5 Author: Pekka Riikonen <priikone@silcnet.org>
7 Copyright (C) 2002 Pekka Riikonen
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; version 2 of the License.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
21 #include "silcincludes.h"
23 static char *silc_create_pk_identifier(void)
25 char *username = NULL, *realname = NULL;
26 char *hostname, email[256];
30 realname = silc_get_real_name();
33 hostname = silc_net_localhost();
37 /* Get username (mandatory) */
38 username = silc_get_username();
42 /* Create default email address, whether it is right or not */
43 snprintf(email, sizeof(email), "%s@%s", username, hostname);
45 ident = silc_pkcs_encode_identifier(username, hostname, realname, email,
55 /* Generate key pair */
57 bool silc_create_key_pair(const char *pkcs_name,
58 SilcUInt32 key_len_bits,
59 const char *pub_filename,
60 const char *prv_filename,
61 const char *pub_identifier,
62 const char *passphrase,
63 SilcPKCS *return_pkcs,
64 SilcPublicKey *return_public_key,
65 SilcPrivateKey *return_private_key,
69 SilcPublicKey pub_key;
70 SilcPrivateKey prv_key;
75 char *pkfile = pub_filename ? strdup(pub_filename) : NULL;
76 char *prvfile = prv_filename ? strdup(prv_filename) : NULL;
77 char *alg = pkcs_name ? strdup(pkcs_name) : NULL;
78 char *identifier = pub_identifier ? strdup(pub_identifier) : NULL;
79 char *pass = passphrase ? strdup(passphrase) : NULL;
81 if (interactive && (!alg || !pub_filename || !prv_filename))
83 New pair of keys will be created. Please, answer to following questions.\n\
89 alg = silc_get_input("PKCS name (l to list names) [rsa]: ", FALSE);
93 if (*alg == 'l' || *alg == 'L') {
94 char *list = silc_pkcs_get_supported();
106 if (!silc_pkcs_is_supported(alg)) {
107 fprintf(stderr, "Unknown PKCS algorithm `%s' or crypto library"
108 "is not initialized", alg);
115 length = silc_get_input("Key length in key_len_bits [2048]: ", FALSE);
117 key_len_bits = atoi(length);
125 char *def = silc_create_pk_identifier();
128 memset(line, 0, sizeof(line));
130 snprintf(line, sizeof(line), "Identifier [%s]: ", def);
132 snprintf(line, sizeof(line),
133 "Identifier (eg. UN=jon, HN=jon.dummy.com, "
134 "RN=Jon Johnson, E=jon@dummy.com): ");
136 while (!identifier) {
137 identifier = silc_get_input(line, FALSE);
138 if (!identifier && def)
139 identifier = strdup(def);
143 fprintf(stderr, "Could not create public key identifier: %s\n",
147 identifier = strdup(def);
153 rng = silc_rng_alloc();
155 silc_rng_global_init(rng);
159 memset(line, 0, sizeof(line));
160 snprintf(line, sizeof(line), "Public key filename [public_key.pub]: ");
161 pkfile = silc_get_input(line, FALSE);
164 pkfile = strdup("public_key.pub");
169 memset(line, 0, sizeof(line));
170 snprintf(line, sizeof(line), "Private key filename [private_key.prv]: ");
171 prvfile = silc_get_input(line, FALSE);
174 prvfile = strdup("private_key.prv");
179 pass = silc_get_input("Private key passphrase: ", TRUE);
185 pass2 = silc_get_input("Retype private key passphrase: ", TRUE);
188 if (!strcmp(pass, pass2))
190 fprintf(stderr, "\nPassphrases do not match");
197 silc_pkcs_alloc(alg, &pkcs);
198 silc_pkcs_generate_key(pkcs, key_len_bits, rng);
200 /* Save public key into file */
201 key = silc_pkcs_get_public_key(pkcs, &key_len);
202 pub_key = silc_pkcs_public_key_alloc(silc_pkcs_get_name(pkcs),
203 identifier, key, key_len);
204 silc_pkcs_save_public_key(pkfile, pub_key, SILC_PKCS_FILE_PEM);
205 if (return_public_key)
206 *return_public_key = pub_key;
208 silc_pkcs_public_key_free(pub_key);
209 memset(key, 0, key_len);
212 /* Save private key into file */
213 key = silc_pkcs_get_private_key(pkcs, &key_len);
214 prv_key = silc_pkcs_private_key_alloc(silc_pkcs_get_name(pkcs),
216 silc_pkcs_save_private_key(prvfile, prv_key,
217 (unsigned char *)pass, strlen(pass),
219 if (return_private_key)
220 *return_private_key = prv_key;
222 silc_pkcs_private_key_free(prv_key);
223 memset(key, 0, key_len);
226 printf("Public key has been saved into `%s'.\n", pkfile);
227 printf("Private key has been saved into `%s'.\n", prvfile);
229 printf("Press <Enter> to continue...\n");
236 silc_pkcs_free(pkcs);
242 silc_free(identifier);
243 memset(pass, 0, strlen(pass));
251 bool silc_load_key_pair(const char *pub_filename,
252 const char *prv_filename,
253 const char *passphrase,
254 SilcPKCS *return_pkcs,
255 SilcPublicKey *return_public_key,
256 SilcPrivateKey *return_private_key)
258 char *pass = passphrase ? strdup(passphrase) : NULL;
260 SILC_LOG_DEBUG(("Loading public and private keys"));
262 if (silc_pkcs_load_public_key((char *)pub_filename, return_public_key,
263 SILC_PKCS_FILE_PEM) == FALSE)
264 if (silc_pkcs_load_public_key((char *)pub_filename, return_public_key,
265 SILC_PKCS_FILE_BIN) == FALSE) {
267 memset(pass, 0, strlen(pass));
273 pass = silc_get_input("Private key passphrase: ", TRUE);
278 if (silc_pkcs_load_private_key((char *)prv_filename, return_private_key,
279 (unsigned char *)pass, strlen(pass),
280 SILC_PKCS_FILE_BIN) == FALSE)
281 if (silc_pkcs_load_private_key((char *)prv_filename, return_private_key,
282 (unsigned char *)pass, strlen(pass),
283 SILC_PKCS_FILE_PEM) == FALSE) {
284 memset(pass, 0, strlen(pass));
290 silc_pkcs_alloc((*return_public_key)->name, return_pkcs);
291 silc_pkcs_public_key_set(*return_pkcs, *return_public_key);
292 silc_pkcs_private_key_set(*return_pkcs, *return_private_key);
295 memset(pass, 0, strlen(pass));
300 /* Dump public key into stdout */
302 bool silc_show_public_key(const char *pub_filename)
304 SilcPublicKey public_key;
305 SilcPublicKeyIdentifier ident;
306 char *fingerprint, *babbleprint;
310 SilcUInt32 key_len = 0;
312 if (silc_pkcs_load_public_key((char *)pub_filename, &public_key,
313 SILC_PKCS_FILE_PEM) == FALSE)
314 if (silc_pkcs_load_public_key((char *)pub_filename, &public_key,
315 SILC_PKCS_FILE_BIN) == FALSE) {
316 fprintf(stderr, "Could not load public key file `%s'\n", pub_filename);
320 ident = silc_pkcs_decode_identifier(public_key->identifier);
322 pk = silc_pkcs_public_key_encode(public_key, &pk_len);
323 fingerprint = silc_hash_fingerprint(NULL, pk, pk_len);
324 babbleprint = silc_hash_babbleprint(NULL, pk, pk_len);
326 if (silc_pkcs_alloc(public_key->name, &pkcs)) {
327 key_len = silc_pkcs_public_key_set(pkcs, public_key);
328 silc_pkcs_free(pkcs);
331 printf("Public key file : %s\n", pub_filename);
332 printf("Algorithm : %s\n", public_key->name);
334 printf("Key length (bits) : %d\n", (unsigned int)key_len);
336 printf("Real name : %s\n", ident->realname);
338 printf("Username : %s\n", ident->username);
340 printf("Hostname : %s\n", ident->host);
342 printf("Email : %s\n", ident->email);
344 printf("Organization : %s\n", ident->org);
346 printf("Country : %s\n", ident->country);
347 printf("Fingerprint (SHA1) : %s\n", fingerprint);
348 printf("Babbleprint (SHA1) : %s\n", babbleprint);
352 silc_free(fingerprint);
353 silc_free(babbleprint);
355 silc_pkcs_public_key_free(public_key);
356 silc_pkcs_free_identifier(ident);
361 /* Change private key passphrase */
363 bool silc_change_private_key_passphrase(const char *prv_filename,
364 const char *old_passphrase,
365 const char *new_passphrase)
367 SilcPrivateKey private_key;
371 pass = old_passphrase ? strdup(old_passphrase) : NULL;
373 pass = silc_get_input("Old passphrase: ", TRUE);
378 if (silc_pkcs_load_private_key((char *)prv_filename, &private_key,
379 (unsigned char *)pass, strlen(pass),
380 SILC_PKCS_FILE_BIN) == FALSE) {
382 if (silc_pkcs_load_private_key((char *)prv_filename, &private_key,
383 (unsigned char *)pass, strlen(pass),
384 SILC_PKCS_FILE_PEM) == FALSE) {
385 memset(pass, 0, strlen(pass));
387 fprintf(stderr, "Could not load private key `%s' file\n", prv_filename);
392 memset(pass, 0, strlen(pass));
395 pass = new_passphrase ? strdup(new_passphrase) : NULL;
398 fprintf(stdout, "\n");
399 pass = silc_get_input("New passphrase: ", TRUE);
405 pass2 = silc_get_input("Retype new passphrase: ", TRUE);
408 if (!strcmp(pass, pass2))
410 fprintf(stderr, "\nPassphrases do not match");
416 silc_pkcs_save_private_key((char *)prv_filename, private_key,
417 (unsigned char *)pass, strlen(pass),
418 base64 ? SILC_PKCS_FILE_PEM : SILC_PKCS_FILE_BIN);
420 fprintf(stdout, "\nPassphrase changed\n");
422 memset(pass, 0, strlen(pass));
425 silc_pkcs_private_key_free(private_key);