blob: 0fbd07b2a240d82786c93cd9c4e5ad5316e27339 [file] [log] [blame]
Zhiyi Zhang23564c82017-03-01 10:22:22 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
2/**
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -07003 * Copyright (c) 2017-2020, Regents of the University of California.
Zhiyi Zhang23564c82017-03-01 10:22:22 -08004 *
5 * This file is part of ndncert, a certificate management system based on NDN.
6 *
7 * ndncert is free software: you can redistribute it and/or modify it under the terms
8 * of the GNU General Public License as published by the Free Software Foundation, either
9 * version 3 of the License, or (at your option) any later version.
10 *
11 * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License along with
16 * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
17 *
18 * See AUTHORS.md for complete list of ndncert authors and contributors.
19 */
20
21#include "client-module.hpp"
Zhiyi Zhang48f23782020-09-28 12:11:24 -070022
Zhiyi Zhang23564c82017-03-01 10:22:22 -080023#include <ndn-cxx/security/signing-helpers.hpp>
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070024#include <ndn-cxx/security/transform/base64-encode.hpp>
25#include <ndn-cxx/security/transform/buffer-source.hpp>
26#include <ndn-cxx/security/transform/stream-sink.hpp>
Zhiyi Zhang48f23782020-09-28 12:11:24 -070027#include <ndn-cxx/security/verification-helpers.hpp>
28#include <ndn-cxx/util/io.hpp>
29#include <ndn-cxx/util/random.hpp>
30
31#include "challenge-module.hpp"
32#include "crypto-support/enc-tlv.hpp"
Zhiyi Zhang48f23782020-09-28 12:11:24 -070033#include "protocol-detail/challenge.hpp"
34#include "protocol-detail/info.hpp"
35#include "protocol-detail/new.hpp"
36#include "protocol-detail/probe.hpp"
37#include "protocol-detail/revoke.hpp"
Zhiyi Zhang23564c82017-03-01 10:22:22 -080038
39namespace ndn {
40namespace ndncert {
41
42_LOG_INIT(ndncert.client);
43
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070044ClientModule::ClientModule(security::v2::KeyChain& keyChain)
Zhiyi Zhang48f23782020-09-28 12:11:24 -070045 : m_keyChain(keyChain)
Zhiyi Zhang23564c82017-03-01 10:22:22 -080046{
47}
48
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -070049ClientModule::~ClientModule()
50{
51 endSession();
52}
Davide Pesavento08994782018-01-22 12:13:41 -050053
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070054shared_ptr<Interest>
swa77020643ac2020-03-26 02:24:45 -070055ClientModule::generateInfoInterest(const Name& caName)
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080056{
57 Name interestName = caName;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070058 if (readString(caName.at(-1)) != "CA")
59 interestName.append("CA");
swa77020643ac2020-03-26 02:24:45 -070060 interestName.append("INFO");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070061 auto interest = make_shared<Interest>(interestName);
62 interest->setMustBeFresh(true);
63 interest->setCanBePrefix(false);
64 return interest;
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080065}
66
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070067bool
Suyong Won19fba4d2020-05-09 13:39:46 -070068ClientModule::verifyInfoResponse(const Data& reply)
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070069{
70 // parse the ca item
Suyong Won19fba4d2020-05-09 13:39:46 -070071 auto caItem = INFO::decodeClientConfigFromContent(reply.getContent());
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070072
73 // verify the probe Data's sig
74 if (!security::verifySignature(reply, caItem.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -070075 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhangcaab5462019-10-18 13:41:02 -070076 return false;
77 }
78 return true;
79}
80
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080081void
Suyong Won19fba4d2020-05-09 13:39:46 -070082ClientModule::addCaFromInfoResponse(const Data& reply)
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080083{
Suyong Won57462ca2020-05-05 22:20:09 -070084 const Block& contentBlock = reply.getContent();
85
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070086 // parse the ca item
Suyong Won19fba4d2020-05-09 13:39:46 -070087 auto caItem = INFO::decodeClientConfigFromContent(contentBlock);
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080088
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070089 // update the local config
90 bool findItem = false;
91 for (auto& item : m_config.m_caItems) {
Suyong Won256c9062020-05-11 02:45:56 -070092 if (item.m_caPrefix == caItem.m_caPrefix) {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070093 findItem = true;
94 item = caItem;
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080095 }
96 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070097 if (!findItem) {
98 m_config.m_caItems.push_back(caItem);
Zhiyi Zhang1c0bd372017-12-18 18:32:55 +080099 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800100}
101
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700102shared_ptr<Interest>
103ClientModule::generateProbeInterest(const ClientCaItem& ca, const std::string& probeInfo)
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800104{
Suyong Won256c9062020-05-11 02:45:56 -0700105 Name interestName = ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700106 interestName.append("CA").append("PROBE");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700107 auto interest = make_shared<Interest>(interestName);
108 interest->setMustBeFresh(true);
109 interest->setCanBePrefix(false);
Suyong Won19fba4d2020-05-09 13:39:46 -0700110 interest->setApplicationParameters(
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700111 PROBE::encodeApplicationParametersFromProbeInfo(ca, probeInfo));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700112
113 // update local state
114 m_ca = ca;
115 return interest;
116}
117
118void
119ClientModule::onProbeResponse(const Data& reply)
120{
121 if (!security::verifySignature(reply, m_ca.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -0700122 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700123 return;
124 }
Suyong Won19fba4d2020-05-09 13:39:46 -0700125
126 auto contentTLV = reply.getContent();
Suyong Won44d0cce2020-05-10 04:07:43 -0700127 contentTLV.parse();
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700128
129 // read the available name and put it into the state
Suyong Won19fba4d2020-05-09 13:39:46 -0700130 if (contentTLV.get(tlv_probe_response).hasValue()) {
Suyong Wonb29e0da2020-05-12 01:59:15 -0700131 Block probeResponseBlock = contentTLV.get(tlv_probe_response);
132 probeResponseBlock.parse();
133 m_identityName.wireDecode(probeResponseBlock.get(tlv::Name));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700134 }
Zhiyi Zhang781a5602019-06-26 19:05:04 -0700135 else {
136 NDN_LOG_TRACE("The JSON_CA_NAME is empty.");
137 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700138}
139
140shared_ptr<Interest>
141ClientModule::generateNewInterest(const time::system_clock::TimePoint& notBefore,
142 const time::system_clock::TimePoint& notAfter,
Zhiyi Zhangb8bbc642020-09-29 14:08:26 -0700143 const Name& identityName)
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700144{
145 // Name requestedName = identityName;
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700146 if (!identityName.empty()) { // if identityName is not empty, find the corresponding CA
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700147 bool findCa = false;
148 for (const auto& caItem : m_config.m_caItems) {
Suyong Won256c9062020-05-11 02:45:56 -0700149 if (caItem.m_caPrefix.isPrefixOf(identityName)) {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700150 m_ca = caItem;
151 findCa = true;
152 }
153 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700154 if (!findCa) { // if cannot find, cannot proceed
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700155 return nullptr;
156 }
157 m_identityName = identityName;
158 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700159 else { // if identityName is empty, check m_identityName or generate a random name
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700160 if (!m_identityName.empty()) {
161 // do nothing
162 }
163 else {
Zhiyi Zhang781a5602019-06-26 19:05:04 -0700164 NDN_LOG_TRACE("Randomly create a new name because m_identityName is empty and the param is empty.");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700165 auto id = std::to_string(random::generateSecureWord64());
Suyong Won256c9062020-05-11 02:45:56 -0700166 m_identityName = m_ca.m_caPrefix;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700167 m_identityName.append(id);
168 }
169 }
170
171 // generate a newly key pair or use an existing key
Zhiyi Zhang10130782018-02-01 18:28:49 -0800172 const auto& pib = m_keyChain.getPib();
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700173 security::pib::Identity identity;
Zhiyi Zhang10130782018-02-01 18:28:49 -0800174 try {
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700175 identity = pib.getIdentity(m_identityName);
Zhiyi Zhang10130782018-02-01 18:28:49 -0800176 }
177 catch (const security::Pib::Error& e) {
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700178 identity = m_keyChain.createIdentity(m_identityName);
179 m_isNewlyCreatedIdentity = true;
180 m_isNewlyCreatedKey = true;
181 }
182 try {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700183 m_key = identity.getDefaultKey();
Zhiyi Zhang10130782018-02-01 18:28:49 -0800184 }
Zhiyi Zhangad9e04f2020-03-27 12:04:31 -0700185 catch (const security::Pib::Error& e) {
186 m_key = m_keyChain.createKey(identity);
187 m_isNewlyCreatedKey = true;
188 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800189
190 // generate certificate request
191 security::v2::Certificate certRequest;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700192 certRequest.setName(Name(m_key.getName()).append("cert-request").appendVersion());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800193 certRequest.setContentType(tlv::ContentType_Key);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700194 certRequest.setContent(m_key.getPublicKey().data(), m_key.getPublicKey().size());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800195 SignatureInfo signatureInfo;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700196 signatureInfo.setValidityPeriod(security::ValidityPeriod(notBefore, notAfter));
197 m_keyChain.sign(certRequest, signingByKey(m_key.getName()).setSignatureInfo(signatureInfo));
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800198
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700199 // generate Interest packet
Suyong Won256c9062020-05-11 02:45:56 -0700200 Name interestName = m_ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700201 interestName.append("CA").append("NEW");
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700202 auto interest = make_shared<Interest>(interestName);
203 interest->setMustBeFresh(true);
204 interest->setCanBePrefix(false);
Suyong Won19fba4d2020-05-09 13:39:46 -0700205 interest->setApplicationParameters(
Zhiyi Zhangb8bbc642020-09-29 14:08:26 -0700206 NEW::encodeApplicationParameters(m_ecdh.getBase64PubKey(), certRequest));
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800207
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700208 // sign the Interest packet
209 m_keyChain.sign(*interest, signingByKey(m_key.getName()));
210 return interest;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800211}
212
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700213std::list<std::string>
tylerliu0e176c32020-09-29 11:39:46 -0700214ClientModule::onNewRenewRevokeResponse(const Data& reply)
tylerliu4a00aad2020-09-26 02:03:17 -0700215{
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700216 if (!security::verifySignature(reply, m_ca.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -0700217 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700218 return std::list<std::string>();
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800219 }
Suyong Won19fba4d2020-05-09 13:39:46 -0700220 auto contentTLV = reply.getContent();
Suyong Won44d0cce2020-05-10 04:07:43 -0700221 contentTLV.parse();
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800222
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700223 // ECDH
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700224 const auto& peerKeyBase64Str = readString(contentTLV.get(tlv_ecdh_pub));
Suyong Won19fba4d2020-05-09 13:39:46 -0700225 const auto& saltStr = readString(contentTLV.get(tlv_salt));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700226 uint64_t saltInt = std::stoull(saltStr);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700227 m_ecdh.deriveSecret(peerKeyBase64Str);
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800228
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700229 // HKDF
Zhiyi Zhang36706832019-07-04 21:33:03 -0700230 hkdf(m_ecdh.context->sharedSecret, m_ecdh.context->sharedSecretLen,
231 (uint8_t*)&saltInt, sizeof(saltInt), m_aesKey, sizeof(m_aesKey));
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800232
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700233 // update state
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700234 m_status = static_cast<Status>(readNonNegativeInteger(contentTLV.get(tlv_status)));
Suyong Won19fba4d2020-05-09 13:39:46 -0700235 m_requestId = readString(contentTLV.get(tlv_request_id));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700236 m_challengeList.clear();
Suyong Won19fba4d2020-05-09 13:39:46 -0700237 for (auto const& element : contentTLV.elements()) {
238 if (element.type() == tlv_challenge) {
239 m_challengeList.push_back(readString(element));
240 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800241 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700242 return m_challengeList;
243}
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800244
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700245shared_ptr<Interest>
tylerliu182bc532020-09-25 01:54:45 -0700246ClientModule::generateRevokeInterest(const security::v2::Certificate& certificate)
247{
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700248 // Name requestedName = identityName;
249 bool findCa = false;
250 for (const auto& caItem : m_config.m_caItems) {
251 if (caItem.m_caName.isPrefixOf(certificate.getName())) {
252 m_ca = caItem;
253 findCa = true;
tylerliu182bc532020-09-25 01:54:45 -0700254 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700255 }
256 if (!findCa) { // if cannot find, cannot proceed
257 _LOG_TRACE("Cannot find corresponding CA for the certificate.");
258 return nullptr;
259 }
tylerliu182bc532020-09-25 01:54:45 -0700260
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700261 // generate Interest packet
262 Name interestName = m_ca.m_caPrefix;
263 interestName.append("CA").append("REVOKE");
264 auto interest = make_shared<Interest>(interestName);
265 interest->setMustBeFresh(true);
266 interest->setCanBePrefix(false);
267 interest->setApplicationParameters(
268 REVOKE::encodeApplicationParameters(m_ecdh.getBase64PubKey(), certificate));
tylerliu182bc532020-09-25 01:54:45 -0700269
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700270 // return the Interest packet
271 return interest;
tylerliu182bc532020-09-25 01:54:45 -0700272}
273
tylerliu182bc532020-09-25 01:54:45 -0700274shared_ptr<Interest>
Suyong Won19fba4d2020-05-09 13:39:46 -0700275ClientModule::generateChallengeInterest(const Block& challengeRequest)
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700276{
Suyong Won44d0cce2020-05-10 04:07:43 -0700277 challengeRequest.parse();
Suyong Won19fba4d2020-05-09 13:39:46 -0700278 m_challengeType = readString(challengeRequest.get(tlv_selected_challenge));
Suyong Won44d0cce2020-05-10 04:07:43 -0700279
Suyong Won256c9062020-05-11 02:45:56 -0700280 Name interestName = m_ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700281 interestName.append("CA").append("CHALLENGE").append(m_requestId);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700282 auto interest = make_shared<Interest>(interestName);
283 interest->setMustBeFresh(true);
284 interest->setCanBePrefix(false);
285
286 // encrypt the Interest parameters
Suyong Won7968f7a2020-05-12 01:01:25 -0700287 auto paramBlock = encodeBlockWithAesGcm128(tlv::ApplicationParameters, m_aesKey,
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700288 challengeRequest.value(), challengeRequest.value_size(),
289 (const uint8_t*)"test", strlen("test"));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700290 interest->setApplicationParameters(paramBlock);
291
292 m_keyChain.sign(*interest, signingByKey(m_key.getName()));
293 return interest;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800294}
295
296void
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700297ClientModule::onChallengeResponse(const Data& reply)
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800298{
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700299 if (!security::verifySignature(reply, m_ca.m_anchor)) {
Suyong Won256c9062020-05-11 02:45:56 -0700300 _LOG_ERROR("Cannot verify data signature from " << m_ca.m_caPrefix.toUri());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800301 return;
302 }
Zhiyi Zhangb8cb0472020-05-05 20:55:05 -0700303 auto result = decodeBlockWithAesGcm128(reply.getContent(), m_aesKey, (const uint8_t*)"test", strlen("test"));
Suyong Won19fba4d2020-05-09 13:39:46 -0700304
Suyong Won44d0cce2020-05-10 04:07:43 -0700305 Block contentTLV = makeBinaryBlock(tlv_encrypted_payload, result.data(), result.size());
306 contentTLV.parse();
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800307
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700308 // update state
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700309 m_status = static_cast<Status>(readNonNegativeInteger(contentTLV.get(tlv_status)));
Suyong Won19fba4d2020-05-09 13:39:46 -0700310 m_challengeStatus = readString(contentTLV.get(tlv_challenge_status));
311 m_remainingTries = readNonNegativeInteger(contentTLV.get(tlv_remaining_tries));
312 m_freshBefore = time::system_clock::now() +
313 time::seconds(readNonNegativeInteger(contentTLV.get(tlv_remaining_time)));
314
Suyong Won7968f7a2020-05-12 01:01:25 -0700315 if (contentTLV.find(tlv_issued_cert_name) != contentTLV.elements_end()) {
316 Block issuedCertNameBlock = contentTLV.get(tlv_issued_cert_name);
317 issuedCertNameBlock.parse();
318 m_issuedCertName.wireDecode(issuedCertNameBlock.get(tlv::Name));
319 }
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700320}
Zhiyi Zhange30eb352017-04-13 15:26:14 -0700321
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700322shared_ptr<Interest>
323ClientModule::generateDownloadInterest()
324{
Suyong Won256c9062020-05-11 02:45:56 -0700325 Name interestName = m_ca.m_caPrefix;
swa770de007bc2020-03-24 21:26:21 -0700326 interestName.append("CA").append("DOWNLOAD").append(m_requestId);
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700327 auto interest = make_shared<Interest>(interestName);
328 interest->setMustBeFresh(true);
329 interest->setCanBePrefix(false);
330 return interest;
331}
Zhiyi Zhange30eb352017-04-13 15:26:14 -0700332
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700333shared_ptr<Interest>
334ClientModule::generateCertFetchInterest()
335{
swa770cf1d8f72020-04-21 23:12:39 -0700336 Name interestName = m_issuedCertName;
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700337 auto interest = make_shared<Interest>(interestName);
338 interest->setMustBeFresh(true);
339 interest->setCanBePrefix(false);
340 return interest;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800341}
342
swa770cf1d8f72020-04-21 23:12:39 -0700343void
344ClientModule::onCertFetchResponse(const Data& reply)
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800345{
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800346 try {
347 security::v2::Certificate cert(reply.getContent().blockFromValue());
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700348 m_keyChain.addCertificate(m_key, cert);
swa770cf1d8f72020-04-21 23:12:39 -0700349 _LOG_TRACE("Fetched and installed the cert " << cert.getName());
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800350 }
351 catch (const std::exception& e) {
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700352 _LOG_ERROR("Cannot add replied certificate into the keychain " << e.what());
Zhiyi Zhangef6b36a2020-09-22 21:20:59 -0700353 return;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800354 }
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800355}
356
Zhiyi Zhangef6b36a2020-09-22 21:20:59 -0700357void
358ClientModule::endSession()
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800359{
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700360 if (getApplicationStatus() == Status::SUCCESS || getApplicationStatus() == Status::ENDED) {
Zhiyi Zhangef6b36a2020-09-22 21:20:59 -0700361 return;
362 }
363 if (m_isNewlyCreatedIdentity) {
364 // put the identity into the if scope is because it may cause an error
365 // outside since when endSession is called, identity may not have been created yet.
366 auto identity = m_keyChain.getPib().getIdentity(m_identityName);
367 m_keyChain.deleteIdentity(identity);
368 }
369 else if (m_isNewlyCreatedKey) {
370 auto identity = m_keyChain.getPib().getIdentity(m_identityName);
371 m_keyChain.deleteKey(identity, m_key);
372 }
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700373 m_status = Status::ENDED;
Zhiyi Zhang23564c82017-03-01 10:22:22 -0800374}
375
Zhiyi Zhang547c8512019-06-18 23:46:14 -0700376std::vector<std::string>
377ClientModule::parseProbeComponents(const std::string& probe)
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700378{
Zhiyi Zhang547c8512019-06-18 23:46:14 -0700379 std::vector<std::string> components;
Yufeng Zhang424d0362019-06-12 16:48:27 -0700380 std::string delimiter = ":";
381 size_t last = 0;
382 size_t next = 0;
Zhiyi Zhang547c8512019-06-18 23:46:14 -0700383 while ((next = probe.find(delimiter, last)) != std::string::npos) {
384 components.push_back(probe.substr(last, next - last));
385 last = next + 1;
386 }
387 components.push_back(probe.substr(last));
388 return components;
389}
Yufeng Zhang424d0362019-06-12 16:48:27 -0700390
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700391} // namespace ndncert
392} // namespace ndn