GCC Code Coverage Report
Directory: ./ Exec Total Coverage
File: usr.bin/openssl/nseq.c Lines: 26 48 54.2 %
Date: 2017-11-13 Branches: 12 24 50.0 %

Line Branch Exec Source
1
/* $OpenBSD: nseq.c,v 1.7 2017/01/20 08:57:12 deraadt Exp $ */
2
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
3
 * project 1999.
4
 */
5
/* ====================================================================
6
 * Copyright (c) 1999 The OpenSSL Project.  All rights reserved.
7
 *
8
 * Redistribution and use in source and binary forms, with or without
9
 * modification, are permitted provided that the following conditions
10
 * are met:
11
 *
12
 * 1. Redistributions of source code must retain the above copyright
13
 *    notice, this list of conditions and the following disclaimer.
14
 *
15
 * 2. Redistributions in binary form must reproduce the above copyright
16
 *    notice, this list of conditions and the following disclaimer in
17
 *    the documentation and/or other materials provided with the
18
 *    distribution.
19
 *
20
 * 3. All advertising materials mentioning features or use of this
21
 *    software must display the following acknowledgment:
22
 *    "This product includes software developed by the OpenSSL Project
23
 *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
24
 *
25
 * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
26
 *    endorse or promote products derived from this software without
27
 *    prior written permission. For written permission, please contact
28
 *    licensing@OpenSSL.org.
29
 *
30
 * 5. Products derived from this software may not be called "OpenSSL"
31
 *    nor may "OpenSSL" appear in their names without prior written
32
 *    permission of the OpenSSL Project.
33
 *
34
 * 6. Redistributions of any form whatsoever must retain the following
35
 *    acknowledgment:
36
 *    "This product includes software developed by the OpenSSL Project
37
 *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
38
 *
39
 * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
40
 * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
41
 * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
42
 * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
43
 * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
44
 * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
45
 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
46
 * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
47
 * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
48
 * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
49
 * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
50
 * OF THE POSSIBILITY OF SUCH DAMAGE.
51
 * ====================================================================
52
 *
53
 * This product includes cryptographic software written by Eric Young
54
 * (eay@cryptsoft.com).  This product includes software written by Tim
55
 * Hudson (tjh@cryptsoft.com).
56
 *
57
 */
58
59
#include <stdio.h>
60
#include <string.h>
61
62
#include "apps.h"
63
64
#include <openssl/err.h>
65
#include <openssl/pem.h>
66
67
static struct {
68
	char *infile;
69
	char *outfile;
70
	int toseq;
71
} nseq_config;
72
73
static struct option nseq_options[] = {
74
	{
75
		.name = "in",
76
		.argname = "file",
77
		.desc = "Input file to read from (default stdin)",
78
		.type = OPTION_ARG,
79
		.opt.arg = &nseq_config.infile,
80
	},
81
	{
82
		.name = "out",
83
		.argname = "file",
84
		.desc = "Output file to write to (default stdout)",
85
		.type = OPTION_ARG,
86
		.opt.arg = &nseq_config.outfile,
87
	},
88
	{
89
		.name = "toseq",
90
		.desc = "Convert certificates to Netscape certificate sequence",
91
		.type = OPTION_FLAG,
92
		.opt.flag = &nseq_config.toseq,
93
	},
94
	{ NULL },
95
};
96
97
static void
98
nseq_usage()
99
{
100
8
	fprintf(stderr, "usage: nseq [-in file] [-out file] [-toseq]\n");
101
4
	options_usage(nseq_options);
102
4
}
103
104
int
105
nseq_main(int argc, char **argv)
106
{
107
	BIO *in = NULL, *out = NULL;
108
	X509 *x509 = NULL;
109
	NETSCAPE_CERT_SEQUENCE *seq = NULL;
110
	int i, ret = 1;
111
112
16
	if (single_execution) {
113
8
		if (pledge("stdio cpath wpath rpath flock", NULL) == -1) {
114
			perror("pledge");
115
			exit(1);
116
		}
117
	}
118
119
8
	memset(&nseq_config, 0, sizeof(nseq_config));
120
121
8
	if (options_parse(argc, argv, nseq_options, NULL, NULL) != 0) {
122
4
		nseq_usage();
123
4
		return (1);
124
	}
125
126
4
	if (nseq_config.infile) {
127
4
		if (!(in = BIO_new_file(nseq_config.infile, "r"))) {
128
			BIO_printf(bio_err,
129
			    "Can't open input file %s\n", nseq_config.infile);
130
			goto end;
131
		}
132
	} else
133
		in = BIO_new_fp(stdin, BIO_NOCLOSE);
134
135
4
	if (nseq_config.outfile) {
136
4
		if (!(out = BIO_new_file(nseq_config.outfile, "w"))) {
137
			BIO_printf(bio_err,
138
			    "Can't open output file %s\n", nseq_config.outfile);
139
			goto end;
140
		}
141
	} else {
142
		out = BIO_new_fp(stdout, BIO_NOCLOSE);
143
	}
144
4
	if (nseq_config.toseq) {
145
4
		seq = NETSCAPE_CERT_SEQUENCE_new();
146
4
		seq->certs = sk_X509_new_null();
147
16
		while ((x509 = PEM_read_bio_X509(in, NULL, NULL, NULL)))
148
4
			sk_X509_push(seq->certs, x509);
149
150
4
		if (!sk_X509_num(seq->certs)) {
151
			BIO_printf(bio_err, "Error reading certs file %s\n", nseq_config.infile);
152
			ERR_print_errors(bio_err);
153
			goto end;
154
		}
155
4
		PEM_write_bio_NETSCAPE_CERT_SEQUENCE(out, seq);
156
		ret = 0;
157
4
		goto end;
158
	}
159
	if (!(seq = PEM_read_bio_NETSCAPE_CERT_SEQUENCE(in, NULL, NULL, NULL))) {
160
		BIO_printf(bio_err, "Error reading sequence file %s\n", nseq_config.infile);
161
		ERR_print_errors(bio_err);
162
		goto end;
163
	}
164
	for (i = 0; i < sk_X509_num(seq->certs); i++) {
165
		x509 = sk_X509_value(seq->certs, i);
166
		dump_cert_text(out, x509);
167
		PEM_write_bio_X509(out, x509);
168
	}
169
	ret = 0;
170
end:
171
4
	BIO_free(in);
172
4
	BIO_free_all(out);
173
4
	NETSCAPE_CERT_SEQUENCE_free(seq);
174
175
4
	return (ret);
176
8
}