annotate OrthancFramework/Sources/Pkcs11.cpp @ 5640:f7adfb22e20e

updated copyright, as Orthanc Team now replaces Osimis
author Sebastien Jodogne <s.jodogne@gmail.com>
date Thu, 30 May 2024 21:19:57 +0200
parents 48b8dae6dc77
children
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
1 /**
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
2 * Orthanc - A Lightweight, RESTful DICOM Store
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
3 * Copyright (C) 2012-2016 Sebastien Jodogne, Medical Physics
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
4 * Department, University Hospital of Liege, Belgium
5640
f7adfb22e20e updated copyright, as Orthanc Team now replaces Osimis
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 5485
diff changeset
5 * Copyright (C) 2017-2023 Osimis S.A., Belgium
f7adfb22e20e updated copyright, as Orthanc Team now replaces Osimis
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 5485
diff changeset
6 * Copyright (C) 2024-2024 Orthanc Team SRL, Belgium
5485
48b8dae6dc77 upgrade to year 2024
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 5185
diff changeset
7 * Copyright (C) 2021-2024 Sebastien Jodogne, ICTEAM UCLouvain, Belgium
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
8 *
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
9 * This program is free software: you can redistribute it and/or
4119
bf7b9edf6b81 re-licensing the OrthancFramework to LGPL, in order to license Stone of Orthanc under LGPL
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4044
diff changeset
10 * modify it under the terms of the GNU Lesser General Public License
bf7b9edf6b81 re-licensing the OrthancFramework to LGPL, in order to license Stone of Orthanc under LGPL
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4044
diff changeset
11 * as published by the Free Software Foundation, either version 3 of
bf7b9edf6b81 re-licensing the OrthancFramework to LGPL, in order to license Stone of Orthanc under LGPL
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4044
diff changeset
12 * the License, or (at your option) any later version.
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
13 *
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
14 * This program is distributed in the hope that it will be useful, but
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
15 * WITHOUT ANY WARRANTY; without even the implied warranty of
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
16 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
4119
bf7b9edf6b81 re-licensing the OrthancFramework to LGPL, in order to license Stone of Orthanc under LGPL
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4044
diff changeset
17 * Lesser General Public License for more details.
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
18 *
4119
bf7b9edf6b81 re-licensing the OrthancFramework to LGPL, in order to license Stone of Orthanc under LGPL
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4044
diff changeset
19 * You should have received a copy of the GNU Lesser General Public
bf7b9edf6b81 re-licensing the OrthancFramework to LGPL, in order to license Stone of Orthanc under LGPL
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4044
diff changeset
20 * License along with this program. If not, see
bf7b9edf6b81 re-licensing the OrthancFramework to LGPL, in order to license Stone of Orthanc under LGPL
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4044
diff changeset
21 * <http://www.gnu.org/licenses/>.
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
22 **/
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
23
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
24
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
25 #include "PrecompiledHeaders.h"
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
26 #include "Pkcs11.h"
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
27
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
28
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
29 #if defined(OPENSSL_NO_RSA) || defined(OPENSSL_NO_EC) || defined(OPENSSL_NO_ECDSA) || defined(OPENSSL_NO_ECDH)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
30 # error OpenSSL was compiled without support for RSA, EC, ECDSA or ECDH
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
31 #endif
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
32
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
33
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
34 #include "Logging.h"
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
35 #include "OrthancException.h"
2145
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2136
diff changeset
36 #include "SystemToolbox.h"
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
37
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
38 extern "C"
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
39 {
2145
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2136
diff changeset
40 # include <libp11/engine.h> // This is P11's "engine.h"
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2136
diff changeset
41 # include <libp11/libp11.h>
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
42 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
43
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
44 #include <openssl/engine.h>
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
45
4741
a6b7c29f5118 compiler warning about openssl license
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4437
diff changeset
46 #if OPENSSL_VERSION_NUMBER < 0x30000000L
5073
859f3668c181 replaced macro "#warning" by "#pragma message" for Visual Studio
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4892
diff changeset
47 # if defined(_MSC_VER)
859f3668c181 replaced macro "#warning" by "#pragma message" for Visual Studio
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4892
diff changeset
48 # pragma message("You are linking Orthanc against OpenSSL 1.x, whose license is incompatible with the GPLv3+ used by Orthanc. Please update to OpenSSL 3.x, that uses the Apache 2 license.")
859f3668c181 replaced macro "#warning" by "#pragma message" for Visual Studio
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4892
diff changeset
49 # else
859f3668c181 replaced macro "#warning" by "#pragma message" for Visual Studio
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4892
diff changeset
50 # warning You are linking Orthanc against OpenSSL 1.x, whose license is incompatible with the GPLv3+ used by Orthanc. Please update to OpenSSL 3.x, that uses the Apache 2 license.
859f3668c181 replaced macro "#warning" by "#pragma message" for Visual Studio
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4892
diff changeset
51 # endif
4741
a6b7c29f5118 compiler warning about openssl license
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4437
diff changeset
52 #endif
a6b7c29f5118 compiler warning about openssl license
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 4437
diff changeset
53
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
54
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
55 namespace Orthanc
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
56 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
57 namespace Pkcs11
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
58 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
59 static const char* PKCS11_ENGINE_ID = "pkcs11";
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
60 static const char* PKCS11_ENGINE_NAME = "PKCS#11 for Orthanc";
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
61 static const ENGINE_CMD_DEFN PKCS11_ENGINE_COMMANDS[] =
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
62 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
63 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
64 CMD_MODULE_PATH,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
65 "MODULE_PATH",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
66 "Specifies the path to the PKCS#11 module shared library",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
67 ENGINE_CMD_FLAG_STRING
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
68 },
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
69 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
70 CMD_PIN,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
71 "PIN",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
72 "Specifies the pin code",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
73 ENGINE_CMD_FLAG_STRING
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
74 },
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
75 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
76 CMD_VERBOSE,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
77 "VERBOSE",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
78 "Print additional details",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
79 ENGINE_CMD_FLAG_NO_INPUT
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
80 },
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
81 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
82 CMD_LOAD_CERT_CTRL,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
83 "LOAD_CERT_CTRL",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
84 "Get the certificate from card",
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
85 ENGINE_CMD_FLAG_INTERNAL
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
86 },
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
87 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
88 0,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
89 NULL,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
90 NULL,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
91 0
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
92 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
93 };
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
94
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
95
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
96 static bool pkcs11Initialized_ = false;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
97 static ENGINE_CTX *context_ = NULL;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
98
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
99 static int EngineInitialize(ENGINE* engine)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
100 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
101 if (context_ == NULL)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
102 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
103 return 0;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
104 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
105 else
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
106 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
107 return pkcs11_init(context_);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
108 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
109 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
110
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
111
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
112 static int EngineFinalize(ENGINE* engine)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
113 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
114 if (context_ == NULL)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
115 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
116 return 0;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
117 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
118 else
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
119 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
120 return pkcs11_finish(context_);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
121 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
122 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
123
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
124
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
125 static int EngineDestroy(ENGINE* engine)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
126 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
127 return (context_ == NULL ? 0 : 1);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
128 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
129
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
130
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
131 static int EngineControl(ENGINE *engine,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
132 int command,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
133 long i,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
134 void *p,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
135 void (*f) ())
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
136 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
137 if (context_ == NULL)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
138 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
139 return 0;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
140 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
141 else
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
142 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
143 return pkcs11_engine_ctrl(context_, command, i, p, f);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
144 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
145 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
146
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
147
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
148 static EVP_PKEY *EngineLoadPublicKey(ENGINE *engine,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
149 const char *s_key_id,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
150 UI_METHOD *ui_method,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
151 void *callback_data)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
152 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
153 if (context_ == NULL)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
154 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
155 return 0;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
156 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
157 else
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
158 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
159 return pkcs11_load_public_key(context_, s_key_id, ui_method, callback_data);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
160 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
161 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
162
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
163
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
164 static EVP_PKEY *EngineLoadPrivateKey(ENGINE *engine,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
165 const char *s_key_id,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
166 UI_METHOD *ui_method,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
167 void *callback_data)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
168 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
169 if (context_ == NULL)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
170 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
171 return 0;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
172 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
173 else
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
174 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
175 return pkcs11_load_private_key(context_, s_key_id, ui_method, callback_data);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
176 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
177 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
178
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
179
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
180 static ENGINE* LoadEngine()
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
181 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
182 // This function creates an engine for PKCS#11 and inspired by
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
183 // the "ENGINE_load_dynamic" function from OpenSSL, in file
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
184 // "crypto/engine/eng_dyn.c"
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
185
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
186 ENGINE* engine = ENGINE_new();
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
187 if (!engine)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
188 {
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
189 throw OrthancException(ErrorCode_InternalError,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
190 "Cannot create an OpenSSL engine for PKCS#11");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
191 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
192
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
193 // Create a PKCS#11 context using libp11
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
194 context_ = pkcs11_new();
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
195 if (!context_)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
196 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
197 ENGINE_free(engine);
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
198 throw OrthancException(ErrorCode_InternalError,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
199 "Cannot create a libp11 context for PKCS#11");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
200 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
201
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
202 if (!ENGINE_set_id(engine, PKCS11_ENGINE_ID) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
203 !ENGINE_set_name(engine, PKCS11_ENGINE_NAME) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
204 !ENGINE_set_cmd_defns(engine, PKCS11_ENGINE_COMMANDS) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
205
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
206 // Register the callback functions
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
207 !ENGINE_set_init_function(engine, EngineInitialize) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
208 !ENGINE_set_finish_function(engine, EngineFinalize) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
209 !ENGINE_set_destroy_function(engine, EngineDestroy) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
210 !ENGINE_set_ctrl_function(engine, EngineControl) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
211 !ENGINE_set_load_pubkey_function(engine, EngineLoadPublicKey) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
212 !ENGINE_set_load_privkey_function(engine, EngineLoadPrivateKey) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
213
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
214 !ENGINE_set_RSA(engine, PKCS11_get_rsa_method()) ||
3723
cc6d4edfe8fe fix pkcs11 compilation
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 3640
diff changeset
215
cc6d4edfe8fe fix pkcs11 compilation
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 3640
diff changeset
216 #if OPENSSL_VERSION_NUMBER < 0x10100000L // OpenSSL 1.0.2
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
217 !ENGINE_set_ECDSA(engine, PKCS11_get_ecdsa_method()) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
218 !ENGINE_set_ECDH(engine, PKCS11_get_ecdh_method()) ||
3723
cc6d4edfe8fe fix pkcs11 compilation
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 3640
diff changeset
219 #else
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
220 !ENGINE_set_EC(engine, PKCS11_get_ec_key_method()) ||
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
221 #endif
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
222
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
223 // Make OpenSSL know about our PKCS#11 engine
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
224 !ENGINE_add(engine))
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
225 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
226 pkcs11_finish(context_);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
227 ENGINE_free(engine);
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
228 throw OrthancException(ErrorCode_InternalError,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
229 "Cannot initialize the OpenSSL engine for PKCS#11");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
230 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
231
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
232 // If the "ENGINE_add" worked, it gets a structural
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
233 // reference. We release our just-created reference.
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
234 ENGINE_free(engine);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
235
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
236 return ENGINE_by_id(PKCS11_ENGINE_ID);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
237 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
238
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
239
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
240 bool IsInitialized()
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
241 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
242 return pkcs11Initialized_;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
243 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
244
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
245 const char* GetEngineIdentifier()
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
246 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
247 return PKCS11_ENGINE_ID;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
248 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
249
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
250 void Initialize(const std::string& module,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
251 const std::string& pin,
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
252 bool verbose)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
253 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
254 if (pkcs11Initialized_)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
255 {
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
256 throw OrthancException(ErrorCode_BadSequenceOfCalls,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
257 "The PKCS#11 engine has already been initialized");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
258 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
259
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
260 if (module.empty() ||
2145
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2136
diff changeset
261 !SystemToolbox::IsRegularFile(module))
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
262 {
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
263 throw OrthancException(
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
264 ErrorCode_InexistentFile,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
265 "The PKCS#11 module must be a path to one shared library (DLL or .so)");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
266 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
267
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
268 ENGINE* engine = LoadEngine();
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
269 if (!engine)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
270 {
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
271 throw OrthancException(ErrorCode_InternalError,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
272 "Cannot create an OpenSSL engine for PKCS#11");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
273 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
274
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
275 if (!ENGINE_ctrl_cmd_string(engine, "MODULE_PATH", module.c_str(), 0))
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
276 {
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
277 throw OrthancException(ErrorCode_InternalError,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
278 "Cannot configure the OpenSSL dynamic engine for PKCS#11");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
279 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
280
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
281 if (verbose)
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
282 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
283 ENGINE_ctrl_cmd_string(engine, "VERBOSE", NULL, 0);
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
284 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
285
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
286 if (!pin.empty() &&
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
287 !ENGINE_ctrl_cmd_string(engine, "PIN", pin.c_str(), 0))
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
288 {
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
289 throw OrthancException(ErrorCode_InternalError,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
290 "Cannot set the PIN code for PKCS#11");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
291 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
292
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
293 if (!ENGINE_init(engine))
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
294 {
2954
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
295 throw OrthancException(ErrorCode_InternalError,
d924f9bb61cc taking advantage of details in OrthancException
Sebastien Jodogne <s.jodogne@gmail.com>
parents: 2447
diff changeset
296 "Cannot initialize the OpenSSL dynamic engine for PKCS#11");
2025
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
297 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
298
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
299 LOG(WARNING) << "The PKCS#11 engine has been successfully initialized";
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
300 pkcs11Initialized_ = true;
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
301 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
302
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
303
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
304 void Finalize()
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
305 {
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
306 // Nothing to do, the unregistration of the engine is
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
307 // automatically done by OpenSSL
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
308 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
309 }
e7e1858d9504 reorganization
Sebastien Jodogne <s.jodogne@gmail.com>
parents:
diff changeset
310 }