/* Extract X.509 certificate in DER form from PKCS#11 or PEM. * * Copyright © 2014-2015 Red Hat, Inc. All Rights Reserved. * Copyright © 2015 Intel Corporation. * * Authors: David Howells <dhowells@redhat.com> * David Woodhouse <dwmw2@infradead.org> * * This program is free software; you can redistribute it and/or * modify it under the terms of the GNU Lesser General Public License * as published by the Free Software Foundation; either version 2.1 * of the licence, or (at your option) any later version. */ #define _GNU_SOURCE #include <stdio.h> #include <stdlib.h> #include <stdint.h> #include <stdbool.h> #include <string.h> #include <err.h> #include <openssl/bio.h> #include <openssl/pem.h> #include <openssl/err.h> #include <openssl/engine.h> /* * OpenSSL 3.0 deprecates the OpenSSL's ENGINE API. * * Remove this if/when that API is no longer used */ #pragma GCC diagnostic ignored "-Wdeprecated-declarations" #define PKEY_ID_PKCS7 2 static __attribute__((noreturn)) void format(void) { fprintf(stderr, "Usage: scripts/extract-cert <source> <dest>\n"); exit(2); } static void display_openssl_errors(int l) { const char *file; char buf[120]; int e, line; if (ERR_peek_error() == 0) return; fprintf(stderr, "At main.c:%d:\n", l); while ((e = ERR_get_error_line(&file, &line))) { ERR_error_string(e, buf); fprintf(stderr, "- SSL %s: %s:%d\n", buf, file, line); } } static void drain_openssl_errors(void) { const char *file; int line; if (ERR_peek_error() == 0) return; while (ERR_get_error_line(&file, &line)) {} } #define ERR(cond, fmt, ...) \ do { \ bool __cond = (cond); \ display_openssl_errors(__LINE__); \ if (__cond) { \ err(1, fmt, ## __VA_ARGS__); \ } \ } while(0) static const char *key_pass; static BIO *wb; static char *cert_dst; static int kbuild_verbose; static void write_cert(X509 *x509) { char buf[200]; if (!wb) { wb = BIO_new_file(cert_dst, "wb"); ERR(!wb, "%s", cert_dst); } X509_NAME_oneline(X509_get_subject_name(x509), buf, sizeof(buf)); ERR(!i2d_X509_bio(wb, x509), "%s", cert_dst); if (kbuild_verbose) fprintf(stderr, "Extracted cert: %s\n", buf); } int main(int argc, char **argv) { char *cert_src; OpenSSL_add_all_algorithms(); ERR_load_crypto_strings(); ERR_clear_error(); kbuild_verbose = atoi(getenv("KBUILD_VERBOSE")?:"0"); key_pass = getenv("KBUILD_SIGN_PIN"); if (argc != 3) format(); cert_src = argv[1]; cert_dst = argv[2]; if (!cert_src[0]) { /* Invoked with no input; create empty file */ FILE *f = fopen(cert_dst, "wb"); ERR(!f, "%s", cert_dst); fclose(f); exit(0); } else if (!strncmp(cert_src, "pkcs11:", 7)) { ENGINE *e; struct { const char *cert_id; X509 *cert; } parms; parms.cert_id = cert_src; parms.cert = NULL; ENGINE_load_builtin_engines(); drain_openssl_errors(); e = ENGINE_by_id("pkcs11"); ERR(!e, "Load PKCS#11 ENGINE"); if (ENGINE_init(e)) drain_openssl_errors(); else ERR(1, "ENGINE_init"); if (key_pass) ERR(!ENGINE_ctrl_cmd_string(e, "PIN", key_pass, 0), "Set PKCS#11 PIN"); ENGINE_ctrl_cmd(e, "LOAD_CERT_CTRL", 0, &parms, NULL, 1); ERR(!parms.cert, "Get X.509 from PKCS#11"); write_cert(parms.cert); } else { BIO *b; X509 *x509; b = BIO_new_file(cert_src, "rb"); ERR(!b, "%s", cert_src); while (1) { x509 = PEM_read_bio_X509(b, NULL, NULL, NULL); if (wb && !x509) { unsigned long err = ERR_peek_last_error(); if (ERR_GET_LIB(err) == ERR_LIB_PEM && ERR_GET_REASON(err) == PEM_R_NO_START_LINE) { ERR_clear_error(); break; } } ERR(!x509, "%s", cert_src); write_cert(x509); } } BIO_free(wb); return 0; }
Name | Type | Size | Permission | Actions |
---|---|---|---|---|
atomic | Folder | 0755 |
|
|
basic | Folder | 0755 |
|
|
clang-tools | Folder | 0755 |
|
|
coccinelle | Folder | 0755 |
|
|
dtc | Folder | 0755 |
|
|
dummy-tools | Folder | 0755 |
|
|
gcc-plugins | Folder | 0755 |
|
|
gdb | Folder | 0755 |
|
|
genksyms | Folder | 0755 |
|
|
kconfig | Folder | 0755 |
|
|
ksymoops | Folder | 0755 |
|
|
mod | Folder | 0755 |
|
|
package | Folder | 0755 |
|
|
selinux | Folder | 0755 |
|
|
tracing | Folder | 0755 |
|
|
.asn1_compiler.cmd | File | 726 B | 0644 |
|
.bin2c.cmd | File | 421 B | 0644 |
|
.extract-cert.cmd | File | 499 B | 0644 |
|
.insert-sys-cert.cmd | File | 521 B | 0644 |
|
.kallsyms.cmd | File | 451 B | 0644 |
|
.sign-file.cmd | File | 469 B | 0644 |
|
.sorttable.cmd | File | 782 B | 0644 |
|
Kbuild.include | File | 10.15 KB | 0644 |
|
Kconfig.include | File | 2.56 KB | 0644 |
|
Lindent | File | 502 B | 0755 |
|
Makefile | File | 1.64 KB | 0644 |
|
Makefile.asm-generic | File | 1.82 KB | 0644 |
|
Makefile.build | File | 19.66 KB | 0644 |
|
Makefile.clang | File | 1.59 KB | 0644 |
|
Makefile.clean | File | 2.2 KB | 0644 |
|
Makefile.compiler | File | 2.54 KB | 0644 |
|
Makefile.dtbinst | File | 1007 B | 0644 |
|
Makefile.extrawarn | File | 2.99 KB | 0644 |
|
Makefile.gcc-plugins | File | 2.71 KB | 0644 |
|
Makefile.headersinst | File | 2.88 KB | 0644 |
|
Makefile.host | File | 4.63 KB | 0644 |
|
Makefile.kasan | File | 1.67 KB | 0644 |
|
Makefile.kcov | File | 333 B | 0644 |
|
Makefile.kcsan | File | 739 B | 0644 |
|
Makefile.lib | File | 18.02 KB | 0644 |
|
Makefile.modfinal | File | 2.73 KB | 0644 |
|
Makefile.modinst | File | 2.51 KB | 0644 |
|
Makefile.modpost | File | 4.37 KB | 0644 |
|
Makefile.package | File | 6.61 KB | 0644 |
|
Makefile.ubsan | File | 770 B | 0644 |
|
Makefile.userprogs | File | 1.57 KB | 0644 |
|
adjust_autoksyms.sh | File | 2.07 KB | 0755 |
|
as-version.sh | File | 2.02 KB | 0755 |
|
asn1_compiler | File | 35.11 KB | 0755 |
|
asn1_compiler.c | File | 35.33 KB | 0644 |
|
bin2c | File | 16.44 KB | 0755 |
|
bin2c.c | File | 743 B | 0644 |
|
bloat-o-meter | File | 3.36 KB | 0755 |
|
bootgraph.pl | File | 5.64 KB | 0755 |
|
bpf_doc.py | File | 24.98 KB | 0755 |
|
cc-can-link.sh | File | 166 B | 0755 |
|
cc-version.sh | File | 1.51 KB | 0755 |
|
check-sysctl-docs | File | 4.37 KB | 0755 |
|
check_extable.sh | File | 4.93 KB | 0755 |
|
checkdeclares.pl | File | 1.1 KB | 0755 |
|
checkincludes.pl | File | 1.94 KB | 0755 |
|
checkkconfigsymbols.py | File | 15.75 KB | 0755 |
|
checkpatch.pl | File | 223.75 KB | 0755 |
|
checkstack.pl | File | 5.86 KB | 0755 |
|
checksyscalls.sh | File | 7.42 KB | 0755 |
|
checkversion.pl | File | 2.16 KB | 0755 |
|
cleanfile | File | 3.46 KB | 0755 |
|
cleanpatch | File | 5.06 KB | 0755 |
|
coccicheck | File | 7.89 KB | 0755 |
|
config | File | 4.67 KB | 0755 |
|
const_structs.checkpatch | File | 1009 B | 0644 |
|
decode_stacktrace.sh | File | 7.51 KB | 0755 |
|
decodecode | File | 2.88 KB | 0755 |
|
depmod.sh | File | 1.41 KB | 0755 |
|
dev-needs.sh | File | 6.07 KB | 0755 |
|
diffconfig | File | 4.12 KB | 0755 |
|
documentation-file-ref-check | File | 5.55 KB | 0755 |
|
export_report.pl | File | 4.5 KB | 0755 |
|
extract-cert | File | 17.89 KB | 0755 |
|
extract-cert.c | File | 3.63 KB | 0644 |
|
extract-ikconfig | File | 1.69 KB | 0755 |
|
extract-module-sig.pl | File | 3.66 KB | 0755 |
|
extract-sys-certs.pl | File | 3.75 KB | 0755 |
|
extract-vmlinux | File | 1.66 KB | 0755 |
|
extract_xc3028.pl | File | 44.62 KB | 0755 |
|
faddr2line | File | 8.17 KB | 0755 |
|
file-size.sh | File | 86 B | 0755 |
|
find-unused-docs.sh | File | 1.27 KB | 0755 |
|
gcc-goto.sh | File | 511 B | 0755 |
|
gcc-ld | File | 711 B | 0755 |
|
gcc-x86_32-has-stack-protector.sh | File | 405 B | 0755 |
|
gcc-x86_64-has-stack-protector.sh | File | 195 B | 0755 |
|
gen_autoksyms.sh | File | 1.47 KB | 0755 |
|
gen_ksymdeps.sh | File | 556 B | 0755 |
|
generate_initcall_order.pl | File | 5.95 KB | 0755 |
|
get_abi.pl | File | 15.1 KB | 0755 |
|
get_dvb_firmware | File | 24.54 KB | 0755 |
|
get_feat.pl | File | 14.34 KB | 0755 |
|
get_maintainer.pl | File | 67.13 KB | 0755 |
|
gfp-translate | File | 1.69 KB | 0755 |
|
headerdep.pl | File | 3.5 KB | 0755 |
|
headers_check.pl | File | 3.73 KB | 0755 |
|
headers_install.sh | File | 3.35 KB | 0755 |
|
insert-sys-cert | File | 22.21 KB | 0755 |
|
insert-sys-cert.c | File | 13.08 KB | 0644 |
|
jobserver-exec | File | 2.16 KB | 0755 |
|
kallsyms | File | 22.47 KB | 0755 |
|
kallsyms.c | File | 18.06 KB | 0644 |
|
kernel-doc | File | 68.74 KB | 0755 |
|
ld-version.sh | File | 1.82 KB | 0755 |
|
leaking_addresses.pl | File | 12.8 KB | 0755 |
|
link-vmlinux.sh | File | 10.92 KB | 0755 |
|
makelst | File | 808 B | 0755 |
|
markup_oops.pl | File | 7.92 KB | 0755 |
|
min-tool-version.sh | File | 558 B | 0755 |
|
mkcompile_h | File | 2.48 KB | 0755 |
|
mksysmap | File | 1.34 KB | 0755 |
|
mkuboot.sh | File | 414 B | 0755 |
|
module.lds | File | 597 B | 0644 |
|
module.lds.S | File | 1.65 KB | 0644 |
|
modules-check.sh | File | 427 B | 0755 |
|
nsdeps | File | 1.72 KB | 0644 |
|
objdiff | File | 2.84 KB | 0755 |
|
pahole-flags.sh | File | 749 B | 0755 |
|
pahole-version.sh | File | 269 B | 0755 |
|
parse-maintainers.pl | File | 4.54 KB | 0755 |
|
patch-kernel | File | 9.95 KB | 0755 |
|
profile2linkerlist.pl | File | 414 B | 0755 |
|
prune-kernel | File | 708 B | 0755 |
|
recordmcount.c | File | 16.75 KB | 0644 |
|
recordmcount.h | File | 19.37 KB | 0644 |
|
recordmcount.pl | File | 17.63 KB | 0755 |
|
remove-stale-files | File | 1.3 KB | 0755 |
|
setlocalversion | File | 3.5 KB | 0755 |
|
show_delta | File | 3.01 KB | 0755 |
|
sign-file | File | 26.52 KB | 0755 |
|
sign-file.c | File | 9.93 KB | 0644 |
|
sorttable | File | 21.51 KB | 0755 |
|
sorttable.c | File | 8.74 KB | 0644 |
|
sorttable.h | File | 9.65 KB | 0644 |
|
spdxcheck-test.sh | File | 277 B | 0644 |
|
spdxcheck.py | File | 10.09 KB | 0755 |
|
spelling.txt | File | 31.88 KB | 0644 |
|
sphinx-pre-install | File | 24.45 KB | 0755 |
|
split-man.pl | File | 604 B | 0755 |
|
stackdelta | File | 1.84 KB | 0755 |
|
stackusage | File | 794 B | 0755 |
|
subarch.include | File | 619 B | 0644 |
|
syscallhdr.sh | File | 1.89 KB | 0755 |
|
syscallnr.sh | File | 1.45 KB | 0755 |
|
syscalltbl.sh | File | 1.45 KB | 0755 |
|
tags.sh | File | 9.87 KB | 0755 |
|
tools-support-relr.sh | File | 546 B | 0755 |
|
ubuntu-retpoline-extract-one | File | 7.26 KB | 0644 |
|
unifdef.c | File | 34.8 KB | 0644 |
|
ver_linux | File | 2.59 KB | 0755 |
|
xen-hypercalls.sh | File | 386 B | 0755 |
|
xz_wrap.sh | File | 563 B | 0755 |
|