5 Author: Pekka Riikonen <priikone@silcnet.org>
7 Copyright (C) 2002 Pekka Riikonen
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; version 2 of the License.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
21 #include "silcincludes.h"
23 static char *silc_create_pk_identifier(void)
25 char *username = NULL, *realname = NULL;
26 char *hostname, email[256];
30 realname = silc_get_real_name();
33 hostname = silc_net_localhost();
37 /* Get username (mandatory) */
38 username = silc_get_username();
42 /* Create default email address, whether it is right or not */
43 snprintf(email, sizeof(email), "%s@%s", username, hostname);
45 ident = silc_pkcs_encode_identifier(username, hostname, realname, email,
55 /* Generate key pair */
57 bool silc_create_key_pair(const char *pkcs_name,
58 SilcUInt32 key_len_bits,
59 const char *pub_filename,
60 const char *prv_filename,
61 const char *pub_identifier,
62 const char *passphrase,
63 SilcPKCS *return_pkcs,
64 SilcPublicKey *return_public_key,
65 SilcPrivateKey *return_private_key,
69 SilcPublicKey pub_key;
70 SilcPrivateKey prv_key;
75 char *pkfile = pub_filename ? strdup(pub_filename) : NULL;
76 char *prvfile = prv_filename ? strdup(prv_filename) : NULL;
77 char *alg = pkcs_name ? strdup(pkcs_name) : NULL;
78 char *identifier = pub_identifier ? strdup(pub_identifier) : NULL;
79 char *pass = passphrase ? strdup(passphrase) : NULL;
81 if (interactive && (!alg || !pub_filename || !prv_filename))
83 New pair of keys will be created. Please, answer to following questions.\n\
89 alg = silc_get_input("PKCS name (l to list names) [rsa]: ", FALSE);
93 if (*alg == 'l' || *alg == 'L') {
94 char *list = silc_pkcs_get_supported();
106 if (!silc_pkcs_is_supported(alg)) {
107 fprintf(stderr, "Unknown PKCS algorithm `%s' or crypto library"
108 "is not initialized", alg);
115 length = silc_get_input("Key length in key_len_bits [2048]: ", FALSE);
117 key_len_bits = atoi(length);
125 char *def = silc_create_pk_identifier();
128 memset(line, 0, sizeof(line));
130 snprintf(line, sizeof(line), "Identifier [%s]: ", def);
132 snprintf(line, sizeof(line),
133 "Identifier (eg. UN=jon, HN=jon.dummy.com, "
134 "RN=Jon Johnson, E=jon@dummy.com): ");
136 while (!identifier) {
137 identifier = silc_get_input(line, FALSE);
138 if (!identifier && def)
139 identifier = strdup(def);
143 fprintf(stderr, "Could not create public key identifier: %s\n",
147 identifier = strdup(def);
153 rng = silc_rng_alloc();
155 silc_rng_global_init(rng);
159 memset(line, 0, sizeof(line));
160 snprintf(line, sizeof(line), "Public key filename [public_key.pub]: ");
161 pkfile = silc_get_input(line, FALSE);
164 pkfile = strdup("public_key.pub");
169 memset(line, 0, sizeof(line));
170 snprintf(line, sizeof(line), "Private key filename [private_key.prv]: ");
171 prvfile = silc_get_input(line, FALSE);
174 prvfile = strdup("private_key.prv");
178 memset(line, 0, sizeof(line));
179 snprintf(line, sizeof(line), "Private key passphrase: ");
180 pass = silc_get_input(line, TRUE);
186 silc_pkcs_alloc(alg, &pkcs);
187 silc_pkcs_generate_key(pkcs, key_len_bits, rng);
189 /* Save public key into file */
190 key = silc_pkcs_get_public_key(pkcs, &key_len);
191 pub_key = silc_pkcs_public_key_alloc(silc_pkcs_get_name(pkcs),
192 identifier, key, key_len);
193 silc_pkcs_save_public_key(pkfile, pub_key, SILC_PKCS_FILE_PEM);
194 if (return_public_key)
195 *return_public_key = pub_key;
197 silc_pkcs_public_key_free(pub_key);
198 memset(key, 0, key_len);
201 /* Save private key into file */
202 key = silc_pkcs_get_private_key(pkcs, &key_len);
203 prv_key = silc_pkcs_private_key_alloc(silc_pkcs_get_name(pkcs),
205 silc_pkcs_save_private_key(prvfile, prv_key,
206 (unsigned char *)pass, strlen(pass),
208 if (return_private_key)
209 *return_private_key = prv_key;
211 silc_pkcs_private_key_free(prv_key);
212 memset(key, 0, key_len);
215 printf("Public key has been saved into `%s'.\n", pkfile);
216 printf("Private key has been saved into `%s'.\n", prvfile);
218 printf("Press <Enter> to continue...\n");
225 silc_pkcs_free(pkcs);
231 silc_free(identifier);
232 memset(pass, 0, strlen(pass));
240 bool silc_load_key_pair(const char *pub_filename,
241 const char *prv_filename,
242 const char *passphrase,
243 SilcPKCS *return_pkcs,
244 SilcPublicKey *return_public_key,
245 SilcPrivateKey *return_private_key)
247 char *pass = passphrase ? strdup(passphrase) : NULL;
249 SILC_LOG_DEBUG(("Loading public and private keys"));
251 if (silc_pkcs_load_public_key((char *)pub_filename, return_public_key,
252 SILC_PKCS_FILE_PEM) == FALSE)
253 if (silc_pkcs_load_public_key((char *)pub_filename, return_public_key,
254 SILC_PKCS_FILE_BIN) == FALSE) {
255 memset(pass, 0, strlen(pass));
261 pass = silc_get_input("Private key passphrase: ", TRUE);
266 if (silc_pkcs_load_private_key((char *)prv_filename, return_private_key,
267 (unsigned char *)pass, strlen(pass),
268 SILC_PKCS_FILE_BIN) == FALSE)
269 if (silc_pkcs_load_private_key((char *)prv_filename, return_private_key,
270 (unsigned char *)pass, strlen(pass),
271 SILC_PKCS_FILE_PEM) == FALSE) {
272 memset(pass, 0, strlen(pass));
278 silc_pkcs_alloc((*return_public_key)->name, return_pkcs);
279 silc_pkcs_public_key_set(*return_pkcs, *return_public_key);
280 silc_pkcs_private_key_set(*return_pkcs, *return_private_key);
283 memset(pass, 0, strlen(pass));
288 /* Dump public key into stdout */
290 bool silc_show_public_key(const char *pub_filename)
292 SilcPublicKey public_key;
293 SilcPublicKeyIdentifier ident;
294 char *fingerprint, *babbleprint;
298 SilcUInt32 key_len = 0;
300 if (silc_pkcs_load_public_key((char *)pub_filename, &public_key,
301 SILC_PKCS_FILE_PEM) == FALSE)
302 if (silc_pkcs_load_public_key((char *)pub_filename, &public_key,
303 SILC_PKCS_FILE_BIN) == FALSE) {
304 fprintf(stderr, "Could not load public key file `%s'\n", pub_filename);
308 ident = silc_pkcs_decode_identifier(public_key->identifier);
310 pk = silc_pkcs_public_key_encode(public_key, &pk_len);
311 fingerprint = silc_hash_fingerprint(NULL, pk, pk_len);
312 babbleprint = silc_hash_babbleprint(NULL, pk, pk_len);
314 if (silc_pkcs_alloc(public_key->name, &pkcs)) {
315 key_len = silc_pkcs_public_key_set(pkcs, public_key);
316 silc_pkcs_free(pkcs);
319 printf("Public key file : %s\n", pub_filename);
320 printf("Algorithm : %s\n", public_key->name);
322 printf("Key length (bits) : %d\n", (unsigned int)key_len);
324 printf("Real name : %s\n", ident->realname);
326 printf("Username : %s\n", ident->username);
328 printf("Hostname : %s\n", ident->host);
330 printf("Email : %s\n", ident->email);
332 printf("Organization : %s\n", ident->org);
334 printf("Country : %s\n", ident->country);
335 printf("Fingerprint (SHA1) : %s\n", fingerprint);
336 printf("Babbleprint (SHA1) : %s\n", babbleprint);
340 silc_free(fingerprint);
341 silc_free(babbleprint);
343 silc_pkcs_public_key_free(public_key);
344 silc_pkcs_free_identifier(ident);
349 /* Change private key passphrase */
351 bool silc_change_private_key_passphrase(const char *prv_filename,
352 const char *old_passphrase,
353 const char *new_passphrase)
355 SilcPrivateKey private_key;
359 pass = old_passphrase ? strdup(old_passphrase) : NULL;
361 pass = silc_get_input("Old passphrase: ", TRUE);
366 if (silc_pkcs_load_private_key((char *)prv_filename, &private_key,
367 (unsigned char *)pass, strlen(pass),
368 SILC_PKCS_FILE_BIN) == FALSE) {
370 if (silc_pkcs_load_private_key((char *)prv_filename, &private_key,
371 (unsigned char *)pass, strlen(pass),
372 SILC_PKCS_FILE_PEM) == FALSE) {
373 memset(pass, 0, strlen(pass));
375 fprintf(stderr, "Could not load private key `%s' file\n", prv_filename);
380 memset(pass, 0, strlen(pass));
383 pass = new_passphrase ? strdup(new_passphrase) : NULL;
385 fprintf(stdout, "\n");
386 pass = silc_get_input("New passphrase: ", TRUE);
391 silc_pkcs_save_private_key(prv_filename, private_key,
392 (unsigned char *)pass, strlen(pass),
393 base64 ? SILC_PKCS_FILE_PEM : SILC_PKCS_FILE_BIN);
395 fprintf(stdout, "\nPassphrase changed\n");
397 memset(pass, 0, strlen(pass));
400 silc_pkcs_private_key_free(private_key);