5 Author: Pekka Riikonen <priikone@silcnet.org>
7 Copyright (C) 2002 Pekka Riikonen
9 This program is free software; you can redistribute it and/or modify
10 it under the terms of the GNU General Public License as published by
11 the Free Software Foundation; version 2 of the License.
13 This program is distributed in the hope that it will be useful,
14 but WITHOUT ANY WARRANTY; without even the implied warranty of
15 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 GNU General Public License for more details.
21 #include "silcincludes.h"
23 static char *silc_create_pk_identifier(void)
25 char *username = NULL, *realname = NULL;
26 char *hostname, email[256];
30 realname = silc_get_real_name();
33 hostname = silc_net_localhost();
37 /* Get username (mandatory) */
38 username = silc_get_username();
42 /* Create default email address, whether it is right or not */
43 snprintf(email, sizeof(email), "%s@%s", username, hostname);
45 ident = silc_pkcs_encode_identifier(username, hostname, realname, email,
55 /* Generate key pair */
57 bool silc_create_key_pair(const char *pkcs_name,
58 SilcUInt32 key_len_bits,
59 const char *pub_filename,
60 const char *prv_filename,
61 const char *pub_identifier,
62 const char *passphrase,
63 SilcPKCS *return_pkcs,
64 SilcPublicKey *return_public_key,
65 SilcPrivateKey *return_private_key,
69 SilcPublicKey pub_key;
70 SilcPrivateKey prv_key;
75 char *pkfile = pub_filename ? strdup(pub_filename) : NULL;
76 char *prvfile = prv_filename ? strdup(prv_filename) : NULL;
77 char *alg = pkcs_name ? strdup(pkcs_name) : NULL;
78 char *identifier = pub_identifier ? strdup(pub_identifier) : NULL;
79 char *pass = passphrase ? strdup(passphrase) : NULL;
81 if (interactive && (!alg || !pub_filename || !prv_filename))
83 New pair of keys will be created. Please, answer to following questions.\n\
89 alg = silc_get_input("PKCS name (l to list names) [rsa]: ", FALSE);
93 if (*alg == 'l' || *alg == 'L') {
94 char *list = silc_pkcs_get_supported();
106 if (!silc_pkcs_is_supported(alg)) {
107 fprintf(stderr, "Unknown PKCS algorithm `%s' or crypto library"
108 "is not initialized", alg);
115 length = silc_get_input("Key length in key_len_bits [2048]: ", FALSE);
117 key_len_bits = atoi(length);
125 char *def = silc_create_pk_identifier();
128 memset(line, 0, sizeof(line));
130 snprintf(line, sizeof(line), "Identifier [%s]: ", def);
132 snprintf(line, sizeof(line),
133 "Identifier (eg. UN=jon, HN=jon.dummy.com, "
134 "RN=Jon Johnson, E=jon@dummy.com): ");
136 while (!identifier) {
137 identifier = silc_get_input(line, FALSE);
138 if (!identifier && def)
139 identifier = strdup(def);
143 fprintf(stderr, "Could not create public key identifier: %s\n",
147 identifier = strdup(def);
153 rng = silc_rng_alloc();
155 silc_rng_global_init(rng);
159 memset(line, 0, sizeof(line));
160 snprintf(line, sizeof(line), "Public key filename [public_key.pub]: ");
161 pkfile = silc_get_input(line, FALSE);
164 pkfile = strdup("public_key.pub");
169 memset(line, 0, sizeof(line));
170 snprintf(line, sizeof(line), "Private key filename [private_key.prv]: ");
171 prvfile = silc_get_input(line, FALSE);
174 prvfile = strdup("private_key.prv");
179 pass = silc_get_input("Private key passphrase: ", TRUE);
185 pass2 = silc_get_input("Retype private key passphrase: ", TRUE);
186 if (!strcmp(pass, pass2))
188 fprintf(stderr, "\nPassphrases do not match");
195 silc_pkcs_alloc(alg, &pkcs);
196 silc_pkcs_generate_key(pkcs, key_len_bits, rng);
198 /* Save public key into file */
199 key = silc_pkcs_get_public_key(pkcs, &key_len);
200 pub_key = silc_pkcs_public_key_alloc(silc_pkcs_get_name(pkcs),
201 identifier, key, key_len);
202 silc_pkcs_save_public_key(pkfile, pub_key, SILC_PKCS_FILE_PEM);
203 if (return_public_key)
204 *return_public_key = pub_key;
206 silc_pkcs_public_key_free(pub_key);
207 memset(key, 0, key_len);
210 /* Save private key into file */
211 key = silc_pkcs_get_private_key(pkcs, &key_len);
212 prv_key = silc_pkcs_private_key_alloc(silc_pkcs_get_name(pkcs),
214 silc_pkcs_save_private_key(prvfile, prv_key,
215 (unsigned char *)pass, strlen(pass),
217 if (return_private_key)
218 *return_private_key = prv_key;
220 silc_pkcs_private_key_free(prv_key);
221 memset(key, 0, key_len);
224 printf("Public key has been saved into `%s'.\n", pkfile);
225 printf("Private key has been saved into `%s'.\n", prvfile);
227 printf("Press <Enter> to continue...\n");
234 silc_pkcs_free(pkcs);
240 silc_free(identifier);
241 memset(pass, 0, strlen(pass));
249 bool silc_load_key_pair(const char *pub_filename,
250 const char *prv_filename,
251 const char *passphrase,
252 SilcPKCS *return_pkcs,
253 SilcPublicKey *return_public_key,
254 SilcPrivateKey *return_private_key)
256 char *pass = passphrase ? strdup(passphrase) : NULL;
258 SILC_LOG_DEBUG(("Loading public and private keys"));
260 if (silc_pkcs_load_public_key((char *)pub_filename, return_public_key,
261 SILC_PKCS_FILE_PEM) == FALSE)
262 if (silc_pkcs_load_public_key((char *)pub_filename, return_public_key,
263 SILC_PKCS_FILE_BIN) == FALSE) {
265 memset(pass, 0, strlen(pass));
271 pass = silc_get_input("Private key passphrase: ", TRUE);
276 if (silc_pkcs_load_private_key((char *)prv_filename, return_private_key,
277 (unsigned char *)pass, strlen(pass),
278 SILC_PKCS_FILE_BIN) == FALSE)
279 if (silc_pkcs_load_private_key((char *)prv_filename, return_private_key,
280 (unsigned char *)pass, strlen(pass),
281 SILC_PKCS_FILE_PEM) == FALSE) {
282 memset(pass, 0, strlen(pass));
288 silc_pkcs_alloc((*return_public_key)->name, return_pkcs);
289 silc_pkcs_public_key_set(*return_pkcs, *return_public_key);
290 silc_pkcs_private_key_set(*return_pkcs, *return_private_key);
293 memset(pass, 0, strlen(pass));
298 /* Dump public key into stdout */
300 bool silc_show_public_key(const char *pub_filename)
302 SilcPublicKey public_key;
303 SilcPublicKeyIdentifier ident;
304 char *fingerprint, *babbleprint;
308 SilcUInt32 key_len = 0;
310 if (silc_pkcs_load_public_key((char *)pub_filename, &public_key,
311 SILC_PKCS_FILE_PEM) == FALSE)
312 if (silc_pkcs_load_public_key((char *)pub_filename, &public_key,
313 SILC_PKCS_FILE_BIN) == FALSE) {
314 fprintf(stderr, "Could not load public key file `%s'\n", pub_filename);
318 ident = silc_pkcs_decode_identifier(public_key->identifier);
320 pk = silc_pkcs_public_key_encode(public_key, &pk_len);
321 fingerprint = silc_hash_fingerprint(NULL, pk, pk_len);
322 babbleprint = silc_hash_babbleprint(NULL, pk, pk_len);
324 if (silc_pkcs_alloc(public_key->name, &pkcs)) {
325 key_len = silc_pkcs_public_key_set(pkcs, public_key);
326 silc_pkcs_free(pkcs);
329 printf("Public key file : %s\n", pub_filename);
330 printf("Algorithm : %s\n", public_key->name);
332 printf("Key length (bits) : %d\n", (unsigned int)key_len);
334 printf("Real name : %s\n", ident->realname);
336 printf("Username : %s\n", ident->username);
338 printf("Hostname : %s\n", ident->host);
340 printf("Email : %s\n", ident->email);
342 printf("Organization : %s\n", ident->org);
344 printf("Country : %s\n", ident->country);
345 printf("Fingerprint (SHA1) : %s\n", fingerprint);
346 printf("Babbleprint (SHA1) : %s\n", babbleprint);
350 silc_free(fingerprint);
351 silc_free(babbleprint);
353 silc_pkcs_public_key_free(public_key);
354 silc_pkcs_free_identifier(ident);
359 /* Change private key passphrase */
361 bool silc_change_private_key_passphrase(const char *prv_filename,
362 const char *old_passphrase,
363 const char *new_passphrase)
365 SilcPrivateKey private_key;
369 pass = old_passphrase ? strdup(old_passphrase) : NULL;
371 pass = silc_get_input("Old passphrase: ", TRUE);
376 if (silc_pkcs_load_private_key((char *)prv_filename, &private_key,
377 (unsigned char *)pass, strlen(pass),
378 SILC_PKCS_FILE_BIN) == FALSE) {
380 if (silc_pkcs_load_private_key((char *)prv_filename, &private_key,
381 (unsigned char *)pass, strlen(pass),
382 SILC_PKCS_FILE_PEM) == FALSE) {
383 memset(pass, 0, strlen(pass));
385 fprintf(stderr, "Could not load private key `%s' file\n", prv_filename);
390 memset(pass, 0, strlen(pass));
393 pass = new_passphrase ? strdup(new_passphrase) : NULL;
396 fprintf(stdout, "\n");
397 pass = silc_get_input("New passphrase: ", TRUE);
403 pass2 = silc_get_input("Retype new passphrase: ", TRUE);
404 if (!strcmp(pass, pass2))
406 fprintf(stderr, "\nPassphrases do not match");
412 silc_pkcs_save_private_key((char *)prv_filename, private_key,
413 (unsigned char *)pass, strlen(pass),
414 base64 ? SILC_PKCS_FILE_PEM : SILC_PKCS_FILE_BIN);
416 fprintf(stdout, "\nPassphrase changed\n");
418 memset(pass, 0, strlen(pass));
421 silc_pkcs_private_key_free(private_key);