|
|
9485e8 |
diff -up ./esc/esc-1.1.2/esc/src/app/esc.js.fix10 ./esc/esc-1.1.2/esc/src/app/esc.js
|
|
|
9485e8 |
--- ./esc/src/app/esc.js.fix10 2020-12-02 15:47:00.688951279 -0800
|
|
|
9485e8 |
+++ ./esc/src/app/esc.js 2020-12-02 15:47:00.690951273 -0800
|
|
|
9485e8 |
@@ -370,12 +370,20 @@ class ESC {
|
|
|
9485e8 |
let nick = "";
|
|
|
9485e8 |
if(certObj.token == null)
|
|
|
9485e8 |
token = "internal";
|
|
|
9485e8 |
- else
|
|
|
9485e8 |
+ else {
|
|
|
9485e8 |
token = certObj.token;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
|
|
|
9485e8 |
nick = certObj.nick;
|
|
|
9485e8 |
-
|
|
|
9485e8 |
- certDetail = this._execProgram(['/usr/bin/certutil','-L','-d', this._getConfigPath(), '-h', token, '-f' , pFileName, '-n', token + ":" + nick]);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ let tokenNick = '"' + token + ":" + nick + '"' ;
|
|
|
9485e8 |
+ token = '"' + token + '"';
|
|
|
9485e8 |
+ let argv1 = ['/usr/bin/certutil','-L','-d', this._getConfigPath(), '-h', token, '-f' , pFileName, '-n', tokenNick];
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ print("argv1: " + argv1);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ certDetail = this._execProgram(argv1);
|
|
|
9485e8 |
|
|
|
9485e8 |
return certDetail;
|
|
|
9485e8 |
}
|
|
|
9485e8 |
@@ -475,7 +483,7 @@ class ESC {
|
|
|
9485e8 |
result = -1;
|
|
|
9485e8 |
return result;
|
|
|
9485e8 |
}
|
|
|
9485e8 |
-
|
|
|
9485e8 |
+
|
|
|
9485e8 |
result = stdoutb.toString();
|
|
|
9485e8 |
|
|
|
9485e8 |
} catch (e) {
|
|
|
9485e8 |
@@ -792,19 +800,18 @@ class ESC {
|
|
|
9485e8 |
let status = this._selectedTokenInfo.status;
|
|
|
9485e8 |
|
|
|
9485e8 |
if(status == 4 /* enrolled */) {
|
|
|
9485e8 |
- this._pinMgr = new PinDialog.pinDialog(this);
|
|
|
9485e8 |
- this._pinMgr.launchPinPrompt(this._promptPinDone.bind(this));
|
|
|
9485e8 |
+ let coolkey_token = this._selectedTokenInfo;
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ this._tokenInfoBuffer.text +=
|
|
|
9485e8 |
+ this.mgr.get_certs_info(coolkey_token);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
}
|
|
|
9485e8 |
|
|
|
9485e8 |
}
|
|
|
9485e8 |
- _promptPinDone(tempFileName) {
|
|
|
9485e8 |
-
|
|
|
9485e8 |
- let coolkey_token = this._selectedTokenInfo;
|
|
|
9485e8 |
-
|
|
|
9485e8 |
- this._tokenInfoBuffer.text +=
|
|
|
9485e8 |
- this._getCertList(coolkey_token,tempFileName) + "\n";
|
|
|
9485e8 |
|
|
|
9485e8 |
+ _promptPinDone(tempFileName) {
|
|
|
9485e8 |
}
|
|
|
9485e8 |
+
|
|
|
9485e8 |
_response_cb() {
|
|
|
9485e8 |
if(this._messageDialog) {
|
|
|
9485e8 |
this._messageDialog.destroy();
|
|
|
9485e8 |
diff -up ./esc/src/app/opensc.esc.conf.fix10 ./esc/src/app/opensc.esc.conf
|
|
|
9485e8 |
--- ./esc/src/app/opensc.esc.conf.fix10 2020-12-02 15:51:05.812283690 -0800
|
|
|
9485e8 |
+++ ./esc/src/app/opensc.esc.conf 2020-12-02 15:51:30.835215539 -0800
|
|
|
9485e8 |
@@ -94,6 +94,7 @@ app default {
|
|
|
9485e8 |
module_path = /usr/lib64;
|
|
|
9485e8 |
}
|
|
|
9485e8 |
framework pkcs15 {
|
|
|
9485e8 |
+ use_file_caching = true;
|
|
|
9485e8 |
builtin_emulators = coolkey, cac, cac1, PIV-II;
|
|
|
9485e8 |
}
|
|
|
9485e8 |
}
|
|
|
9485e8 |
diff -up ./esc/src/app/pinDialog.js.fix10 ./esc/src/app/pinDialog.js
|
|
|
9485e8 |
--- ./esc/src/app/pinDialog.js.fix10 2020-12-02 15:47:00.683951293 -0800
|
|
|
9485e8 |
+++ ./esc/src/app/pinDialog.js 2020-12-02 15:47:00.691951271 -0800
|
|
|
9485e8 |
@@ -94,7 +94,6 @@ pinDialog.prototype = {
|
|
|
9485e8 |
if(this.notify) {
|
|
|
9485e8 |
this.notify(this.tempFileName);
|
|
|
9485e8 |
}
|
|
|
9485e8 |
-
|
|
|
9485e8 |
this.clearTempFile();
|
|
|
9485e8 |
this.dialog.destroy();
|
|
|
9485e8 |
this.dialog = null;
|
|
|
9485e8 |
diff -up ./esc/src/lib/coolkey/CoolKeyHandler.cpp.fix10 ./esc/src/lib/coolkey/CoolKeyHandler.cpp
|
|
|
9485e8 |
--- ./esc/src/lib/coolkey/CoolKeyHandler.cpp.fix10 2020-12-02 16:25:29.075670723 -0800
|
|
|
9485e8 |
+++ ./esc/src/lib/coolkey/CoolKeyHandler.cpp 2020-12-02 16:30:53.310789119 -0800
|
|
|
9485e8 |
@@ -46,6 +46,7 @@
|
|
|
9485e8 |
|
|
|
9485e8 |
static const char *cac_manu_id= "Common Access Card";
|
|
|
9485e8 |
static const char *piv_manu_id= "piv II ";
|
|
|
9485e8 |
+static const char *piv_manu_id_1= "piv_II";
|
|
|
9485e8 |
|
|
|
9485e8 |
//static char *test_extended_login = "s=325&msg_type=13&invalid_login=0&blocked=0&error=&required_parameter0=id%3DUSER%5FID%26name%3DUser+ID%26desc%3DUser+ID%26type%3Dstring%26option%3Doption1%2Coption2%2Coption3&required_parameter1=id%3DUSER%5FPWD%26name%3DUser+Password%26desc%3DUser+Password%26type%3Dpassword%26option%3D&required_parameter2=id%3DUSER%5FPIN%26name%3DPIN%26desc%3DOne+time+PIN+received+via+mail%26type%3Dpassword%26option%3D";
|
|
|
9485e8 |
|
|
|
9485e8 |
@@ -2300,7 +2301,9 @@ CKHGetCoolKeyInfo(PK11SlotInfo *aSlot,Co
|
|
|
9485e8 |
if(!memcmp( tokenInfo.manufacturerID,cac_manu_id,strlen(cac_manu_id ))) {
|
|
|
9485e8 |
isACAC = 1;
|
|
|
9485e8 |
} else if(!memcmp(tokenInfo.manufacturerID, piv_manu_id, strlen(piv_manu_id))) {
|
|
|
9485e8 |
- isAPIV = 1;
|
|
|
9485e8 |
+ isAPIV = 1;
|
|
|
9485e8 |
+ } else if(!memcmp(tokenInfo.manufacturerID, piv_manu_id_1, strlen(piv_manu_id_1))) {
|
|
|
9485e8 |
+ isAPIV = 1;
|
|
|
9485e8 |
} else {
|
|
|
9485e8 |
isACOOLKey = 1;
|
|
|
9485e8 |
}
|
|
|
9485e8 |
diff -up ./esc/src/lib/coolkey-mgr/coolkey-api.cpp.fix10 ./esc/src/lib/coolkey-mgr/coolkey-api.cpp
|
|
|
9485e8 |
--- ./esc/src/lib/coolkey-mgr/coolkey-api.cpp.fix10 2020-12-02 15:47:00.673951320 -0800
|
|
|
9485e8 |
+++ ./esc/src/lib/coolkey-mgr/coolkey-api.cpp 2020-12-02 15:47:00.691951271 -0800
|
|
|
9485e8 |
@@ -17,6 +17,8 @@
|
|
|
9485e8 |
|
|
|
9485e8 |
#include "coolkey-api.h"
|
|
|
9485e8 |
#include "rhCoolKey.h"
|
|
|
9485e8 |
+#include <string>
|
|
|
9485e8 |
+
|
|
|
9485e8 |
|
|
|
9485e8 |
static rhCoolKey *coolkey = NULL;
|
|
|
9485e8 |
static const char * coolkeyDbusName = NULL;
|
|
|
9485e8 |
@@ -79,6 +81,54 @@ char *coolkey_get_phone_home(char *url)
|
|
|
9485e8 |
}
|
|
|
9485e8 |
}
|
|
|
9485e8 |
|
|
|
9485e8 |
+/* get a string with all the certs detail for a token */
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+char *coolkey_get_certs_info(int keyType, const char *keyID) {
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ string str_result;
|
|
|
9485e8 |
+ if (coolkey == NULL) {
|
|
|
9485e8 |
+ return NULL;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ char *result = NULL;
|
|
|
9485e8 |
+ char **names = NULL;
|
|
|
9485e8 |
+ PRUint32 count = 0;
|
|
|
9485e8 |
+ HRESULT res = coolkey->GetCoolKeyCertNicknames(keyType, keyID, &count, &names);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(count > 0 && res == S_OK) {
|
|
|
9485e8 |
+ for(int i = 0 ; i < count ; i++) {
|
|
|
9485e8 |
+ char *curName = names[i];
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(curName) {
|
|
|
9485e8 |
+ char *certDetail = NULL;
|
|
|
9485e8 |
+ str_result = str_result + curName + "\n" ;
|
|
|
9485e8 |
+ res = coolkey->GetCoolKeyCertInfo(keyType, keyID, curName, &certDetail);
|
|
|
9485e8 |
+ if(res == S_OK && certDetail != NULL) {
|
|
|
9485e8 |
+ str_result = str_result + certDetail + "\n";
|
|
|
9485e8 |
+ PL_strfree(certDetail);
|
|
|
9485e8 |
+ certDetail = NULL;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(str_result.c_str()) {
|
|
|
9485e8 |
+ result = PL_strdup((char *) str_result.c_str());
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ for(int i = 0 ; i < count ; i++) {
|
|
|
9485e8 |
+ if(names[i]) {
|
|
|
9485e8 |
+ PL_strfree(names[i]);
|
|
|
9485e8 |
+ names[i] = NULL;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ PR_Free(names);
|
|
|
9485e8 |
+ names = NULL;
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ return result;
|
|
|
9485e8 |
+}
|
|
|
9485e8 |
+
|
|
|
9485e8 |
|
|
|
9485e8 |
/* get a block of data about a token in a structure format */
|
|
|
9485e8 |
tokenInfo *coolkey_get_token_info(int keyType, const char *keyID) {
|
|
|
9485e8 |
diff -up ./esc/src/lib/coolkey-mgr/coolkey-api.h.fix10 ./esc/src/lib/coolkey-mgr/coolkey-api.h
|
|
|
9485e8 |
--- ./esc/src/lib/coolkey-mgr/coolkey-api.h.fix10 2020-12-02 15:47:00.673951320 -0800
|
|
|
9485e8 |
+++ ./esc/src/lib/coolkey-mgr/coolkey-api.h 2020-12-02 15:47:00.691951271 -0800
|
|
|
9485e8 |
@@ -43,6 +43,8 @@ void coolkey_init(const char *db_dir, co
|
|
|
9485e8 |
void coolkey_destroy();
|
|
|
9485e8 |
|
|
|
9485e8 |
char *coolkey_get_phone_home(char *url);
|
|
|
9485e8 |
+char *coolkey_get_certs_info(int keyType, const char *keyID);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
tokenInfo *coolkey_get_token_info(int keyType,const char *keyID);
|
|
|
9485e8 |
void coolkey_free_token_info(tokenInfo *tInfo);
|
|
|
9485e8 |
|
|
|
9485e8 |
diff -up ./esc/src/lib/coolkey-mgr/coolkey-mgr.c.fix10 ./esc/src/lib/coolkey-mgr/coolkey-mgr.c
|
|
|
9485e8 |
--- ./esc/src/lib/coolkey-mgr/coolkey-mgr.c.fix10 2020-12-02 15:47:00.673951320 -0800
|
|
|
9485e8 |
+++ ./esc/src/lib/coolkey-mgr/coolkey-mgr.c 2020-12-02 15:47:00.691951271 -0800
|
|
|
9485e8 |
@@ -346,6 +346,36 @@ cleanup:
|
|
|
9485e8 |
}
|
|
|
9485e8 |
|
|
|
9485e8 |
|
|
|
9485e8 |
+gchar*
|
|
|
9485e8 |
+coolkey_mgr_get_certs_info(CoolkeyMgr *self, CoolkeyToken* token) {
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ gchar *cuid = NULL;
|
|
|
9485e8 |
+ gchar *keyType = NULL;
|
|
|
9485e8 |
+ int keyTypeInt = 0;
|
|
|
9485e8 |
+ gchar *certInfo = NULL;
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ g_object_get(token,"key_type", &keyType,NULL);
|
|
|
9485e8 |
+ g_object_get(token,"cuid", &cuid, NULL);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(keyType == NULL || cuid == NULL) {
|
|
|
9485e8 |
+ goto cleanup;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ keyTypeInt = atoi(keyType);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(keyType == NULL || cuid == NULL) {
|
|
|
9485e8 |
+ goto cleanup;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ certInfo = coolkey_get_certs_info(keyTypeInt, cuid);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+cleanup:
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ g_free (keyType);
|
|
|
9485e8 |
+ g_free (cuid);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ return certInfo;
|
|
|
9485e8 |
+}
|
|
|
9485e8 |
|
|
|
9485e8 |
void
|
|
|
9485e8 |
coolkey_mgr_get_token_info(CoolkeyMgr* self, CoolkeyToken* token) {
|
|
|
9485e8 |
diff -up ./esc/src/lib/coolkey-mgr/coolkey-mgr.h.fix10 ./esc/src/lib/coolkey-mgr/coolkey-mgr.h
|
|
|
9485e8 |
--- ./esc/src/lib/coolkey-mgr/coolkey-mgr.h.fix10 2020-12-02 15:47:00.673951320 -0800
|
|
|
9485e8 |
+++ ./esc/src/lib/coolkey-mgr/coolkey-mgr.h 2020-12-02 15:47:00.691951271 -0800
|
|
|
9485e8 |
@@ -46,6 +46,8 @@ int coolkey_mgr_cancel_token_operation(C
|
|
|
9485e8 |
|
|
|
9485e8 |
void coolkey_mgr_get_token_info(CoolkeyMgr* self, CoolkeyToken* token);
|
|
|
9485e8 |
|
|
|
9485e8 |
+gchar * coolkey_mgr_get_certs_info(CoolkeyMgr*self, CoolkeyToken* token);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
gchar * coolkey_mgr_phone_home(CoolkeyMgr* self, gchar *url);
|
|
|
9485e8 |
|
|
|
9485e8 |
gchar * coolkey_mgr_speak (CoolkeyMgr* self, gchar *words);
|
|
|
9485e8 |
diff -up ./esc/src/lib/coolkey/NSSManager.cpp.fix10 ./esc/src/lib/coolkey/NSSManager.cpp
|
|
|
9485e8 |
--- ./esc/src/lib/coolkey/NSSManager.cpp.fix10 2020-12-02 15:47:00.680951301 -0800
|
|
|
9485e8 |
+++ ./esc/src/lib/coolkey/NSSManager.cpp 2020-12-02 15:47:00.691951271 -0800
|
|
|
9485e8 |
@@ -41,7 +41,7 @@
|
|
|
9485e8 |
|
|
|
9485e8 |
#include <iostream>
|
|
|
9485e8 |
#include <sstream>
|
|
|
9485e8 |
-
|
|
|
9485e8 |
+#include <algorithm>
|
|
|
9485e8 |
#include "SlotUtils.h"
|
|
|
9485e8 |
|
|
|
9485e8 |
static PRLogModuleInfo *coolKeyLogNSS = PR_NewLogModule("coolKeyNSS");
|
|
|
9485e8 |
@@ -314,7 +314,10 @@ NSSManager::GetKeyCertNicknames( const C
|
|
|
9485e8 |
CERTCertificate *cert = node->cert;
|
|
|
9485e8 |
if(cert)
|
|
|
9485e8 |
{
|
|
|
9485e8 |
- if(cert->slot != slot)
|
|
|
9485e8 |
+ char *certSlotName = PK11_GetSlotName(cert->slot);
|
|
|
9485e8 |
+ char *slotName = PK11_GetSlotName(slot);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(strcmp(certSlotName, slotName))
|
|
|
9485e8 |
{
|
|
|
9485e8 |
CERT_RemoveCertListNode(node);
|
|
|
9485e8 |
}
|
|
|
9485e8 |
@@ -346,7 +349,10 @@ NSSManager::GetKeyCertNicknames( const C
|
|
|
9485e8 |
PR_LOG( coolKeyLogNSS, PR_LOG_DEBUG, ("%s NSSManager::GetCertKeyNicknames name %s \n",GetTStamp(tBuff,56),curName));
|
|
|
9485e8 |
|
|
|
9485e8 |
string str = curName;
|
|
|
9485e8 |
- aStrings.push_back (str);
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if (find(aStrings.begin(), aStrings.end(), str) == aStrings.end()) {
|
|
|
9485e8 |
+ aStrings.push_back (str);
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
}
|
|
|
9485e8 |
|
|
|
9485e8 |
CERT_FreeNicknames(nicknames);
|
|
|
9485e8 |
@@ -691,6 +697,16 @@ HRESULT NSSManager::GetKeyCertInfo(const
|
|
|
9485e8 |
aCertInfo = issuedToCNStr + "\n" + issuerCNStr + "\n"
|
|
|
9485e8 |
+ notBeforeStr + "\n" + notAfterStr + "\n" + serialStr ;
|
|
|
9485e8 |
PR_LOG( coolKeyLogNSS, PR_LOG_DEBUG, ("%s NSSManager::GetKeyCertInfo issuerCN %s issuedToCN %s \n",GetTStamp(tBuff,56),issuerCN, issuedToCN));
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(nBefore) {
|
|
|
9485e8 |
+ PORT_Free(nBefore);
|
|
|
9485e8 |
+ nBefore = NULL;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
+
|
|
|
9485e8 |
+ if(nAfter) {
|
|
|
9485e8 |
+ PORT_Free(nAfter);
|
|
|
9485e8 |
+ nAfter = NULL;
|
|
|
9485e8 |
+ }
|
|
|
9485e8 |
|
|
|
9485e8 |
break;
|
|
|
9485e8 |
}
|