2 Cassiopeia - CAcert signing module
3 Copyright (C) 2014 CAcert Inc.
5 This program is free software; you can redistribute it and/or modify
6 it under the terms of the GNU General Public License as published by
7 the Free Software Foundation; either version 2 of the License, or
8 (at your option) any later version.
10 This program is distributed in the hope that it will be useful,
11 but WITHOUT ANY WARRANTY; without even the implied warranty of
12 MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 GNU General Public License for more details.
15 You should have received a copy of the GNU General Public License along
16 with this program; if not, write to the Free Software Foundation, Inc.,
17 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
28 #include "simpleOpensslSigner.h"
37 std::vector<Profile> profiles;
38 std::string sqlHost, sqlUser, sqlPass, sqlDB;
40 std::string writeBackFile( uint32_t serial, std::string cert ) {
41 std::string filename = "keys";
42 mkdir( filename.c_str(), 0755 );
44 mkdir( filename.c_str(), 0755 );
45 filename += "/" + std::to_string( serial / 1000 );
46 mkdir( filename.c_str(), 0755 );
47 filename += "/" + std::to_string( serial ) + ".crt";
49 file.open( filename.c_str() );
52 std::cout << "wrote to " << filename << std::endl;
56 int main( int argc, const char* argv[] ) {
60 config.open( "config.txt" );
62 if( !config.is_open() ) {
63 std::cerr << "config missing" << std::endl;
69 while( config >> line1 ) {
70 if( line1[0] == '#' ) {
74 int splitter = line1.find( "=" );
76 if( splitter == -1 ) {
77 std::cerr << "Ignoring malformed config line: " << line1 << std::endl;
81 std::string key = line1.substr( 0, splitter );
82 std::string value = line1.substr( splitter + 1 );
84 if( key == "key.directory" ) {
87 } else if( key == "sql.host" ) {
89 } else if( key == "sql.user" ) {
91 } else if( key == "sql.password" ) {
93 } else if( key == "sql.database" ) {
97 if( key.compare( 0, 8, "profile." ) == 0 ) {
98 int numE = key.find( ".", 9 );
101 std::cout << "invalid line: " << line1 << std::endl;
105 unsigned int i = atoi( key.substr( 8, numE - 8 ).c_str() );
106 std::string rest = key.substr( numE + 1 );
108 if( i + 1 > profiles.size() ) {
109 profiles.resize( i + 1 );
112 if( rest == "key" ) {
113 profiles[i].key = value;
114 } else if( rest == "cert" ) {
115 profiles[i].cert = value;
117 std::cout << "invalid line: " << line1 << std::endl;
123 std::cout << profiles.size() << " profiles loaded." << std::endl;
126 std::cerr << "Missing config property key.directory" << std::endl;
132 std::shared_ptr<JobProvider> jp( new MySQLJobProvider( sqlHost, sqlUser, sqlPass, sqlDB ) );
133 std::shared_ptr<Signer> sign( new SimpleOpensslSigner() );
136 std::shared_ptr<Job> job = jp->fetchJob();
139 std::cout << "Nothing to work on" << std::endl;
144 if( job->task == "sign" ) {
146 std::shared_ptr<TBSCertificate> cert = jp->fetchTBSCert( job );
149 std::cout << "wasn't able to load CSR" << std::endl;
153 std::cout << "Found a CSR at '" << cert->csr << "' signing" << std::endl;
154 std::ifstream t( cert->csr );
155 cert->csr_content = std::string( std::istreambuf_iterator<char>( t ), std::istreambuf_iterator<char>() );
157 std::shared_ptr<SignedCertificate> res = sign->sign( cert );
158 std::string fn = writeBackFile( atoi( job->target.c_str() ), res->certificate );
160 jp->writeBack( job, res );
161 } catch( const char* c ) {
162 std::cerr << c << std::endl;
166 std::cout << "Unknown job type" << job->task << std::endl;
169 if( DAEMON && !jp->finishJob( job ) ) {