blob: 6ebe9d74315ee3de9be418d799492afcd231ec5f [file] [log] [blame]
Zhiyi Zhang23564c82017-03-01 10:22:22 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2/**
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -07003 * Copyright (c) 2017-2020, Regents of the University of California.
Zhiyi Zhang23564c82017-03-01 10:22:22 -08004 *
5 * This file is part of ndncert, a certificate management system based on NDN.
6 *
7 * ndncert is free software: you can redistribute it and/or modify it under the terms
8 * of the GNU General Public License as published by the Free Software Foundation, either
9 * version 3 of the License, or (at your option) any later version.
10 *
11 * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License along with
16 * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
17 *
18 * See AUTHORS.md for complete list of ndncert authors and contributors.
19 */
20
21#include "client-module.hpp"
Zhiyi Zhang48f23782020-09-28 12:11:24 -070022
Zhiyi Zhang23564c82017-03-01 10:22:22 -080023#include <ndn-cxx/security/signing-helpers.hpp>
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070024#include <ndn-cxx/security/transform/base64-encode.hpp>
25#include <ndn-cxx/security/transform/buffer-source.hpp>
26#include <ndn-cxx/security/transform/stream-sink.hpp>
Zhiyi Zhang48f23782020-09-28 12:11:24 -070027#include <ndn-cxx/security/verification-helpers.hpp>
28#include <ndn-cxx/util/io.hpp>
29#include <ndn-cxx/util/random.hpp>
30
31#include "challenge-module.hpp"
32#include "crypto-support/enc-tlv.hpp"
33#include "logging.hpp"
34#include "protocol-detail/challenge.hpp"
35#include "protocol-detail/info.hpp"
36#include "protocol-detail/new.hpp"
37#include "protocol-detail/probe.hpp"
38#include "protocol-detail/revoke.hpp"
Zhiyi Zhang23564c82017-03-01 10:22:22 -080039
40namespace ndn {
41namespace ndncert {
42
43_LOG_INIT(ndncert.client);
44
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070045ClientModule::ClientModule(security::v2::KeyChain& keyChain)
Zhiyi Zhang48f23782020-09-28 12:11:24 -070046 : m_keyChain(keyChain)
Zhiyi Zhang23564c82017-03-01 10:22:22 -080047{
48}
49
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -070050ClientModule::~ClientModule()
51{
52 endSession();
53}
Davide Pesavento08994782018-01-22 12:13:41 -050054
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070055shared_ptr<Interest>
swa77020643ac2020-03-26 02:24:45 -070056ClientModule::generateInfoInterest(const Name& caName)
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080057{
58 Name interestName = caName;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070059 if (readString(caName.at(-1)) != "CA")
60 interestName.append("CA");
swa77020643ac2020-03-26 02:24:45 -070061 interestName.append("INFO");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070062 auto interest = make_shared<Interest>(interestName);
63 interest->setMustBeFresh(true);
64 interest->setCanBePrefix(false);
65 return interest;
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080066}
67
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070068bool
Suyong Won19fba4d2020-05-09 13:39:46 -070069ClientModule::verifyInfoResponse(const Data& reply)
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070070{
71 // parse the ca item
Suyong Won19fba4d2020-05-09 13:39:46 -070072 auto caItem = INFO::decodeClientConfigFromContent(reply.getContent());
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070073
74 // verify the probe Data's sig
75 if (!security::verifySignature(reply, caItem.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -070076 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070077 return false;
78 }
79 return true;
80}
81
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080082void
Suyong Won19fba4d2020-05-09 13:39:46 -070083ClientModule::addCaFromInfoResponse(const Data& reply)
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080084{
Suyong Won57462ca2020-05-05 22:20:09 -070085 const Block& contentBlock = reply.getContent();
86
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070087 // parse the ca item
Suyong Won19fba4d2020-05-09 13:39:46 -070088 auto caItem = INFO::decodeClientConfigFromContent(contentBlock);
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080089
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070090 // update the local config
91 bool findItem = false;
92 for (auto& item : m_config.m_caItems) {
Suyong Won256c9062020-05-11 02:45:56 -070093 if (item.m_caPrefix == caItem.m_caPrefix) {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070094 findItem = true;
95 item = caItem;
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080096 }
97 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070098 if (!findItem) {
99 m_config.m_caItems.push_back(caItem);
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +0800100 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800101}
102
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700103shared_ptr<Interest>
104ClientModule::generateProbeInterest(const ClientCaItem& ca, const std::string& probeInfo)
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800105{
Suyong Won256c9062020-05-11 02:45:56 -0700106 Name interestName = ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700107 interestName.append("CA").append("PROBE");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700108 auto interest = make_shared<Interest>(interestName);
109 interest->setMustBeFresh(true);
110 interest->setCanBePrefix(false);
Suyong Won19fba4d2020-05-09 13:39:46 -0700111 interest->setApplicationParameters(
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700112 PROBE::encodeApplicationParametersFromProbeInfo(ca, probeInfo));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700113
114 // update local state
115 m_ca = ca;
116 return interest;
117}
118
119void
120ClientModule::onProbeResponse(const Data& reply)
121{
122 if (!security::verifySignature(reply, m_ca.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -0700123 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700124 return;
125 }
Suyong Won19fba4d2020-05-09 13:39:46 -0700126
127 auto contentTLV = reply.getContent();
Suyong Won44d0cce2020-05-10 04:07:43 -0700128 contentTLV.parse();
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700129
130 // read the available name and put it into the state
Suyong Won19fba4d2020-05-09 13:39:46 -0700131 if (contentTLV.get(tlv_probe_response).hasValue()) {
Suyong Wonb29e0da2020-05-12 01:59:15 -0700132 Block probeResponseBlock = contentTLV.get(tlv_probe_response);
133 probeResponseBlock.parse();
134 m_identityName.wireDecode(probeResponseBlock.get(tlv::Name));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700135 }
Zhiyi Zhang781a5602019-06-26 19:05:04 -0700136 else {
137 NDN_LOG_TRACE("The JSON_CA_NAME is empty.");
138 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700139}
140
141shared_ptr<Interest>
142ClientModule::generateNewInterest(const time::system_clock::TimePoint& notBefore,
143 const time::system_clock::TimePoint& notAfter,
Zhiyi Zhang5f749a22019-06-12 17:02:33 -0700144 const Name& identityName, const shared_ptr<Data>& probeToken)
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700145{
146 // Name requestedName = identityName;
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700147 if (!identityName.empty()) { // if identityName is not empty, find the corresponding CA
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700148 bool findCa = false;
149 for (const auto& caItem : m_config.m_caItems) {
Suyong Won256c9062020-05-11 02:45:56 -0700150 if (caItem.m_caPrefix.isPrefixOf(identityName)) {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700151 m_ca = caItem;
152 findCa = true;
153 }
154 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700155 if (!findCa) { // if cannot find, cannot proceed
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700156 return nullptr;
157 }
158 m_identityName = identityName;
159 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700160 else { // if identityName is empty, check m_identityName or generate a random name
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700161 if (!m_identityName.empty()) {
162 // do nothing
163 }
164 else {
Zhiyi Zhang781a5602019-06-26 19:05:04 -0700165 NDN_LOG_TRACE("Randomly create a new name because m_identityName is empty and the param is empty.");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700166 auto id = std::to_string(random::generateSecureWord64());
Suyong Won256c9062020-05-11 02:45:56 -0700167 m_identityName = m_ca.m_caPrefix;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700168 m_identityName.append(id);
169 }
170 }
171
172 // generate a newly key pair or use an existing key
Zhiyi Zhang10130782018-02-01 18:28:49 -0800173 const auto& pib = m_keyChain.getPib();
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700174 security::pib::Identity identity;
Zhiyi Zhang10130782018-02-01 18:28:49 -0800175 try {
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700176 identity = pib.getIdentity(m_identityName);
Zhiyi Zhang10130782018-02-01 18:28:49 -0800177 }
178 catch (const security::Pib::Error& e) {
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700179 identity = m_keyChain.createIdentity(m_identityName);
180 m_isNewlyCreatedIdentity = true;
181 m_isNewlyCreatedKey = true;
182 }
183 try {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700184 m_key = identity.getDefaultKey();
Zhiyi Zhang10130782018-02-01 18:28:49 -0800185 }
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700186 catch (const security::Pib::Error& e) {
187 m_key = m_keyChain.createKey(identity);
188 m_isNewlyCreatedKey = true;
189 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800190
191 // generate certificate request
192 security::v2::Certificate certRequest;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700193 certRequest.setName(Name(m_key.getName()).append("cert-request").appendVersion());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800194 certRequest.setContentType(tlv::ContentType_Key);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700195 certRequest.setContent(m_key.getPublicKey().data(), m_key.getPublicKey().size());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800196 SignatureInfo signatureInfo;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700197 signatureInfo.setValidityPeriod(security::ValidityPeriod(notBefore, notAfter));
198 m_keyChain.sign(certRequest, signingByKey(m_key.getName()).setSignatureInfo(signatureInfo));
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800199
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700200 // generate Interest packet
Suyong Won256c9062020-05-11 02:45:56 -0700201 Name interestName = m_ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700202 interestName.append("CA").append("NEW");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700203 auto interest = make_shared<Interest>(interestName);
204 interest->setMustBeFresh(true);
205 interest->setCanBePrefix(false);
Suyong Won19fba4d2020-05-09 13:39:46 -0700206 interest->setApplicationParameters(
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700207 NEW::encodeApplicationParameters(m_ecdh.getBase64PubKey(), certRequest, probeToken));
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800208
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700209 // sign the Interest packet
210 m_keyChain.sign(*interest, signingByKey(m_key.getName()));
211 return interest;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800212}
213
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700214std::list<std::string>
215ClientModule::onNewResponse(const Data& reply)
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800216{
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700217 return onRequestInitResponse(reply, REQUEST_TYPE_NEW);
tylerliu4a00aad2020-09-26 02:03:17 -0700218}
219
220std::list<std::string>
221ClientModule::onRequestInitResponse(const Data& reply, int requestType)
222{
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700223 if (!security::verifySignature(reply, m_ca.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -0700224 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700225 return std::list<std::string>();
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800226 }
Suyong Won19fba4d2020-05-09 13:39:46 -0700227 auto contentTLV = reply.getContent();
Suyong Won44d0cce2020-05-10 04:07:43 -0700228 contentTLV.parse();
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800229
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700230 // ECDH
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700231 const auto& peerKeyBase64Str = readString(contentTLV.get(tlv_ecdh_pub));
Suyong Won19fba4d2020-05-09 13:39:46 -0700232 const auto& saltStr = readString(contentTLV.get(tlv_salt));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700233 uint64_t saltInt = std::stoull(saltStr);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700234 m_ecdh.deriveSecret(peerKeyBase64Str);
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800235
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700236 // HKDF
Zhiyi Zhang36706832019-07-04 21:33:03 -0700237 hkdf(m_ecdh.context->sharedSecret, m_ecdh.context->sharedSecretLen,
238 (uint8_t*)&saltInt, sizeof(saltInt), m_aesKey, sizeof(m_aesKey));
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800239
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700240 // update state
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700241 m_status = static_cast<Status>(readNonNegativeInteger(contentTLV.get(tlv_status)));
Suyong Won19fba4d2020-05-09 13:39:46 -0700242 m_requestId = readString(contentTLV.get(tlv_request_id));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700243 m_challengeList.clear();
Suyong Won19fba4d2020-05-09 13:39:46 -0700244 for (auto const& element : contentTLV.elements()) {
245 if (element.type() == tlv_challenge) {
246 m_challengeList.push_back(readString(element));
247 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800248 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700249 return m_challengeList;
250}
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800251
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700252shared_ptr<Interest>
tylerliu182bc532020-09-25 01:54:45 -0700253ClientModule::generateRevokeInterest(const security::v2::Certificate& certificate)
254{
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700255 // Name requestedName = identityName;
256 bool findCa = false;
257 for (const auto& caItem : m_config.m_caItems) {
258 if (caItem.m_caName.isPrefixOf(certificate.getName())) {
259 m_ca = caItem;
260 findCa = true;
tylerliu182bc532020-09-25 01:54:45 -0700261 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700262 }
263 if (!findCa) { // if cannot find, cannot proceed
264 _LOG_TRACE("Cannot find corresponding CA for the certificate.");
265 return nullptr;
266 }
tylerliu182bc532020-09-25 01:54:45 -0700267
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700268 // generate Interest packet
269 Name interestName = m_ca.m_caPrefix;
270 interestName.append("CA").append("REVOKE");
271 auto interest = make_shared<Interest>(interestName);
272 interest->setMustBeFresh(true);
273 interest->setCanBePrefix(false);
274 interest->setApplicationParameters(
275 REVOKE::encodeApplicationParameters(m_ecdh.getBase64PubKey(), certificate));
tylerliu182bc532020-09-25 01:54:45 -0700276
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700277 // return the Interest packet
278 return interest;
tylerliu182bc532020-09-25 01:54:45 -0700279}
280
281std::list<std::string>
282ClientModule::onRevokeResponse(const Data& reply)
283{
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700284 return onRequestInitResponse(reply, REQUEST_TYPE_REVOKE);
tylerliu182bc532020-09-25 01:54:45 -0700285}
286
287shared_ptr<Interest>
Suyong Won19fba4d2020-05-09 13:39:46 -0700288ClientModule::generateChallengeInterest(const Block& challengeRequest)
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700289{
Suyong Won44d0cce2020-05-10 04:07:43 -0700290 challengeRequest.parse();
Suyong Won19fba4d2020-05-09 13:39:46 -0700291 m_challengeType = readString(challengeRequest.get(tlv_selected_challenge));
Suyong Won44d0cce2020-05-10 04:07:43 -0700292
Suyong Won256c9062020-05-11 02:45:56 -0700293 Name interestName = m_ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700294 interestName.append("CA").append("CHALLENGE").append(m_requestId);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700295 auto interest = make_shared<Interest>(interestName);
296 interest->setMustBeFresh(true);
297 interest->setCanBePrefix(false);
298
299 // encrypt the Interest parameters
Suyong Won7968f7a2020-05-12 01:01:25 -0700300 auto paramBlock = encodeBlockWithAesGcm128(tlv::ApplicationParameters, m_aesKey,
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700301 challengeRequest.value(), challengeRequest.value_size(),
302 (const uint8_t*)"test", strlen("test"));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700303 interest->setApplicationParameters(paramBlock);
304
305 m_keyChain.sign(*interest, signingByKey(m_key.getName()));
306 return interest;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800307}
308
309void
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700310ClientModule::onChallengeResponse(const Data& reply)
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800311{
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700312 if (!security::verifySignature(reply, m_ca.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -0700313 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800314 return;
315 }
Zhiyi Zhangb8cb0472020-05-05 20:55:05 -0700316 auto result = decodeBlockWithAesGcm128(reply.getContent(), m_aesKey, (const uint8_t*)"test", strlen("test"));
Suyong Won19fba4d2020-05-09 13:39:46 -0700317
Suyong Won44d0cce2020-05-10 04:07:43 -0700318 Block contentTLV = makeBinaryBlock(tlv_encrypted_payload, result.data(), result.size());
319 contentTLV.parse();
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800320
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700321 // update state
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700322 m_status = static_cast<Status>(readNonNegativeInteger(contentTLV.get(tlv_status)));
Suyong Won19fba4d2020-05-09 13:39:46 -0700323 m_challengeStatus = readString(contentTLV.get(tlv_challenge_status));
324 m_remainingTries = readNonNegativeInteger(contentTLV.get(tlv_remaining_tries));
325 m_freshBefore = time::system_clock::now() +
326 time::seconds(readNonNegativeInteger(contentTLV.get(tlv_remaining_time)));
327
Suyong Won7968f7a2020-05-12 01:01:25 -0700328 if (contentTLV.find(tlv_issued_cert_name) != contentTLV.elements_end()) {
329 Block issuedCertNameBlock = contentTLV.get(tlv_issued_cert_name);
330 issuedCertNameBlock.parse();
331 m_issuedCertName.wireDecode(issuedCertNameBlock.get(tlv::Name));
332 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700333}
Zhiyi Zhange30eb352017-04-13 15:26:14 -0700334
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700335shared_ptr<Interest>
336ClientModule::generateDownloadInterest()
337{
Suyong Won256c9062020-05-11 02:45:56 -0700338 Name interestName = m_ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700339 interestName.append("CA").append("DOWNLOAD").append(m_requestId);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700340 auto interest = make_shared<Interest>(interestName);
341 interest->setMustBeFresh(true);
342 interest->setCanBePrefix(false);
343 return interest;
344}
Zhiyi Zhange30eb352017-04-13 15:26:14 -0700345
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700346shared_ptr<Interest>
347ClientModule::generateCertFetchInterest()
348{
swa770cf1d8f72020-04-21 23:12:39 -0700349 Name interestName = m_issuedCertName;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700350 auto interest = make_shared<Interest>(interestName);
351 interest->setMustBeFresh(true);
352 interest->setCanBePrefix(false);
353 return interest;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800354}
355
swa770cf1d8f72020-04-21 23:12:39 -0700356void
357ClientModule::onCertFetchResponse(const Data& reply)
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800358{
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800359 try {
360 security::v2::Certificate cert(reply.getContent().blockFromValue());
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700361 m_keyChain.addCertificate(m_key, cert);
swa770cf1d8f72020-04-21 23:12:39 -0700362 _LOG_TRACE("Fetched and installed the cert " << cert.getName());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800363 }
364 catch (const std::exception& e) {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700365 _LOG_ERROR("Cannot add replied certificate into the keychain " << e.what());
Zhiyi Zhangef6b36a2020-09-22 21:20:59 -0700366 return;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800367 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800368}
369
Zhiyi Zhangef6b36a2020-09-22 21:20:59 -0700370void
371ClientModule::endSession()
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800372{
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700373 if (getApplicationStatus() == Status::SUCCESS || getApplicationStatus() == Status::ENDED) {
Zhiyi Zhangef6b36a2020-09-22 21:20:59 -0700374 return;
375 }
376 if (m_isNewlyCreatedIdentity) {
377 // put the identity into the if scope is because it may cause an error
378 // outside since when endSession is called, identity may not have been created yet.
379 auto identity = m_keyChain.getPib().getIdentity(m_identityName);
380 m_keyChain.deleteIdentity(identity);
381 }
382 else if (m_isNewlyCreatedKey) {
383 auto identity = m_keyChain.getPib().getIdentity(m_identityName);
384 m_keyChain.deleteKey(identity, m_key);
385 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700386 m_status = Status::ENDED;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800387}
388
Zhiyi Zhang547c8512019-06-18 23:46:14 -0700389std::vector<std::string>
390ClientModule::parseProbeComponents(const std::string& probe)
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700391{
Zhiyi Zhang547c8512019-06-18 23:46:14 -0700392 std::vector<std::string> components;
Yufeng Zhang424d0362019-06-12 16:48:27 -0700393 std::string delimiter = ":";
394 size_t last = 0;
395 size_t next = 0;
Zhiyi Zhang547c8512019-06-18 23:46:14 -0700396 while ((next = probe.find(delimiter, last)) != std::string::npos) {
397 components.push_back(probe.substr(last, next - last));
398 last = next + 1;
399 }
400 components.push_back(probe.substr(last));
401 return components;
402}
Yufeng Zhang424d0362019-06-12 16:48:27 -0700403
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700404} // namespace ndncert
405} // namespace ndn