Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 1 | /* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */ |
swa770 | 20643ac | 2020-03-26 02:24:45 -0700 | [diff] [blame] | 2 | /** |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 3 | * Copyright (c) 2017-2020, Regents of the University of California. |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 4 | * |
| 5 | * This file is part of ndncert, a certificate management system based on NDN. |
| 6 | * |
| 7 | * ndncert is free software: you can redistribute it and/or modify it under the terms |
| 8 | * of the GNU General Public License as published by the Free Software Foundation, either |
| 9 | * version 3 of the License, or (at your option) any later version. |
| 10 | * |
| 11 | * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY |
| 12 | * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A |
| 13 | * PARTICULAR PURPOSE. See the GNU General Public License for more details. |
| 14 | * |
| 15 | * You should have received copies of the GNU General Public License along with |
| 16 | * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>. |
| 17 | * |
| 18 | * See AUTHORS.md for complete list of ndncert authors and contributors. |
| 19 | */ |
| 20 | |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 21 | #include "requester.hpp" |
Zhiyi Zhang | 90c7578 | 2020-10-06 15:04:03 -0700 | [diff] [blame] | 22 | #include <ndn-cxx/security/verification-helpers.hpp> |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 23 | #include <boost/asio.hpp> |
Davide Pesavento | b48bbda | 2020-07-27 19:41:37 -0400 | [diff] [blame] | 24 | #include <boost/program_options/options_description.hpp> |
| 25 | #include <boost/program_options/parsers.hpp> |
| 26 | #include <boost/program_options/variables_map.hpp> |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 27 | #include <iostream> |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 28 | #include <string> |
| 29 | |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 30 | namespace ndn { |
| 31 | namespace ndncert { |
| 32 | |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 33 | static void |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 34 | selectCaProfile(std::string configFilePath); |
| 35 | static void |
| 36 | runProbe(CaProfile profile); |
| 37 | static void |
| 38 | runNew(CaProfile profile, Name identityName); |
| 39 | static void |
| 40 | runChallenge(const std::string& challengeType); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 41 | |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 42 | size_t nStep = 1; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 43 | Face face; |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 44 | security::KeyChain keyChain; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 45 | shared_ptr<RequesterState> requesterState = nullptr; |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 46 | |
Zhiyi Zhang | 4604983 | 2020-09-28 17:08:12 -0700 | [diff] [blame] | 47 | static void |
| 48 | captureParams(std::vector<std::tuple<std::string, std::string>>& requirement) |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 49 | { |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 50 | std::list<std::string> results; |
Zhiyi Zhang | 4604983 | 2020-09-28 17:08:12 -0700 | [diff] [blame] | 51 | for (auto& item : requirement) { |
| 52 | std::cerr << std::get<1>(item) << std::endl; |
| 53 | std::string captured; |
| 54 | getline(std::cin, captured); |
| 55 | std::get<1>(item) = captured; |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 56 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 57 | std::cerr << "Got it. This is what you've provided:" << std::endl; |
Zhiyi Zhang | 4604983 | 2020-09-28 17:08:12 -0700 | [diff] [blame] | 58 | for (const auto& item : requirement) { |
| 59 | std::cerr << std::get<0>(item) << " : " << std::get<1>(item) << std::endl; |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 60 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 61 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 62 | |
Zhiyi Zhang | 9829da9 | 2020-09-30 16:19:34 -0700 | [diff] [blame] | 63 | static std::vector<std::tuple<std::string, std::string>> |
| 64 | captureParams(const std::list<std::string>& requirement) |
Zhiyi Zhang | 547c851 | 2019-06-18 23:46:14 -0700 | [diff] [blame] | 65 | { |
Zhiyi Zhang | 9829da9 | 2020-09-30 16:19:34 -0700 | [diff] [blame] | 66 | std::vector<std::tuple<std::string, std::string>> results; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 67 | for (const auto& r : requirement) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 68 | results.emplace_back(r, "Please input: " + r); |
Zhiyi Zhang | 547c851 | 2019-06-18 23:46:14 -0700 | [diff] [blame] | 69 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 70 | captureParams(results); |
Zhiyi Zhang | 547c851 | 2019-06-18 23:46:14 -0700 | [diff] [blame] | 71 | return results; |
| 72 | } |
| 73 | |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 74 | static int |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 75 | captureValidityPeriod() |
| 76 | { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 77 | std::cerr << "\n***************************************\n" |
| 78 | << "Step " << nStep++ |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 79 | << ": Please type in your expected validity period of your certificate." |
| 80 | << " Type the number of hours (168 for week, 730 for month, 8760 for year)." |
| 81 | << " The CA may reject your application if your expected period is too long." << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 82 | while (true) { |
| 83 | std::string periodStr = ""; |
| 84 | getline(std::cin, periodStr); |
| 85 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 86 | return std::stoul(periodStr); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 87 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 88 | catch (const std::exception& e) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 89 | std::cerr << "Your input is invalid. Try again: " << std::endl; |
| 90 | } |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 91 | } |
| 92 | } |
| 93 | |
| 94 | static void |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 95 | onNackCb() |
| 96 | { |
| 97 | std::cerr << "Got NACK\n"; |
| 98 | } |
| 99 | |
| 100 | static void |
| 101 | timeoutCb() |
| 102 | { |
| 103 | std::cerr << "Interest sent time out\n"; |
| 104 | } |
| 105 | |
| 106 | static void |
swa770 | cf1d8f7 | 2020-04-21 23:12:39 -0700 | [diff] [blame] | 107 | certFetchCb(const Data& reply) |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 108 | { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 109 | auto item = Requester::onCertFetchResponse(reply); |
| 110 | if (item) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 111 | keyChain.addCertificate(keyChain.getPib().getIdentity(item->getIdentity()).getKey(item->getKeyName()), *item); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 112 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 113 | std::cerr << "\n***************************************\n" |
| 114 | << "Step " << nStep++ |
| 115 | << ": DONE\nCertificate with Name: " << reply.getName().toUri() |
| 116 | << "has already been installed to your local keychain" << std::endl |
| 117 | << "Exit now"; |
| 118 | face.getIoService().stop(); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 119 | } |
| 120 | |
| 121 | static void |
| 122 | challengeCb(const Data& reply) |
| 123 | { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 124 | try { |
| 125 | Requester::onChallengeResponse(*requesterState, reply); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 126 | } |
| 127 | catch (const std::exception& e) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 128 | std::cerr << "Error when decoding challenge step: " << e.what() << std::endl; |
| 129 | exit(1); |
| 130 | } |
| 131 | if (requesterState->m_status == Status::SUCCESS) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 132 | std::cerr << "Certificate has already been issued, downloading certificate..." << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 133 | face.expressInterest(*Requester::genCertFetchInterest(*requesterState), bind(&certFetchCb, _2), |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 134 | bind(&onNackCb), bind(&timeoutCb)); |
Zhiyi Zhang | 4d89fe0 | 2017-04-28 18:51:51 -0700 | [diff] [blame] | 135 | return; |
| 136 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 137 | runChallenge(requesterState->m_challengeType); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 138 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 139 | |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 140 | static void |
| 141 | newCb(const Data& reply) |
| 142 | { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 143 | std::list<std::string> challengeList; |
| 144 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 145 | challengeList = Requester::onNewRenewRevokeResponse(*requesterState, reply); |
| 146 | } |
| 147 | catch (const std::exception& e) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 148 | std::cerr << "Error on decoding NEW step reply because: " << e.what() << std::endl; |
| 149 | exit(1); |
| 150 | } |
| 151 | |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 152 | size_t challengeIndex = 0; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 153 | if (challengeList.size() < 1) { |
| 154 | std::cerr << "There is no available challenge provided by the CA. Exit" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 155 | exit(1); |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 156 | } |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 157 | else if (challengeList.size() > 1) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 158 | std::cerr << "\n***************************************\n" |
| 159 | << "Step " << nStep++ |
| 160 | << ": CHALLENGE SELECTION" << std::endl; |
| 161 | size_t count = 0; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 162 | std::string choice = ""; |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 163 | for (auto item : challengeList) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 164 | std::cerr << "> Index: " << count++ << std::endl |
| 165 | << ">> Challenge:" << item << std::endl; |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 166 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 167 | std::cerr << "Please type in the challenge index that you want to perform:" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 168 | while (true) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 169 | getline(std::cin, choice); |
| 170 | try { |
| 171 | challengeIndex = std::stoul(choice); |
| 172 | } |
| 173 | catch (const std::exception& e) { |
| 174 | std::cerr << "Your input is not valid. Try again:" << std::endl; |
| 175 | continue; |
| 176 | } |
| 177 | if (challengeIndex >= count) { |
| 178 | std::cerr << "Your input index is out of range. Try again:" << std::endl; |
| 179 | continue; |
| 180 | } |
| 181 | break; |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 182 | } |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 183 | } |
| 184 | auto it = challengeList.begin(); |
| 185 | std::advance(it, challengeIndex); |
Zhiyi Zhang | c5d93a9 | 2020-10-14 17:07:35 -0700 | [diff] [blame] | 186 | std::cerr << "The challenge has been selected: " << *it << std::endl; |
| 187 | runChallenge(*it); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 188 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 189 | |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 190 | static void |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 191 | InfoCb(const Data& reply, const Name& certFullName) |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 192 | { |
Zhiyi Zhang | 997669a | 2020-10-28 21:15:40 -0700 | [diff] [blame^] | 193 | optional<CaProfile> profile; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 194 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 195 | if (certFullName.empty()) { |
| 196 | profile = Requester::onCaProfileResponse(reply); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 197 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 198 | else { |
| 199 | profile = Requester::onCaProfileResponseAfterRedirection(reply, certFullName); |
| 200 | } |
| 201 | } |
| 202 | catch (const std::exception& e) { |
| 203 | std::cerr << "The fetched CA information cannot be used because: " << e.what() << std::endl; |
| 204 | return; |
Zhiyi Zhang | caab546 | 2019-10-18 13:41:02 -0700 | [diff] [blame] | 205 | } |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 206 | std::cerr << "\n***************************************\n" |
| 207 | << "Step " << nStep++ |
| 208 | << ": Will use a new trust anchor, please double check the identity info:" << std::endl |
| 209 | << "> New CA name: " << profile->m_caPrefix.toUri() << std::endl |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 210 | << "> This trust anchor information is signed by: " << reply.getSignatureInfo().getKeyLocator() << std::endl |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 211 | << "> The certificate: " << profile->m_cert << std::endl |
Davide Pesavento | b48bbda | 2020-07-27 19:41:37 -0400 | [diff] [blame] | 212 | << "Do you trust the information? Type in YES or NO" << std::endl; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 213 | |
| 214 | std::string answer; |
| 215 | getline(std::cin, answer); |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 216 | boost::algorithm::to_lower(answer); |
| 217 | if (answer == "yes") { |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 218 | std::cerr << "You answered YES: new CA " << profile->m_caPrefix.toUri() << " will be used" << std::endl; |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 219 | runProbe(*profile); |
Zhiyi Zhang | caab546 | 2019-10-18 13:41:02 -0700 | [diff] [blame] | 220 | // client.getClientConf().save(std::string(SYSCONFDIR) + "/ndncert/client.conf"); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 221 | } |
| 222 | else { |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 223 | std::cerr << "You answered NO: new CA " << profile->m_caPrefix.toUri() << " will not be used" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 224 | exit(0); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 225 | } |
| 226 | } |
| 227 | |
| 228 | static void |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 229 | probeCb(const Data& reply, CaProfile profile) |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 230 | { |
tylerliu | b47dad7 | 2020-10-08 21:36:55 -0700 | [diff] [blame] | 231 | std::vector<std::pair<Name, int>> names; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 232 | std::vector<Name> redirects; |
| 233 | Requester::onProbeResponse(reply, profile, names, redirects); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 234 | size_t count = 0; |
| 235 | std::cerr << "\n***************************************\n" |
| 236 | << "Step " << nStep++ |
| 237 | << ": You can either select one of the following names suggested by the CA: " << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 238 | for (const auto& name : names) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 239 | std::cerr << "> Index: " << count++ << std::endl |
tylerliu | b47dad7 | 2020-10-08 21:36:55 -0700 | [diff] [blame] | 240 | << ">> Suggested name: " << name.first.toUri() << std::endl |
| 241 | << ">> Corresponding Max sufiix length: " << name.second << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 242 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 243 | std::cerr << "\nOr choose another trusted CA suggested by the CA: " << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 244 | for (const auto& redirect : redirects) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 245 | std::cerr << "> Index: " << count++ << std::endl |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 246 | << ">> Suggested CA: " << security::extractIdentityFromCertName(redirect.getPrefix(-1)) << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 247 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 248 | std::cerr << "Please type in the index of your choice:" << std::endl; |
| 249 | size_t index = 0; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 250 | try { |
| 251 | std::string input; |
| 252 | getline(std::cin, input); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 253 | index = std::stoul(input); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 254 | } |
| 255 | catch (const std::exception& e) { |
| 256 | std::cerr << "Your input is Invalid. Exit" << std::endl; |
| 257 | exit(0); |
| 258 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 259 | if (index >= names.size() + redirects.size()) { |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 260 | std::cerr << "Your input is not an existing index. Exit" << std::endl; |
| 261 | return; |
| 262 | } |
| 263 | if (index < names.size()) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 264 | //names |
tylerliu | b47dad7 | 2020-10-08 21:36:55 -0700 | [diff] [blame] | 265 | std::cerr << "You selected name: " << names[index].first.toUri() << std::endl; |
| 266 | //TODO add prompt to "add suffix" |
| 267 | runNew(profile, names[index].first); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 268 | } |
| 269 | else { |
| 270 | //redirects |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 271 | auto redirectedCaFullName = redirects[index - names.size()]; |
tylerliu | a7bea66 | 2020-10-08 18:51:02 -0700 | [diff] [blame] | 272 | auto redirectedCaName = security::extractIdentityFromCertName(redirectedCaFullName.getPrefix(-1)); |
Zhiyi Zhang | 696cd04 | 2020-10-07 21:27:36 -0700 | [diff] [blame] | 273 | std::cerr << "You selected to be redirected to CA: " << redirectedCaName.toUri() << std::endl; |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 274 | face.expressInterest( |
Zhiyi Zhang | 696cd04 | 2020-10-07 21:27:36 -0700 | [diff] [blame] | 275 | *Requester::genCaProfileDiscoveryInterest(redirectedCaName), |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 276 | [&](const Interest&, const Data& data) { |
| 277 | auto fetchingInterest = Requester::genCaProfileInterestFromDiscoveryResponse(data); |
| 278 | face.expressInterest(*fetchingInterest, |
| 279 | bind(&InfoCb, _2, redirectedCaFullName), |
| 280 | bind(&onNackCb), |
| 281 | bind(&timeoutCb)); |
| 282 | }, |
| 283 | bind(&onNackCb), |
| 284 | bind(&timeoutCb)); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 285 | } |
| 286 | } |
| 287 | |
| 288 | static void |
| 289 | selectCaProfile(std::string configFilePath) |
| 290 | { |
| 291 | RequesterCaCache caCache; |
| 292 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 293 | caCache.load(configFilePath); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 294 | } |
| 295 | catch (const std::exception& e) { |
| 296 | std::cerr << "Cannot load the configuration file: " << e.what() << std::endl; |
| 297 | exit(1); |
| 298 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 299 | size_t count = 0; |
| 300 | std::cerr << "***************************************\n" |
| 301 | << "Step " << nStep++ << ": CA SELECTION" << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 302 | for (auto item : caCache.m_caItems) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 303 | std::cerr << "> Index: " << count++ << std::endl |
| 304 | << ">> CA prefix:" << item.m_caPrefix << std::endl |
| 305 | << ">> Introduction: " << item.m_caInfo << std::endl; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 306 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 307 | std::cerr << "Please type in the CA's index that you want to apply or type in NONE if your expected CA is not in the list:\n"; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 308 | |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 309 | std::string caIndexS, caIndexSLower; |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 310 | getline(std::cin, caIndexS); |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 311 | caIndexSLower = caIndexS; |
| 312 | boost::algorithm::to_lower(caIndexSLower); |
| 313 | if (caIndexSLower == "none") { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 314 | std::cerr << "\n***************************************\n" |
| 315 | << "Step " << nStep << ": ADD NEW CA\nPlease type in the CA's Name:" << std::endl; |
Zhiyi Zhang | caab546 | 2019-10-18 13:41:02 -0700 | [diff] [blame] | 316 | std::string expectedCAName; |
| 317 | getline(std::cin, expectedCAName); |
Zhiyi Zhang | fbcab84 | 2020-10-07 15:17:13 -0700 | [diff] [blame] | 318 | face.expressInterest( |
| 319 | *Requester::genCaProfileDiscoveryInterest(Name(expectedCAName)), |
| 320 | [&](const Interest&, const Data& data) { |
| 321 | auto fetchingInterest = Requester::genCaProfileInterestFromDiscoveryResponse(data); |
| 322 | face.expressInterest(*fetchingInterest, |
| 323 | bind(&InfoCb, _2, Name()), |
| 324 | bind(&onNackCb), |
| 325 | bind(&timeoutCb)); |
| 326 | }, |
| 327 | bind(&onNackCb), |
| 328 | bind(&timeoutCb)); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 329 | } |
| 330 | else { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 331 | size_t caIndex; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 332 | try { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 333 | caIndex = std::stoul(caIndexS); |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 334 | } |
| 335 | catch (const std::exception& e) { |
| 336 | std::cerr << "Your input is neither NONE nor a valid index. Exit" << std::endl; |
| 337 | return; |
| 338 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 339 | if (caIndex >= count) { |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 340 | std::cerr << "Your input is not an existing index. Exit" << std::endl; |
| 341 | return; |
| 342 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 343 | auto itemIterator = caCache.m_caItems.cbegin(); |
| 344 | std::advance(itemIterator, caIndex); |
| 345 | auto targetCaItem = *itemIterator; |
| 346 | runProbe(targetCaItem); |
| 347 | } |
| 348 | } |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 349 | |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 350 | static void |
| 351 | runProbe(CaProfile profile) |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 352 | { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 353 | std::cerr << "\n***************************************\n" |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 354 | << "Step " << nStep++ |
| 355 | << ": Do you know your identity name to be certified by CA " |
| 356 | << profile.m_caPrefix.toUri() |
| 357 | << " already? Type in YES or NO" << std::endl; |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 358 | bool validAnswer = false; |
| 359 | while (!validAnswer) { |
| 360 | std::string answer; |
| 361 | getline(std::cin, answer); |
| 362 | boost::algorithm::to_lower(answer); |
| 363 | if (answer == "yes") { |
| 364 | validAnswer = true; |
| 365 | std::cerr << "You answered YES" << std::endl; |
| 366 | std::cerr << "\n***************************************\n" |
| 367 | << "Step " << nStep++ |
Zhiyi Zhang | 6bb1d08 | 2020-10-08 14:25:21 -0700 | [diff] [blame] | 368 | << ": Please type in the full identity name you want to get (with CA prefix " |
| 369 | << profile.m_caPrefix.toUri() |
| 370 | << "):" << std::endl; |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 371 | std::string identityNameStr; |
| 372 | getline(std::cin, identityNameStr); |
| 373 | runNew(profile, Name(identityNameStr)); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 374 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 375 | else if (answer == "no") { |
| 376 | validAnswer = true; |
| 377 | std::cerr << "You answered NO" << std::endl; |
| 378 | std::cerr << "\n***************************************\n" |
| 379 | << "Step " << nStep++ << ": Please provide information for name assignment" << std::endl; |
| 380 | auto capturedParams = captureParams(profile.m_probeParameterKeys); |
| 381 | face.expressInterest(*Requester::genProbeInterest(profile, std::move(capturedParams)), |
| 382 | bind(&probeCb, _2, profile), bind(&onNackCb), bind(&timeoutCb)); |
| 383 | } |
| 384 | else { |
| 385 | std::cerr << "Invalid answer. Type in YES or NO" << std::endl; |
| 386 | } |
| 387 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 388 | } |
| 389 | |
| 390 | static void |
| 391 | runNew(CaProfile profile, Name identityName) |
| 392 | { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 393 | int validityPeriod = captureValidityPeriod(); |
| 394 | auto now = time::system_clock::now(); |
| 395 | std::cerr << "The validity period of your certificate will be: " << validityPeriod << " hours" << std::endl; |
Zhiyi Zhang | 3243728 | 2020-10-10 16:15:37 -0700 | [diff] [blame] | 396 | requesterState =std::make_shared<RequesterState>(keyChain, profile, RequestType::NEW); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 397 | auto interest = Requester::genNewInterest(*requesterState, identityName, now, now + time::hours(validityPeriod)); |
| 398 | if (interest != nullptr) { |
| 399 | face.expressInterest(*interest, bind(&newCb, _2), bind(&onNackCb), bind(&timeoutCb)); |
| 400 | } |
| 401 | else { |
| 402 | std::cerr << "Cannot generate the Interest for NEW step. Exit" << std::endl; |
| 403 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 404 | } |
| 405 | |
| 406 | static void |
| 407 | runChallenge(const std::string& challengeType) |
| 408 | { |
Zhiyi Zhang | c5d93a9 | 2020-10-14 17:07:35 -0700 | [diff] [blame] | 409 | std::vector<std::tuple<std::string, std::string>> requirement; |
| 410 | try { |
| 411 | requirement = Requester::selectOrContinueChallenge(*requesterState, challengeType); |
| 412 | } |
| 413 | catch (const std::exception& e) { |
| 414 | std::cerr << "Error. Cannot successfully load the Challenge Module with error: " << std::string(e.what()) |
| 415 | << "Exit." << std::endl; |
| 416 | exit(1); |
| 417 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 418 | if (requirement.size() > 0) { |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 419 | std::cerr << "\n***************************************\n" |
| 420 | << "Step " << nStep |
| 421 | << ": Please provide parameters used for Identity Verification Challenge" << std::endl; |
| 422 | captureParams(requirement); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 423 | } |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 424 | face.expressInterest(*Requester::genChallengeInterest(*requesterState, std::move(requirement)), |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 425 | bind(&challengeCb, _2), bind(&onNackCb), bind(&timeoutCb)); |
Zhiyi Zhang | af7c290 | 2019-03-14 22:13:21 -0700 | [diff] [blame] | 426 | } |
| 427 | |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 428 | static void |
| 429 | handleSignal(const boost::system::error_code& error, int signalNum) |
| 430 | { |
| 431 | if (error) { |
| 432 | return; |
| 433 | } |
| 434 | const char* signalName = ::strsignal(signalNum); |
| 435 | std::cerr << "Exiting on signal "; |
| 436 | if (signalName == nullptr) { |
| 437 | std::cerr << signalNum; |
| 438 | } |
| 439 | else { |
| 440 | std::cerr << signalName; |
| 441 | } |
| 442 | std::cerr << std::endl; |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 443 | if (requesterState) { |
| 444 | Requester::endSession(*requesterState); |
| 445 | } |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 446 | face.getIoService().stop(); |
tylerliu | feabfdc | 2020-10-03 15:09:58 -0700 | [diff] [blame] | 447 | exit(1); |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 448 | } |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 449 | |
| 450 | int |
| 451 | main(int argc, char* argv[]) |
| 452 | { |
Zhiyi Zhang | ad9e04f | 2020-03-27 12:04:31 -0700 | [diff] [blame] | 453 | boost::asio::signal_set terminateSignals(face.getIoService()); |
| 454 | terminateSignals.add(SIGINT); |
| 455 | terminateSignals.add(SIGTERM); |
| 456 | terminateSignals.async_wait(handleSignal); |
| 457 | |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 458 | namespace po = boost::program_options; |
Zhiyi Zhang | 840afd9 | 2020-10-21 13:24:08 -0700 | [diff] [blame] | 459 | std::string configFilePath = std::string(NDNCERT_SYSCONFDIR) + "/ndncert/client.conf"; |
Zhiyi Zhang | 3670683 | 2019-07-04 21:33:03 -0700 | [diff] [blame] | 460 | po::options_description description("General Usage\n ndncert-client [-h] [-c] [-v]\n"); |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 461 | description.add_options()("help,h", "produce help message")("config-file,c", po::value<std::string>(&configFilePath), "configuration file name"); |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 462 | po::positional_options_description p; |
| 463 | |
| 464 | po::variables_map vm; |
| 465 | try { |
| 466 | po::store(po::command_line_parser(argc, argv).options(description).positional(p).run(), vm); |
| 467 | po::notify(vm); |
| 468 | } |
| 469 | catch (const std::exception& e) { |
| 470 | std::cerr << "ERROR: " << e.what() << std::endl; |
| 471 | return 1; |
| 472 | } |
| 473 | if (vm.count("help") != 0) { |
| 474 | std::cerr << description << std::endl; |
| 475 | return 0; |
| 476 | } |
Zhiyi Zhang | 837406d | 2020-10-05 22:01:31 -0700 | [diff] [blame] | 477 | selectCaProfile(configFilePath); |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 478 | face.processEvents(); |
| 479 | return 0; |
| 480 | } |
| 481 | |
Zhiyi Zhang | e4891b7 | 2020-10-10 15:11:57 -0700 | [diff] [blame] | 482 | } // namespace ndncert |
| 483 | } // namespace ndn |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 484 | |
Zhiyi Zhang | 48f2378 | 2020-09-28 12:11:24 -0700 | [diff] [blame] | 485 | int |
| 486 | main(int argc, char* argv[]) |
Zhiyi Zhang | 08e0e98 | 2017-03-01 10:10:42 -0800 | [diff] [blame] | 487 | { |
| 488 | return ndn::ndncert::main(argc, argv); |
| 489 | } |