSwyllys argline[j] = 0;
67499ebb4caSwyllys j--;
67599ebb4caSwyllys }
67699ebb4caSwyllys /* If it was a blank line, get the next one. */
67799ebb4caSwyllys if (!strlen(argline))
67899ebb4caSwyllys continue;
67999ebb4caSwyllys
68030a5e8faSwyllys (*argv) = realloc((*argv),
68130a5e8faSwyllys (nargs + 1) * sizeof (char *));
68299ebb4caSwyllys if ((*argv) == NULL) {
68399ebb4caSwyllys perror("memory error");
68499ebb4caSwyllys (void) fclose(fp);
68599ebb4caSwyllys return (errno);
68699ebb4caSwyllys }
68799ebb4caSwyllys p = (char *)strdup(argline);
68899ebb4caSwyllys if (p == NULL) {
68999ebb4caSwyllys perror("memory error");
69099ebb4caSwyllys (void) fclose(fp);
69199ebb4caSwyllys return (errno);
69299ebb4caSwyllys }
69399ebb4caSwyllys (*argv)[nargs] = p;
69499ebb4caSwyllys nargs++;
69599ebb4caSwyllys }
69699ebb4caSwyllys *argc = nargs;
69799ebb4caSwyllys (void) fclose(fp);
6987711facfSdinak return (0);
6997c478bd9Sstevel@tonic-gate }
7007c478bd9Sstevel@tonic-gate
7017c478bd9Sstevel@tonic-gate /*
7027c478bd9Sstevel@tonic-gate * MAIN() -- where all the action is
7037c478bd9Sstevel@tonic-gate */
7047c478bd9Sstevel@tonic-gate int
main(int argc,char * argv[],char * envp[])7057c478bd9Sstevel@tonic-gate main(int argc, char *argv[], char *envp[])
7067c478bd9Sstevel@tonic-gate /* ARGSUSED2 */
7077c478bd9Sstevel@tonic-gate {
7087c478bd9Sstevel@tonic-gate int i, found = -1;
7097c478bd9Sstevel@tonic-gate int rv;
7107c478bd9Sstevel@tonic-gate int pk_argc = 0;
7117c478bd9Sstevel@tonic-gate char **pk_argv = NULL;
7127711facfSdinak int save_errno = 0;
7137c478bd9Sstevel@tonic-gate
7147c478bd9Sstevel@tonic-gate /* Set up for i18n/l10n. */
7157c478bd9Sstevel@tonic-gate (void) setlocale(LC_ALL, "");
7167c478bd9Sstevel@tonic-gate #if !defined(TEXT_DOMAIN) /* Should be defined by cc -D. */
7177c478bd9Sstevel@tonic-gate #define TEXT_DOMAIN "SYS_TEST" /* Use this only if it isn't. */
7187c478bd9Sstevel@tonic-gate #endif
7197c478bd9Sstevel@tonic-gate (void) textdomain(TEXT_DOMAIN);
7207c478bd9Sstevel@tonic-gate
721d00756ccSwyllys init_command_list();
722d00756ccSwyllys
7237c478bd9Sstevel@tonic-gate /* Get program base name and move pointer over 0th arg. */
7247c478bd9Sstevel@tonic-gate prog = basename(argv[0]);
7257c478bd9Sstevel@tonic-gate argv++, argc--;
7267c478bd9Sstevel@tonic-gate
7277c478bd9Sstevel@tonic-gate /* Set up for debug and error output. */
7287c478bd9Sstevel@tonic-gate if (argc == 0) {
72999ebb4caSwyllys usage(-1);
7307c478bd9Sstevel@tonic-gate return (1);
7317c478bd9Sstevel@tonic-gate }
7327c478bd9Sstevel@tonic-gate
7337711facfSdinak /* Check for help options. For CLIP-compliance. */
73499ebb4caSwyllys if (strcmp(argv[0], "-?") == 0) {
7357711facfSdinak return (pk_help(argc, argv));
73699ebb4caSwyllys } else if (strcmp(argv[0], "-f") == 0 && argc == 2) {
73799ebb4caSwyllys rv = process_arg_file(argv[1], &pk_argv, &pk_argc);
73899ebb4caSwyllys if (rv)
73999ebb4caSwyllys return (rv);
74099ebb4caSwyllys } else if (argc >= 1 && argv[0][0] == '-') {
74199ebb4caSwyllys usage(-1);
7427711facfSdinak return (1);
7437711facfSdinak }
7447711facfSdinak
7457711facfSdinak /* Always turns off Metaslot so that we can see softtoken. */
7467c478bd9Sstevel@tonic-gate if (setenv("METASLOT_ENABLED", "false", 1) < 0) {
7477711facfSdinak save_errno = errno;
7487c478bd9Sstevel@tonic-gate cryptoerror(LOG_STDERR,
7497711facfSdinak gettext("Disabling Metaslot failed (%s)."),
7507711facfSdinak strerror(save_errno));
7517c478bd9Sstevel@tonic-gate return (1);
7527c478bd9Sstevel@tonic-gate }
7537c478bd9Sstevel@tonic-gate
7547c478bd9Sstevel@tonic-gate /* Begin parsing command line. */
75599ebb4caSwyllys if (pk_argc == 0 && pk_argv == NULL) {
7567c478bd9Sstevel@tonic-gate pk_argc = argc;
7577c478bd9Sstevel@tonic-gate pk_argv = argv;
75899ebb4caSwyllys }
7597c478bd9Sstevel@tonic-gate
7607711facfSdinak /* Check for valid verb (or an abbreviation of it). */
7617c478bd9Sstevel@tonic-gate found = -1;
7627c478bd9Sstevel@tonic-gate for (i = 0; i < num_cmds; i++) {
7637c478bd9Sstevel@tonic-gate if (strcmp(cmds[i].verb, pk_argv[0]) == 0) {
7647c478bd9Sstevel@tonic-gate if (found < 0) {
7657c478bd9Sstevel@tonic-gate found = i;
7667c478bd9Sstevel@tonic-gate break;
7677c478bd9Sstevel@tonic-gate }
7687c478bd9Sstevel@tonic-gate }
7697c478bd9Sstevel@tonic-gate }
7707c478bd9Sstevel@tonic-gate /* Stop here if no valid verb found. */
7717c478bd9Sstevel@tonic-gate if (found < 0) {
7727711facfSdinak cryptoerror(LOG_STDERR, gettext("Invalid verb: %s"),
7737711facfSdinak pk_argv[0]);
7747c478bd9Sstevel@tonic-gate return (1);
7757c478bd9Sstevel@tonic-gate }
7767c478bd9Sstevel@tonic-gate
7777c478bd9Sstevel@tonic-gate /* Get to work! */
7787c478bd9Sstevel@tonic-gate rv = (*cmds[found].action)(pk_argc, pk_argv);
7797c478bd9Sstevel@tonic-gate switch (rv) {
7807c478bd9Sstevel@tonic-gate case PK_ERR_NONE:
7817c478bd9Sstevel@tonic-gate break; /* Command succeeded, do nothing. */
7827c478bd9Sstevel@tonic-gate case PK_ERR_USAGE:
78399ebb4caSwyllys usage(found);
7847c478bd9Sstevel@tonic-gate break;
7857c478bd9Sstevel@tonic-gate case PK_ERR_QUIT:
7867c478bd9Sstevel@tonic-gate exit(0);
7877c478bd9Sstevel@tonic-gate /* NOTREACHED */
7887711facfSdinak case PK_ERR_PK11:
7897711facfSdinak case PK_ERR_SYSTEM:
7907711facfSdinak case PK_ERR_OPENSSL:
79199ebb4caSwyllys case PK_ERR_NSS:
7927c478bd9Sstevel@tonic-gate default:
7937c478bd9Sstevel@tonic-gate break;
7947c478bd9Sstevel@tonic-gate }
7957c478bd9Sstevel@tonic-gate return (rv);
7967c478bd9Sstevel@tonic-gate }
797