blob: 990d84a39333cf7345011f52145316dc0a20b285 [file] [log] [blame]
Zhiyi Zhang3f20f952020-11-19 19:26:43 -08001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesaventoe5b43692021-11-15 22:05:03 -05002/*
Davide Pesavento842f1f72024-02-21 21:27:25 -05003 * Copyright (c) 2017-2024, Regents of the University of California.
Zhiyi Zhang3f20f952020-11-19 19:26:43 -08004 *
5 * This file is part of ndncert, a certificate management system based on NDN.
6 *
7 * ndncert is free software: you can redistribute it and/or modify it under the terms
8 * of the GNU General Public License as published by the Free Software Foundation, either
9 * version 3 of the License, or (at your option) any later version.
10 *
11 * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License along with
16 * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
17 *
18 * See AUTHORS.md for complete list of ndncert authors and contributors.
19 */
20
21#include "detail/ca-configuration.hpp"
Davide Pesaventoe5b43692021-11-15 22:05:03 -050022
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080023#include <ndn-cxx/util/io.hpp>
Davide Pesaventoe5b43692021-11-15 22:05:03 -050024
Davide Pesaventoe5b43692021-11-15 22:05:03 -050025#include <boost/property_tree/json_parser.hpp>
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080026
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040027namespace ndncert::ca {
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080028
29void
30CaConfig::load(const std::string& fileName)
31{
32 JsonSection configJson;
33 try {
34 boost::property_tree::read_json(fileName, configJson);
35 }
36 catch (const std::exception& error) {
37 NDN_THROW(std::runtime_error("Failed to parse configuration file " + fileName + ", " + error.what()));
38 }
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040039
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080040 if (configJson.begin() == configJson.end()) {
41 NDN_THROW(std::runtime_error("No JSON configuration found in file: " + fileName));
42 }
Davide Pesaventoe5b43692021-11-15 22:05:03 -050043 caProfile = CaProfile::fromJson(configJson);
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040044 if (caProfile.supportedChallenges.empty()) {
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080045 NDN_THROW(std::runtime_error("At least one challenge should be specified."));
46 }
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040047
48 // parse redirection section if present
tylerliuf2e6bb52020-12-13 13:23:05 -080049 redirection.clear();
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080050 auto redirectionItems = configJson.get_child_optional(CONFIG_REDIRECTION);
51 if (redirectionItems) {
52 for (const auto& item : *redirectionItems) {
53 auto caPrefixStr = item.second.get(CONFIG_CA_PREFIX, "");
54 auto caCertStr = item.second.get(CONFIG_CERTIFICATE, "");
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040055 if (caCertStr.empty()) {
Tianyuan Yu13aac732022-03-03 20:59:54 -080056 NDN_THROW(std::runtime_error("Redirect-to item's certificate cannot be empty."));
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080057 }
58 std::istringstream ss(caCertStr);
Davide Pesavento0dc02012021-11-23 22:55:03 -050059 auto caCert = ndn::io::load<Certificate>(ss);
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040060 if (!caPrefixStr.empty() && Name(caPrefixStr) != caCert->getIdentity()) {
Tianyuan Yu13aac732022-03-03 20:59:54 -080061 NDN_THROW(std::runtime_error("Redirect-to item's prefix and certificate does not match."));
62 }
63
64 auto policyType = item.second.get(CONFIG_REDIRECTION_POLICY_TYPE, "");
65 auto policyParam = item.second.get(CONFIG_REDIRECTION_POLICY_PARAM, "");
66 if (policyType.empty()) {
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040067 NDN_THROW(std::runtime_error("Redirect-to policy type expected but not provided."));
Tianyuan Yu13aac732022-03-03 20:59:54 -080068 }
69 auto policy = RedirectionPolicy::createPolicyFunc(policyType, policyParam);
70 if (policy == nullptr) {
71 NDN_THROW(std::runtime_error("Error on creating redirection policy"));
72 }
73 redirection.emplace_back(caCert, std::move(policy));
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080074 }
75 }
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040076
77 // parse name assignment if present
tylerliuf2e6bb52020-12-13 13:23:05 -080078 nameAssignmentFuncs.clear();
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080079 auto nameAssignmentItems = configJson.get_child_optional(CONFIG_NAME_ASSIGNMENT);
80 if (nameAssignmentItems) {
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040081 for (const auto& [key, val] : *nameAssignmentItems) {
82 auto func = NameAssignmentFunc::createNameAssignmentFunc(key, val.data());
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080083 if (func == nullptr) {
84 NDN_THROW(std::runtime_error("Error on creating name assignment function"));
85 }
tylerliuf2e6bb52020-12-13 13:23:05 -080086 nameAssignmentFuncs.push_back(std::move(func));
Zhiyi Zhang3f20f952020-11-19 19:26:43 -080087 }
88 }
89}
90
Davide Pesavento0d1d11c2022-04-11 22:11:34 -040091} // namespace ndncert::ca