Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 1 | /* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */ |
swa770 | 20643ac | 2020-03-26 02:24:45 -0700 | [diff] [blame] | 2 | /** |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 3 | * Copyright (c) 2017-2020, Regents of the University of California. |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 4 | * |
| 5 | * This file is part of ndncert, a certificate management system based on NDN. |
| 6 | * |
| 7 | * ndncert is free software: you can redistribute it and/or modify it under the terms |
| 8 | * of the GNU General Public License as published by the Free Software Foundation, either |
| 9 | * version 3 of the License, or (at your option) any later version. |
| 10 | * |
| 11 | * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY |
| 12 | * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A |
| 13 | * PARTICULAR PURPOSE. See the GNU General Public License for more details. |
| 14 | * |
| 15 | * You should have received copies of the GNU General Public License along with |
| 16 | * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>. |
| 17 | * |
| 18 | * See AUTHORS.md for complete list of ndncert authors and contributors. |
| 19 | */ |
| 20 | |
Zhiyi Zhang | dbd9d43 | 2020-10-07 15:56:27 -0700 | [diff] [blame] | 21 | #include "identity-challenge/challenge-module.hpp" |
Zhiyi Zhang | c87d52b | 2020-09-28 22:07:18 -0700 | [diff] [blame] | 22 | #include "protocol-detail/info.hpp" |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 23 | #include "requester.hpp" |
Zhiyi Zhang | 90c7578 | 2020-10-06 15:04:03 -0700 | [diff] [blame] | 24 | #include <ndn-cxx/security/verification-helpers.hpp> |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 25 | #include <boost/asio.hpp> |
Davide Pesavento | b48bbda | 2020-07-27 19:41:37 -0400 | [diff] [blame] | 26 | #include <boost/program_options/options_description.hpp> |
| 27 | #include <boost/program_options/parsers.hpp> |
| 28 | #include <boost/program_options/variables_map.hpp> |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 29 | #include <iostream> |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 30 | #include <string> |
| 31 | |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 32 | namespace ndn { |
| 33 | namespace ndncert { |
| 34 | |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 35 | static void |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 36 | selectCaProfile(std::string configFilePath); |
| 37 | static void |
| 38 | runProbe(CaProfile profile); |
| 39 | static void |
| 40 | runNew(CaProfile profile, Name identityName); |
| 41 | static void |
| 42 | runChallenge(const std::string& challengeType); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 43 | |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 44 | size_t nStep = 1; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 45 | Face face; |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 46 | security::KeyChain keyChain; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 47 | shared_ptr<RequesterState> requesterState = nullptr; |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 48 | |
Zhiyi Zhang | 4604983 | 2020-09-28 17:08:12 -0700 | [diff] [blame] | 49 | static void |
| 50 | captureParams(std::vector<std::tuple<std::string, std::string>>& requirement) |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 51 | { |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 52 | std::list<std::string> results; |
Zhiyi Zhang | 4604983 | 2020-09-28 17:08:12 -0700 | [diff] [blame] | 53 | for (auto& item : requirement) { |
| 54 | std::cerr << std::get<1>(item) << std::endl; |
| 55 | std::string captured; |
| 56 | getline(std::cin, captured); |
| 57 | std::get<1>(item) = captured; |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 58 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 59 | std::cerr << "Got it. This is what you've provided:" << std::endl; |
Zhiyi Zhang | 4604983 | 2020-09-28 17:08:12 -0700 | [diff] [blame] | 60 | for (const auto& item : requirement) { |
| 61 | std::cerr << std::get<0>(item) << " : " << std::get<1>(item) << std::endl; |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 62 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 63 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 64 | |
Zhiyi Zhang | 9829da9 | 2020-09-30 16:19:34 -0700 | [diff] [blame] | 65 | static std::vector<std::tuple<std::string, std::string>> |
| 66 | captureParams(const std::list<std::string>& requirement) |
Zhiyi Zhang | 547c851 | 2019-06-18 23:46:14 -0700 | [diff] [blame] | 67 | { |
Zhiyi Zhang | 9829da9 | 2020-09-30 16:19:34 -0700 | [diff] [blame] | 68 | std::vector<std::tuple<std::string, std::string>> results; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 69 | for (const auto& r : requirement) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 70 | results.emplace_back(r, "Please input: " + r); |
Zhiyi Zhang | 547c851 | 2019-06-18 23:46:14 -0700 | [diff] [blame] | 71 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 72 | captureParams(results); |
Zhiyi Zhang | 547c851 | 2019-06-18 23:46:14 -0700 | [diff] [blame] | 73 | return results; |
| 74 | } |
| 75 | |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 76 | static int |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 77 | captureValidityPeriod() |
| 78 | { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 79 | std::cerr << "\n***************************************\n" |
| 80 | << "Step " << nStep++ |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 81 | << ": Please type in your expected validity period of your certificate." |
| 82 | << " Type the number of hours (168 for week, 730 for month, 8760 for year)." |
| 83 | << " The CA may reject your application if your expected period is too long." << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 84 | while (true) { |
| 85 | std::string periodStr = ""; |
| 86 | getline(std::cin, periodStr); |
| 87 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 88 | return std::stoul(periodStr); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 89 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 90 | catch (const std::exception& e) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 91 | std::cerr << "Your input is invalid. Try again: " << std::endl; |
| 92 | } |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 93 | } |
| 94 | } |
| 95 | |
| 96 | static void |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 97 | onNackCb() |
| 98 | { |
| 99 | std::cerr << "Got NACK\n"; |
| 100 | } |
| 101 | |
| 102 | static void |
| 103 | timeoutCb() |
| 104 | { |
| 105 | std::cerr << "Interest sent time out\n"; |
| 106 | } |
| 107 | |
| 108 | static void |
swa770 | cf1d8f7 | 2020-04-21 23:12:39 -0700 | [diff] [blame] | 109 | certFetchCb(const Data& reply) |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 110 | { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 111 | auto item = Requester::onCertFetchResponse(reply); |
| 112 | if (item) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 113 | keyChain.addCertificate(keyChain.getPib().getIdentity(item->getIdentity()).getKey(item->getKeyName()), *item); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 114 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 115 | std::cerr << "\n***************************************\n" |
| 116 | << "Step " << nStep++ |
| 117 | << ": DONE\nCertificate with Name: " << reply.getName().toUri() |
| 118 | << "has already been installed to your local keychain" << std::endl |
| 119 | << "Exit now"; |
| 120 | face.getIoService().stop(); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 121 | } |
| 122 | |
| 123 | static void |
| 124 | challengeCb(const Data& reply) |
| 125 | { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 126 | try { |
| 127 | Requester::onChallengeResponse(*requesterState, reply); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 128 | } |
| 129 | catch (const std::exception& e) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 130 | std::cerr << "Error when decoding challenge step: " << e.what() << std::endl; |
| 131 | exit(1); |
| 132 | } |
| 133 | if (requesterState->m_status == Status::SUCCESS) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 134 | std::cerr << "Certificate has already been issued, downloading certificate..." << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 135 | face.expressInterest(*Requester::genCertFetchInterest(*requesterState), bind(&certFetchCb, _2), |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 136 | bind(&onNackCb), bind(&timeoutCb)); |
Zhiyi Zhang | 4d89fe0 | 2017-04-28 18:51:51 -0700 | [diff] [blame] | 137 | return; |
| 138 | } |
| 139 | |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 140 | runChallenge(requesterState->m_challengeType); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 141 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 142 | |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 143 | static void |
| 144 | newCb(const Data& reply) |
| 145 | { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 146 | std::list<std::string> challengeList; |
| 147 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 148 | challengeList = Requester::onNewRenewRevokeResponse(*requesterState, reply); |
| 149 | } |
| 150 | catch (const std::exception& e) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 151 | std::cerr << "Error on decoding NEW step reply because: " << e.what() << std::endl; |
| 152 | exit(1); |
| 153 | } |
| 154 | |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 155 | size_t challengeIndex = 0; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 156 | if (challengeList.size() < 1) { |
| 157 | std::cerr << "There is no available challenge provided by the CA. Exit" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 158 | exit(1); |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 159 | } |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 160 | else if (challengeList.size() > 1) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 161 | std::cerr << "\n***************************************\n" |
| 162 | << "Step " << nStep++ |
| 163 | << ": CHALLENGE SELECTION" << std::endl; |
| 164 | size_t count = 0; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 165 | std::string choice = ""; |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 166 | for (auto item : challengeList) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 167 | std::cerr << "> Index: " << count++ << std::endl |
| 168 | << ">> Challenge:" << item << std::endl; |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 169 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 170 | std::cerr << "Please type in the challenge index that you want to perform:" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 171 | while (true) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 172 | getline(std::cin, choice); |
| 173 | try { |
| 174 | challengeIndex = std::stoul(choice); |
| 175 | } |
| 176 | catch (const std::exception& e) { |
| 177 | std::cerr << "Your input is not valid. Try again:" << std::endl; |
| 178 | continue; |
| 179 | } |
| 180 | if (challengeIndex >= count) { |
| 181 | std::cerr << "Your input index is out of range. Try again:" << std::endl; |
| 182 | continue; |
| 183 | } |
| 184 | break; |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 185 | } |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 186 | } |
| 187 | auto it = challengeList.begin(); |
| 188 | std::advance(it, challengeIndex); |
| 189 | unique_ptr<ChallengeModule> challenge = ChallengeModule::createChallengeModule(*it); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 190 | if (challenge != nullptr) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 191 | std::cerr << "The challenge has been selected: " << *it << std::endl; |
| 192 | runChallenge(*it); |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 193 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 194 | else { |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 195 | std::cerr << "Error. Cannot load selected Challenge Module. Exit." << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 196 | exit(1); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 197 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 198 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 199 | |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 200 | static void |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 201 | InfoCb(const Data& reply, const Name& certFullName) |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 202 | { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 203 | boost::optional<CaProfile> profile; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 204 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 205 | if (certFullName.empty()) { |
| 206 | profile = Requester::onCaProfileResponse(reply); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 207 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 208 | else { |
| 209 | profile = Requester::onCaProfileResponseAfterRedirection(reply, certFullName); |
| 210 | } |
| 211 | } |
| 212 | catch (const std::exception& e) { |
| 213 | std::cerr << "The fetched CA information cannot be used because: " << e.what() << std::endl; |
| 214 | return; |
Zhiyi Zhang | caab546 | 2019-10-18 13:41:02 -0700 | [diff] [blame] | 215 | } |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 216 | std::cerr << "\n***************************************\n" |
| 217 | << "Step " << nStep++ |
| 218 | << ": Will use a new trust anchor, please double check the identity info:" << std::endl |
| 219 | << "> New CA name: " << profile->m_caPrefix.toUri() << std::endl |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 220 | << "> This trust anchor information is signed by: " << reply.getSignatureInfo().getKeyLocator() << std::endl |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 221 | << "> The certificate: " << profile->m_cert << std::endl |
Davide Pesavento | b48bbda | 2020-07-27 19:41:37 -0400 | [diff] [blame] | 222 | << "Do you trust the information? Type in YES or NO" << std::endl; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 223 | |
| 224 | std::string answer; |
| 225 | getline(std::cin, answer); |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 226 | boost::algorithm::to_lower(answer); |
| 227 | if (answer == "yes") { |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 228 | std::cerr << "You answered YES: new CA " << profile->m_caPrefix.toUri() << " will be used" << std::endl; |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 229 | runProbe(*profile); |
Zhiyi Zhang | caab546 | 2019-10-18 13:41:02 -0700 | [diff] [blame] | 230 | // client.getClientConf().save(std::string(SYSCONFDIR) + "/ndncert/client.conf"); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 231 | } |
| 232 | else { |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 233 | std::cerr << "You answered NO: new CA " << profile->m_caPrefix.toUri() << " will not be used" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 234 | exit(0); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 235 | } |
| 236 | } |
| 237 | |
| 238 | static void |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 239 | probeCb(const Data& reply, CaProfile profile) |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 240 | { |
tylerliu | b47dad7 | 2020-10-08 21:36:55 -0700 | [diff] [blame] | 241 | std::vector<std::pair<Name, int>> names; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 242 | std::vector<Name> redirects; |
| 243 | Requester::onProbeResponse(reply, profile, names, redirects); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 244 | size_t count = 0; |
| 245 | std::cerr << "\n***************************************\n" |
| 246 | << "Step " << nStep++ |
| 247 | << ": You can either select one of the following names suggested by the CA: " << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 248 | for (const auto& name : names) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 249 | std::cerr << "> Index: " << count++ << std::endl |
tylerliu | b47dad7 | 2020-10-08 21:36:55 -0700 | [diff] [blame] | 250 | << ">> Suggested name: " << name.first.toUri() << std::endl |
| 251 | << ">> Corresponding Max sufiix length: " << name.second << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 252 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 253 | std::cerr << "\nOr choose another trusted CA suggested by the CA: " << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 254 | for (const auto& redirect : redirects) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 255 | std::cerr << "> Index: " << count++ << std::endl |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 256 | << ">> Suggested CA: " << security::extractIdentityFromCertName(redirect.getPrefix(-1)) << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 257 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 258 | std::cerr << "Please type in the index of your choice:" << std::endl; |
| 259 | size_t index = 0; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 260 | try { |
| 261 | std::string input; |
| 262 | getline(std::cin, input); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 263 | index = std::stoul(input); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 264 | } |
| 265 | catch (const std::exception& e) { |
| 266 | std::cerr << "Your input is Invalid. Exit" << std::endl; |
| 267 | exit(0); |
| 268 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 269 | if (index >= names.size() + redirects.size()) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 270 | std::cerr << "Your input is not an existing index. Exit" << std::endl; |
| 271 | return; |
| 272 | } |
| 273 | if (index < names.size()) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 274 | //names |
tylerliu | b47dad7 | 2020-10-08 21:36:55 -0700 | [diff] [blame] | 275 | std::cerr << "You selected name: " << names[index].first.toUri() << std::endl; |
| 276 | //TODO add prompt to "add suffix" |
| 277 | runNew(profile, names[index].first); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 278 | } |
| 279 | else { |
| 280 | //redirects |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 281 | auto redirectedCaFullName = redirects[index - names.size()]; |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 282 | auto redirectedCaName = security::extractIdentityFromCertName(redirectedCaFullName.getPrefix(-1)); |
Zhiyi Zhang | 696cd04 | 2020-10-07 21:27:36 -0700 | [diff] [blame] | 283 | std::cerr << "You selected to be redirected to CA: " << redirectedCaName.toUri() << std::endl; |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 284 | face.expressInterest( |
Zhiyi Zhang | 696cd04 | 2020-10-07 21:27:36 -0700 | [diff] [blame] | 285 | *Requester::genCaProfileDiscoveryInterest(redirectedCaName), |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 286 | [&](const Interest&, const Data& data) { |
| 287 | auto fetchingInterest = Requester::genCaProfileInterestFromDiscoveryResponse(data); |
| 288 | face.expressInterest(*fetchingInterest, |
| 289 | bind(&InfoCb, _2, redirectedCaFullName), |
| 290 | bind(&onNackCb), |
| 291 | bind(&timeoutCb)); |
| 292 | }, |
| 293 | bind(&onNackCb), |
| 294 | bind(&timeoutCb)); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 295 | } |
| 296 | } |
| 297 | |
| 298 | static void |
| 299 | selectCaProfile(std::string configFilePath) |
| 300 | { |
| 301 | RequesterCaCache caCache; |
| 302 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 303 | caCache.load(configFilePath); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 304 | } |
| 305 | catch (const std::exception& e) { |
| 306 | std::cerr << "Cannot load the configuration file: " << e.what() << std::endl; |
| 307 | exit(1); |
| 308 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 309 | size_t count = 0; |
| 310 | std::cerr << "***************************************\n" |
| 311 | << "Step " << nStep++ << ": CA SELECTION" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 312 | for (auto item : caCache.m_caItems) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 313 | std::cerr << "> Index: " << count++ << std::endl |
| 314 | << ">> CA prefix:" << item.m_caPrefix << std::endl |
| 315 | << ">> Introduction: " << item.m_caInfo << std::endl; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 316 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 317 | std::cerr << "Please type in the CA's index that you want to apply or type in NONE if your expected CA is not in the list:\n"; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 318 | |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 319 | std::string caIndexS, caIndexSLower; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 320 | getline(std::cin, caIndexS); |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 321 | caIndexSLower = caIndexS; |
| 322 | boost::algorithm::to_lower(caIndexSLower); |
| 323 | if (caIndexSLower == "none") { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 324 | std::cerr << "\n***************************************\n" |
| 325 | << "Step " << nStep << ": ADD NEW CA\nPlease type in the CA's Name:" << std::endl; |
Zhiyi Zhang | caab546 | 2019-10-18 13:41:02 -0700 | [diff] [blame] | 326 | std::string expectedCAName; |
| 327 | getline(std::cin, expectedCAName); |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 328 | face.expressInterest( |
| 329 | *Requester::genCaProfileDiscoveryInterest(Name(expectedCAName)), |
| 330 | [&](const Interest&, const Data& data) { |
| 331 | auto fetchingInterest = Requester::genCaProfileInterestFromDiscoveryResponse(data); |
| 332 | face.expressInterest(*fetchingInterest, |
| 333 | bind(&InfoCb, _2, Name()), |
| 334 | bind(&onNackCb), |
| 335 | bind(&timeoutCb)); |
| 336 | }, |
| 337 | bind(&onNackCb), |
| 338 | bind(&timeoutCb)); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 339 | } |
| 340 | else { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 341 | size_t caIndex; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 342 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 343 | caIndex = std::stoul(caIndexS); |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 344 | } |
| 345 | catch (const std::exception& e) { |
| 346 | std::cerr << "Your input is neither NONE nor a valid index. Exit" << std::endl; |
| 347 | return; |
| 348 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 349 | if (caIndex >= count) { |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 350 | std::cerr << "Your input is not an existing index. Exit" << std::endl; |
| 351 | return; |
| 352 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 353 | auto itemIterator = caCache.m_caItems.cbegin(); |
| 354 | std::advance(itemIterator, caIndex); |
| 355 | auto targetCaItem = *itemIterator; |
| 356 | runProbe(targetCaItem); |
| 357 | } |
| 358 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 359 | |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 360 | static void |
| 361 | runProbe(CaProfile profile) |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 362 | { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 363 | std::cerr << "\n***************************************\n" |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 364 | << "Step " << nStep++ |
| 365 | << ": Do you know your identity name to be certified by CA " |
| 366 | << profile.m_caPrefix.toUri() |
| 367 | << " already? Type in YES or NO" << std::endl; |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 368 | bool validAnswer = false; |
| 369 | while (!validAnswer) { |
| 370 | std::string answer; |
| 371 | getline(std::cin, answer); |
| 372 | boost::algorithm::to_lower(answer); |
| 373 | if (answer == "yes") { |
| 374 | validAnswer = true; |
| 375 | std::cerr << "You answered YES" << std::endl; |
| 376 | std::cerr << "\n***************************************\n" |
| 377 | << "Step " << nStep++ |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 378 | << ": Please type in the full identity name you want to get (with CA prefix " |
| 379 | << profile.m_caPrefix.toUri() |
| 380 | << "):" << std::endl; |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 381 | std::string identityNameStr; |
| 382 | getline(std::cin, identityNameStr); |
| 383 | runNew(profile, Name(identityNameStr)); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 384 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 385 | else if (answer == "no") { |
| 386 | validAnswer = true; |
| 387 | std::cerr << "You answered NO" << std::endl; |
| 388 | std::cerr << "\n***************************************\n" |
| 389 | << "Step " << nStep++ << ": Please provide information for name assignment" << std::endl; |
| 390 | auto capturedParams = captureParams(profile.m_probeParameterKeys); |
| 391 | face.expressInterest(*Requester::genProbeInterest(profile, std::move(capturedParams)), |
| 392 | bind(&probeCb, _2, profile), bind(&onNackCb), bind(&timeoutCb)); |
| 393 | } |
| 394 | else { |
| 395 | std::cerr << "Invalid answer. Type in YES or NO" << std::endl; |
| 396 | } |
| 397 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 398 | } |
| 399 | |
| 400 | static void |
| 401 | runNew(CaProfile profile, Name identityName) |
| 402 | { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 403 | int validityPeriod = captureValidityPeriod(); |
| 404 | auto now = time::system_clock::now(); |
| 405 | std::cerr << "The validity period of your certificate will be: " << validityPeriod << " hours" << std::endl; |
Zhiyi Zhang | 3243728 | 2020-10-10 16:15:37 -0700 | [diff] [blame^] | 406 | requesterState =std::make_shared<RequesterState>(keyChain, profile, RequestType::NEW); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 407 | auto interest = Requester::genNewInterest(*requesterState, identityName, now, now + time::hours(validityPeriod)); |
| 408 | if (interest != nullptr) { |
| 409 | face.expressInterest(*interest, bind(&newCb, _2), bind(&onNackCb), bind(&timeoutCb)); |
| 410 | } |
| 411 | else { |
| 412 | std::cerr << "Cannot generate the Interest for NEW step. Exit" << std::endl; |
| 413 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 414 | } |
| 415 | |
| 416 | static void |
| 417 | runChallenge(const std::string& challengeType) |
| 418 | { |
| 419 | auto requirement = Requester::selectOrContinueChallenge(*requesterState, challengeType); |
| 420 | if (requirement.size() > 0) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 421 | std::cerr << "\n***************************************\n" |
| 422 | << "Step " << nStep |
| 423 | << ": Please provide parameters used for Identity Verification Challenge" << std::endl; |
| 424 | captureParams(requirement); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 425 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 426 | face.expressInterest(*Requester::genChallengeInterest(*requesterState, std::move(requirement)), |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 427 | bind(&challengeCb, _2), bind(&onNackCb), bind(&timeoutCb)); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 428 | } |
| 429 | |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 430 | static void |
| 431 | handleSignal(const boost::system::error_code& error, int signalNum) |
| 432 | { |
| 433 | if (error) { |
| 434 | return; |
| 435 | } |
| 436 | const char* signalName = ::strsignal(signalNum); |
| 437 | std::cerr << "Exiting on signal "; |
| 438 | if (signalName == nullptr) { |
| 439 | std::cerr << signalNum; |
| 440 | } |
| 441 | else { |
| 442 | std::cerr << signalName; |
| 443 | } |
| 444 | std::cerr << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 445 | if (requesterState) { |
| 446 | Requester::endSession(*requesterState); |
| 447 | } |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 448 | face.getIoService().stop(); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 449 | exit(1); |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 450 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 451 | |
| 452 | int |
| 453 | main(int argc, char* argv[]) |
| 454 | { |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 455 | boost::asio::signal_set terminateSignals(face.getIoService()); |
| 456 | terminateSignals.add(SIGINT); |
| 457 | terminateSignals.add(SIGTERM); |
| 458 | terminateSignals.async_wait(handleSignal); |
| 459 | |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 460 | namespace po = boost::program_options; |
| 461 | std::string configFilePath = std::string(SYSCONFDIR) + "/ndncert/client.conf"; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 462 | po::options_description description("General Usage\n ndncert-client [-h] [-c] [-v]\n"); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 463 | description.add_options()("help,h", "produce help message")("config-file,c", po::value<std::string>(&configFilePath), "configuration file name"); |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 464 | po::positional_options_description p; |
| 465 | |
| 466 | po::variables_map vm; |
| 467 | try { |
| 468 | po::store(po::command_line_parser(argc, argv).options(description).positional(p).run(), vm); |
| 469 | po::notify(vm); |
| 470 | } |
| 471 | catch (const std::exception& e) { |
| 472 | std::cerr << "ERROR: " << e.what() << std::endl; |
| 473 | return 1; |
| 474 | } |
| 475 | if (vm.count("help") != 0) { |
| 476 | std::cerr << description << std::endl; |
| 477 | return 0; |
| 478 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 479 | selectCaProfile(configFilePath); |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 480 | face.processEvents(); |
| 481 | return 0; |
| 482 | } |
| 483 | |
Zhiyi Zhang | e4891b7 | 2020-10-10 15:11:57 -0700 | [diff] [blame] | 484 | } // namespace ndncert |
| 485 | } // namespace ndn |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 486 | |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 487 | int |
| 488 | main(int argc, char* argv[]) |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 489 | { |
| 490 | return ndn::ndncert::main(argc, argv); |
| 491 | } |