create.c revision 269e59f9a28bf47e0f463e64fc5af4a408b73b21
/*
* CDDL HEADER START
*
* The contents of this file are subject to the terms of the
* Common Development and Distribution License (the "License").
* You may not use this file except in compliance with the License.
*
* You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
* See the License for the specific language governing permissions
* and limitations under the License.
*
* When distributing Covered Code, include this CDDL HEADER in each
* file and include the License file at usr/src/OPENSOLARIS.LICENSE.
* If applicable, add the following below this CDDL HEADER, with the
* fields enclosed by brackets "[]" replaced with your own identifying
* information: Portions Copyright [yyyy] [name of copyright owner]
*
* CDDL HEADER END
*
*/
#include <stdio.h>
#include <strings.h>
#include <ctype.h>
#include <libgen.h>
#include <libintl.h>
#include <errno.h>
#include <kmfapiP.h>
#include <cryptoutil.h>
#include "util.h"
int
{
int opt;
extern int optind_av;
extern char *optarg_av;
int ocsp_set_attr = 0;
boolean_t crl_set_attr = 0;
"i:(dbfile)"
"p:(policy)"
"d:(ignore-date)"
"e:(ignore-unknown-eku)"
"a:(ignore-trust-anchor)"
"v:(validity-adjusttime)"
"t:(ta-name)"
"s:(ta-serial)"
"o:(ocsp-responder)"
"P:(ocsp-proxy)"
"r:(ocsp-use-cert-responder)"
"T:(ocsp-response-lifetime)"
"R:(ocsp-ignore-response-sign)"
"n:(ocsp-responder-cert-name)"
"A:(ocsp-responder-cert-serial)"
"c:(crl-basefilename)"
"I:(crl-directory)"
"g:(crl-get-crl-uri)"
"X:(crl-proxy)"
"S:(crl-ignore-crl-sign)"
"D:(crl-ignore-crl-date)"
"m:(mapper-name)"
"M:(mapper-directory)"
"Q:(mapper-pathname)"
"q:(mapper-options)"
"u:(keyusage)"
"E:(ekunames)"
"O:(ekuoids)")) != EOF) {
switch (opt) {
case 'i':
gettext("Error dbfile input.\n"));
}
break;
case 'p':
gettext("Error policy name.\n"));
}
break;
case 'd':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
}
break;
case 'e':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
}
break;
case 'a':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
}
break;
case 'v':
gettext("Error time input.\n"));
} else {
/* for syntax checking */
if (str2lifetime(
&adj) < 0) {
gettext("Error time "
"input.\n"));
rv = KC_ERR_USAGE;
}
}
break;
case 't':
gettext("Error name input.\n"));
} else {
/* for syntax checking */
gettext("Error name "
"input.\n"));
rv = KC_ERR_USAGE;
} else {
kmf_free_dn(&taDN);
}
}
break;
case 's':
gettext("Error serial input.\n"));
} else {
gettext("serial number "
"must be specified as a "
"hex number "
"(ex: 0x0102030405"
"ffeeddee)\n"));
rv = KC_ERR_USAGE;
}
}
break;
case 'o':
"Error responder input.\n"));
} else {
}
break;
case 'P':
gettext("Error proxy input.\n"));
} else {
}
break;
case 'r':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
} else {
}
break;
case 'T':
gettext("Error time input.\n"));
} else {
/* for syntax checking */
if (str2lifetime(
&adj) < 0) {
gettext("Error time "
"input.\n"));
rv = KC_ERR_USAGE;
} else {
}
}
break;
case 'R':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
} else {
}
break;
case 'n':
gettext("Error name input.\n"));
} else {
/* for syntax checking */
if (kmf_dn_parser(
gettext("Error name "
"input.\n"));
rv = KC_ERR_USAGE;
} else {
}
}
break;
case 'A':
gettext("Error serial input.\n"));
} else {
gettext("serial number "
"must be specified as a "
"hex number "
"(ex: 0x0102030405"
"ffeeddee)\n"));
rv = KC_ERR_USAGE;
break;
}
}
break;
case 'c':
gettext("Error boolean input.\n"));
} else {
crl_set_attr++;
}
break;
case 'I':
gettext("Error boolean input.\n"));
} else {
crl_set_attr++;
}
break;
case 'g':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
} else {
crl_set_attr++;
}
break;
case 'X':
gettext("Error proxy input.\n"));
} else {
crl_set_attr++;
}
break;
case 'S':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
} else {
crl_set_attr++;
}
break;
case 'D':
gettext("Error boolean input.\n"));
rv = KC_ERR_USAGE;
} else {
crl_set_attr++;
}
break;
case 'u':
"Error keyusage input.\n"));
rv = KC_ERR_USAGE;
}
break;
case 'E':
gettext("Error EKU input.\n"));
rv = KC_ERR_USAGE;
}
break;
case 'O':
gettext("Error EKU OID input.\n"));
rv = KC_ERR_USAGE;
}
break;
case 'm':
gettext("Error mapper-name "
"input.\n"));
}
break;
case 'M':
gettext("Error mapper-dir "
"input.\n"));
}
break;
case 'Q':
&rv);
gettext("Error mapper-pathname "
"input.\n"));
}
break;
case 'q':
gettext("Error mapper-options "
"input.\n"));
}
break;
default:
gettext("Error input option.\n"));
rv = KC_ERR_USAGE;
break;
}
goto out;
}
/* No additional args allowed. */
if (argc) {
gettext("Error input option\n"));
rv = KC_ERR_USAGE;
goto out;
}
rv = KC_ERR_MEMORY;
goto out;
}
}
/*
* Must have a policy name. The policy name can not be default
* if using the default policy file.
*/
gettext("You must specify a policy name\n"));
rv = KC_ERR_USAGE;
goto out;
gettext("Can not create a default policy in the default "
"policy file\n"));
rv = KC_ERR_USAGE;
goto out;
}
/*
* If the policy file exists and the policy is in the policy file
* already, we will not create it again.
*/
int found = 0;
goto out;
found++;
}
if (found) {
gettext("Could not create policy \"%s\" - exists "
rv = KC_ERR_USAGE;
goto out;
}
}
/*
* If any OCSP attribute is set, turn on the OCSP checking flag.
* Also set "has_resp_cert" to be true, if the responder cert
* is provided.
*/
if (ocsp_set_attr > 0)
}
/*
* Setting mapper-name (with optional mapper-dir) and mapper-pathname is
* mutually exclusive. Also, you cannot set options only, you need the
* name or pathname, and you can set the directory only with the name,
* not the pathname.
*/
gettext("Error in mapper input options\n"));
rv = KC_ERR_USAGE;
goto out;
}
/*
* If any CRL attribute is set, turn on the CRL checking flag.
*/
if (crl_set_attr > 0)
/*
* Does a sanity check on the new policy.
*/
goto out;
}
/*
* Add to the DB.
*/
}
out:
return (rv);
}