blob: 4f0971d640b3338d88a67057eb2dfcfb0ec3a5f3 [file] [log] [blame]
Zhiyi Zhang91c846b2017-04-12 14:16:31 -07001/* -*- Mode:C++; c-file-style:"gnu"; indent-tabs-mode:nil; -*- */
Davide Pesaventob48bbda2020-07-27 19:41:37 -04002/*
3 * Copyright (c) 2017-2020, Regents of the University of California.
Zhiyi Zhang91c846b2017-04-12 14:16:31 -07004 *
5 * This file is part of ndncert, a certificate management system based on NDN.
6 *
7 * ndncert is free software: you can redistribute it and/or modify it under the terms
8 * of the GNU General Public License as published by the Free Software Foundation, either
9 * version 3 of the License, or (at your option) any later version.
10 *
11 * ndncert is distributed in the hope that it will be useful, but WITHOUT ANY
12 * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A
13 * PARTICULAR PURPOSE. See the GNU General Public License for more details.
14 *
15 * You should have received copies of the GNU General Public License along with
16 * ndncert, e.g., in COPYING.md file. If not, see <http://www.gnu.org/licenses/>.
17 *
18 * See AUTHORS.md for complete list of ndncert authors and contributors.
19 */
20
Zhiyi Zhangb041d442020-10-22 21:57:11 -070021#include "detail/ca-sqlite.hpp"
Davide Pesaventob48bbda2020-07-27 19:41:37 -040022
Zhiyi Zhanga749f442020-09-29 17:19:51 -070023#include <sqlite3.h>
Zhiyi Zhanga749f442020-09-29 17:19:51 -070024#include <boost/filesystem.hpp>
tylerliua7bea662020-10-08 18:51:02 -070025#include <ndn-cxx/security/validation-policy.hpp>
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070026#include <ndn-cxx/util/sqlite3-statement.hpp>
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070027
28namespace ndn {
29namespace ndncert {
30
Zhiyi Zhang59812232020-10-12 13:11:35 -070031using namespace ndn::util;
Davide Pesaventob48bbda2020-07-27 19:41:37 -040032const std::string CaSqlite::STORAGE_TYPE = "ca-storage-sqlite3";
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070033
34NDNCERT_REGISTER_CA_STORAGE(CaSqlite);
35
Zhiyi Zhang59812232020-10-12 13:11:35 -070036std::string
37convertJson2String(const JsonSection& json)
38{
39 std::stringstream ss;
40 boost::property_tree::write_json(ss, json);
41 return ss.str();
42}
43
44JsonSection
45convertString2Json(const std::string& jsonContent)
46{
47 std::istringstream ss(jsonContent);
48 JsonSection json;
49 boost::property_tree::json_parser::read_json(ss, json);
50 return json;
51}
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070052
53static const std::string INITIALIZATION = R"_DBTEXT_(
54CREATE TABLE IF NOT EXISTS
tylerliu8704d032020-06-23 10:18:15 -070055 CaStates(
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070056 id INTEGER PRIMARY KEY,
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -070057 request_id BLOB NOT NULL,
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070058 ca_name BLOB NOT NULL,
tylerliu182bc532020-09-25 01:54:45 -070059 request_type INTEGER NOT NULL,
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070060 status INTEGER NOT NULL,
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070061 cert_request BLOB NOT NULL,
62 challenge_type TEXT,
Zhiyi Zhanga749f442020-09-29 17:19:51 -070063 challenge_status TEXT,
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -070064 challenge_tp TEXT,
65 remaining_tries INTEGER,
Zhiyi Zhang5f749a22019-06-12 17:02:33 -070066 remaining_time INTEGER,
tylerliu8e170d62020-09-30 01:31:53 -070067 challenge_secrets TEXT,
Zhiyi Zhang222810b2020-10-16 21:50:35 -070068 encryption_key BLOB NOT NULL,
69 aes_block_counter INTEGER
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070070 );
71CREATE UNIQUE INDEX IF NOT EXISTS
tylerliu8704d032020-06-23 10:18:15 -070072 CaStateIdIndex ON CaStates(request_id);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070073)_DBTEXT_";
74
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -070075CaSqlite::CaSqlite(const Name& caName, const std::string& path)
Zhiyi Zhanga749f442020-09-29 17:19:51 -070076 : CaStorage()
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070077{
78 // Determine the path of sqlite db
79 boost::filesystem::path dbDir;
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -070080 if (!path.empty()) {
81 dbDir = boost::filesystem::path(path);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070082 }
83 else {
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -070084 std::string dbName = caName.toUri();
85 std::replace(dbName.begin(), dbName.end(), '/', '_');
86 dbName += ".db";
87 if (getenv("HOME") != nullptr) {
88 dbDir = boost::filesystem::path(getenv("HOME")) / ".ndncert";
89 }
90 else {
91 dbDir = boost::filesystem::current_path() / ".ndncert";
92 }
93 boost::filesystem::create_directories(dbDir);
94 dbDir /= dbName;
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070095 }
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070096
97 // open and initialize database
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -070098 int result = sqlite3_open_v2(dbDir.c_str(), &m_database,
Zhiyi Zhang91c846b2017-04-12 14:16:31 -070099 SQLITE_OPEN_READWRITE | SQLITE_OPEN_CREATE,
100#ifdef NDN_CXX_DISABLE_SQLITE3_FS_LOCKING
101 "unix-dotfile"
102#else
103 nullptr
104#endif
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700105 );
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700106 if (result != SQLITE_OK)
tylerliu41c11532020-10-10 16:14:45 -0700107 NDN_THROW(std::runtime_error("CaSqlite DB cannot be opened/created: " + dbDir.string()));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700108
109 // initialize database specific tables
110 char* errorMessage = nullptr;
Davide Pesaventob48bbda2020-07-27 19:41:37 -0400111 result = sqlite3_exec(m_database, INITIALIZATION.data(),
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700112 nullptr, nullptr, &errorMessage);
113 if (result != SQLITE_OK && errorMessage != nullptr) {
114 sqlite3_free(errorMessage);
tylerliu41c11532020-10-10 16:14:45 -0700115 NDN_THROW(std::runtime_error("CaSqlite DB cannot be initialized"));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700116 }
117}
118
119CaSqlite::~CaSqlite()
120{
121 sqlite3_close(m_database);
122}
123
tylerliu8704d032020-06-23 10:18:15 -0700124CaState
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700125CaSqlite::getRequest(const RequestID& requestId)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700126{
127 Sqlite3Statement statement(m_database,
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700128 R"_SQLTEXT_(SELECT id, ca_name, status,
129 challenge_status, cert_request,
130 challenge_type, challenge_secrets,
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700131 challenge_tp, remaining_tries, remaining_time,
132 request_type, encryption_key, aes_block_counter
tylerliu8704d032020-06-23 10:18:15 -0700133 FROM CaStates where request_id = ?)_SQLTEXT_");
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700134 statement.bind(1, requestId.data(), requestId.size(), SQLITE_TRANSIENT);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700135
136 if (statement.step() == SQLITE_ROW) {
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700137 Name caName(statement.getBlock(1));
138 auto status = static_cast<Status>(statement.getInt(2));
139 auto challengeStatus = statement.getString(3);
tylerliua7bea662020-10-08 18:51:02 -0700140 security::Certificate cert(statement.getBlock(4));
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700141 auto challengeType = statement.getString(5);
142 auto challengeSecrets = statement.getString(6);
143 auto challengeTp = statement.getString(7);
144 auto remainingTries = statement.getInt(8);
145 auto remainingTime = statement.getInt(9);
146 auto requestType = static_cast<RequestType>(statement.getInt(10));
tylerliu8e170d62020-09-30 01:31:53 -0700147 auto encryptionKey = statement.getBlock(11);
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700148 auto aesCounter = statement.getInt(12);
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700149 if (challengeType != "") {
tylerliu8704d032020-06-23 10:18:15 -0700150 return CaState(caName, requestId, requestType, status, cert,
151 challengeType, challengeStatus, time::fromIsoString(challengeTp),
152 remainingTries, time::seconds(remainingTime),
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700153 convertString2Json(challengeSecrets), encryptionKey, aesCounter);
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700154 }
155 else {
tylerliu8704d032020-06-23 10:18:15 -0700156 return CaState(caName, requestId, requestType, status, cert, encryptionKey);
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700157 }
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700158 }
159 else {
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700160 NDN_THROW(std::runtime_error("Request " + toHex(requestId.data(), requestId.size()) + " cannot be fetched from database"));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700161 }
162}
163
164void
tylerliu8704d032020-06-23 10:18:15 -0700165CaSqlite::addRequest(const CaState& request)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700166{
Zhiyi Zhangb8bbc642020-09-29 14:08:26 -0700167 Sqlite3Statement statement(
168 m_database,
tylerliu8704d032020-06-23 10:18:15 -0700169 R"_SQLTEXT_(INSERT OR ABORT INTO CaStates (request_id, ca_name, status, request_type,
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700170 cert_request, challenge_type, challenge_status, challenge_secrets,
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700171 challenge_tp, remaining_tries, remaining_time, encryption_key, aes_block_counter)
172 values (?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?))_SQLTEXT_");
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700173 statement.bind(1, request.m_requestId.data(), request.m_requestId.size(), SQLITE_TRANSIENT);
Zhiyi Zhangb8bbc642020-09-29 14:08:26 -0700174 statement.bind(2, request.m_caPrefix.wireEncode(), SQLITE_TRANSIENT);
175 statement.bind(3, static_cast<int>(request.m_status));
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700176 statement.bind(4, static_cast<int>(request.m_requestType));
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700177 statement.bind(5, request.m_cert.wireEncode(), SQLITE_TRANSIENT);
178 statement.bind(12, request.m_encryptionKey, SQLITE_TRANSIENT);
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700179 statement.bind(13, request.m_aesBlockCounter);
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700180 if (request.m_challengeState) {
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700181 statement.bind(6, request.m_challengeType, SQLITE_TRANSIENT);
182 statement.bind(7, request.m_challengeState->m_challengeStatus, SQLITE_TRANSIENT);
183 statement.bind(8, convertJson2String(request.m_challengeState->m_secrets),
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700184 SQLITE_TRANSIENT);
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700185 statement.bind(9, time::toIsoString(request.m_challengeState->m_timestamp), SQLITE_TRANSIENT);
186 statement.bind(10, request.m_challengeState->m_remainingTries);
187 statement.bind(11, request.m_challengeState->m_remainingTime.count());
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700188 }
Zhiyi Zhangb8bbc642020-09-29 14:08:26 -0700189 if (statement.step() != SQLITE_DONE) {
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700190 NDN_THROW(std::runtime_error("Request " + toHex(request.m_requestId.data(), request.m_requestId.size()) + " cannot be added to database"));
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700191 }
192}
193
194void
tylerliu8704d032020-06-23 10:18:15 -0700195CaSqlite::updateRequest(const CaState& request)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700196{
197 Sqlite3Statement statement(m_database,
tylerliu8704d032020-06-23 10:18:15 -0700198 R"_SQLTEXT_(UPDATE CaStates
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700199 SET status = ?, challenge_type = ?, challenge_status = ?, challenge_secrets = ?,
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700200 challenge_tp = ?, remaining_tries = ?, remaining_time = ?, aes_block_counter = ?
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700201 WHERE request_id = ?)_SQLTEXT_");
Zhiyi Zhang48f23782020-09-28 12:11:24 -0700202 statement.bind(1, static_cast<int>(request.m_status));
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700203 statement.bind(2, request.m_challengeType, SQLITE_TRANSIENT);
204 if (request.m_challengeState) {
205 statement.bind(3, request.m_challengeState->m_challengeStatus, SQLITE_TRANSIENT);
Zhiyi Zhang14f0bc82020-10-12 13:02:23 -0700206 statement.bind(4, convertJson2String(request.m_challengeState->m_secrets), SQLITE_TRANSIENT);
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700207 statement.bind(5, time::toIsoString(request.m_challengeState->m_timestamp), SQLITE_TRANSIENT);
208 statement.bind(6, request.m_challengeState->m_remainingTries);
209 statement.bind(7, request.m_challengeState->m_remainingTime.count());
210 }
211 else {
212 statement.bind(3, "", SQLITE_TRANSIENT);
213 statement.bind(4, "", SQLITE_TRANSIENT);
214 statement.bind(5, "", SQLITE_TRANSIENT);
215 statement.bind(6, 0);
216 statement.bind(7, 0);
217 }
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700218 statement.bind(8, request.m_aesBlockCounter);
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700219 statement.bind(9, request.m_requestId.data(), request.m_requestId.size(), SQLITE_TRANSIENT);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700220
221 if (statement.step() != SQLITE_DONE) {
222 addRequest(request);
223 }
224}
225
tylerliu8704d032020-06-23 10:18:15 -0700226std::list<CaState>
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700227CaSqlite::listAllRequests()
228{
tylerliu8704d032020-06-23 10:18:15 -0700229 std::list<CaState> result;
tylerliu182bc532020-09-25 01:54:45 -0700230 Sqlite3Statement statement(m_database, R"_SQLTEXT_(SELECT id, request_id, ca_name, status,
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700231 challenge_status, cert_request, challenge_type, challenge_secrets,
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700232 challenge_tp, remaining_tries, remaining_time, request_type,
233 encryption_key, aes_block_counter
tylerliu8704d032020-06-23 10:18:15 -0700234 FROM CaStates)_SQLTEXT_");
Davide Pesaventob48bbda2020-07-27 19:41:37 -0400235 while (statement.step() == SQLITE_ROW) {
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700236 RequestID requestId;
237 std::memcpy(requestId.data(), statement.getBlob(1), statement.getSize(1));
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700238 Name caName(statement.getBlock(2));
Zhiyi Zhangc87d52b2020-09-28 22:07:18 -0700239 auto status = static_cast<Status>(statement.getInt(3));
240 auto challengeStatus = statement.getString(4);
tylerliua7bea662020-10-08 18:51:02 -0700241 security::Certificate cert(statement.getBlock(5));
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700242 auto challengeType = statement.getString(6);
243 auto challengeSecrets = statement.getString(7);
244 auto challengeTp = statement.getString(8);
245 auto remainingTries = statement.getInt(9);
246 auto remainingTime = statement.getInt(10);
247 auto requestType = static_cast<RequestType>(statement.getInt(11));
248 auto encryptionKey = statement.getBlock(12);
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700249 auto aesBlockCounter = statement.getInt(13);
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700250 if (challengeType != "") {
tylerliu8704d032020-06-23 10:18:15 -0700251 result.push_back(CaState(caName, requestId, requestType, status, cert,
252 challengeType, challengeStatus, time::fromIsoString(challengeTp),
253 remainingTries, time::seconds(remainingTime),
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700254 convertString2Json(challengeSecrets), encryptionKey, aesBlockCounter));
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700255 }
256 else {
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700257 result.push_back(CaState(caName, requestId, requestType, status, cert, encryptionKey, aesBlockCounter));
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700258 }
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700259 }
260 return result;
261}
262
tylerliu8704d032020-06-23 10:18:15 -0700263std::list<CaState>
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700264CaSqlite::listAllRequests(const Name& caName)
265{
tylerliu8704d032020-06-23 10:18:15 -0700266 std::list<CaState> result;
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700267 Sqlite3Statement statement(m_database,
tylerliu182bc532020-09-25 01:54:45 -0700268 R"_SQLTEXT_(SELECT id, request_id, ca_name, status,
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700269 challenge_status, cert_request, challenge_type, challenge_secrets,
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700270 challenge_tp, remaining_tries, remaining_time, request_type,
271 encryption_key, aes_block_counter
tylerliu8704d032020-06-23 10:18:15 -0700272 FROM CaStates WHERE ca_name = ?)_SQLTEXT_");
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700273 statement.bind(1, caName.wireEncode(), SQLITE_TRANSIENT);
274
Davide Pesaventob48bbda2020-07-27 19:41:37 -0400275 while (statement.step() == SQLITE_ROW) {
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700276 RequestID requestId;
277 std::memcpy(requestId.data(), statement.getBlob(1), statement.getSize(1));
Zhiyi Zhangaf7c2902019-03-14 22:13:21 -0700278 Name caName(statement.getBlock(2));
Zhiyi Zhangc87d52b2020-09-28 22:07:18 -0700279 auto status = static_cast<Status>(statement.getInt(3));
280 auto challengeStatus = statement.getString(4);
tylerliua7bea662020-10-08 18:51:02 -0700281 security::Certificate cert(statement.getBlock(5));
Zhiyi Zhangd1d9f5a2020-10-05 18:04:23 -0700282 auto challengeType = statement.getString(6);
283 auto challengeSecrets = statement.getString(7);
284 auto challengeTp = statement.getString(8);
285 auto remainingTries = statement.getInt(9);
286 auto remainingTime = statement.getInt(10);
287 auto requestType = static_cast<RequestType>(statement.getInt(11));
288 auto encryptionKey = statement.getBlock(12);
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700289 auto aesBlockCounter = statement.getInt(13);
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700290 if (challengeType != "") {
tylerliu8704d032020-06-23 10:18:15 -0700291 result.push_back(CaState(caName, requestId, requestType, status, cert,
292 challengeType, challengeStatus, time::fromIsoString(challengeTp),
293 remainingTries, time::seconds(remainingTime),
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700294 convertString2Json(challengeSecrets), encryptionKey, aesBlockCounter));
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700295 }
296 else {
Zhiyi Zhang222810b2020-10-16 21:50:35 -0700297 result.push_back(CaState(caName, requestId, requestType, status, cert, encryptionKey, aesBlockCounter));
Zhiyi Zhanga749f442020-09-29 17:19:51 -0700298 }
Zhiyi Zhangae123bf2017-04-14 12:24:53 -0700299 }
300 return result;
301}
302
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700303void
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700304CaSqlite::deleteRequest(const RequestID& requestId)
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700305{
306 Sqlite3Statement statement(m_database,
tylerliu8704d032020-06-23 10:18:15 -0700307 R"_SQLTEXT_(DELETE FROM CaStates WHERE request_id = ?)_SQLTEXT_");
Zhiyi Zhang8fdb36b2020-10-18 11:58:51 -0700308 statement.bind(1, requestId.data(), requestId.size(), SQLITE_TRANSIENT);
Zhiyi Zhang91c846b2017-04-12 14:16:31 -0700309 statement.step();
310}
311
Zhiyi Zhange4891b72020-10-10 15:11:57 -0700312} // namespace ndncert
313} // namespace ndn