[0aaa651] | 1 | |
---|
[461541a] | 2 | /* display.c */ |
---|
| 3 | |
---|
| 4 | #include <time.h> |
---|
| 5 | #include <string.h> |
---|
| 6 | #include <err.h> |
---|
| 7 | |
---|
[4721618] | 8 | #include "libabac_common.h" |
---|
[0aaa651] | 9 | #include "creddy_common.h" |
---|
| 10 | |
---|
[405bba3] | 11 | // helper |
---|
[461541a] | 12 | void _print_validity(struct tm not_before, struct tm not_after); |
---|
| 13 | void _print_info(abac_attribute_t *attr, int show_issuer, int show_subject, int show_validity, int show_roles, char*); |
---|
[405bba3] | 14 | |
---|
[0aaa651] | 15 | void display_main(options_t *opts) { |
---|
| 16 | if (opts->cert == NULL) |
---|
| 17 | usage(opts); |
---|
| 18 | |
---|
| 19 | char *show = opts->show; |
---|
| 20 | if (show == NULL) |
---|
| 21 | usage(opts); |
---|
| 22 | |
---|
| 23 | int show_issuer = 0; |
---|
[b19d1f0] | 24 | int show_subject = 0; |
---|
[405bba3] | 25 | int show_validity = 0; |
---|
[08e7235] | 26 | int show_roles = 0; |
---|
[0aaa651] | 27 | char *opt; |
---|
| 28 | |
---|
| 29 | while ((opt = strsep(&show, ",")) != NULL) { |
---|
| 30 | if (strcmp(opt, "issuer") == 0) |
---|
| 31 | show_issuer = 1; |
---|
[b19d1f0] | 32 | else if (strcmp(opt, "subject") == 0) |
---|
| 33 | show_subject = 1; |
---|
[405bba3] | 34 | else if (strcmp(opt, "validity") == 0) |
---|
| 35 | show_validity = 1; |
---|
[08e7235] | 36 | else if (strcmp(opt, "roles") == 0) |
---|
| 37 | show_roles = 1; |
---|
[0aaa651] | 38 | else if (strcmp(opt, "all") == 0) { |
---|
| 39 | show_issuer = 1; |
---|
[b19d1f0] | 40 | show_subject = 1; |
---|
[405bba3] | 41 | show_validity = 1; |
---|
[08e7235] | 42 | show_roles = 1; |
---|
[0aaa651] | 43 | } |
---|
| 44 | else { |
---|
| 45 | printf("Error: Unknown option to --show: %s\n", opt); |
---|
| 46 | usage(opts); |
---|
| 47 | } |
---|
| 48 | } |
---|
| 49 | |
---|
| 50 | // first try ID cert |
---|
[461541a] | 51 | abac_id_t *id = abac_id_from_file(opts->cert); |
---|
[0aaa651] | 52 | if (id != NULL) { |
---|
| 53 | if (show_issuer) { |
---|
[461541a] | 54 | char *issuer = abac_id_issuer(id); |
---|
[405bba3] | 55 | printf("Issuer: %s\n", issuer); |
---|
| 56 | free(issuer); |
---|
| 57 | } |
---|
| 58 | |
---|
[b19d1f0] | 59 | if (show_subject) { |
---|
[461541a] | 60 | char *subject = abac_id_subject(id); |
---|
[b19d1f0] | 61 | printf("Subject: %s\n", subject); |
---|
| 62 | free(subject); |
---|
| 63 | } |
---|
| 64 | |
---|
[405bba3] | 65 | if (show_validity) { |
---|
[461541a] | 66 | struct tm not_before, not_after; |
---|
| 67 | abac_id_validity(id, ¬_before, ¬_after); |
---|
[405bba3] | 68 | _print_validity(not_before, not_after); |
---|
[0aaa651] | 69 | } |
---|
| 70 | |
---|
[461541a] | 71 | abac_id_free(id); |
---|
[0aaa651] | 72 | return; |
---|
| 73 | } |
---|
| 74 | |
---|
| 75 | // then try attribute cert |
---|
[461541a] | 76 | abac_attribute_t *attr; |
---|
[bec30b5] | 77 | abac_list_t *attr_list = abac_attribute_certs_from_file(NULL,opts->cert); |
---|
[461541a] | 78 | int sz=abac_list_size(attr_list); |
---|
| 79 | abac_list_foreach(attr_list, attr, |
---|
| 80 | _print_info(attr,show_issuer,show_subject,show_validity,show_roles, opts->cert); |
---|
| 81 | abac_attribute_free(attr); |
---|
[0aaa651] | 82 | ); |
---|
[461541a] | 83 | abac_list_free(attr_list); |
---|
[405bba3] | 84 | |
---|
[461541a] | 85 | // give up if neither works |
---|
| 86 | if(sz==0) |
---|
| 87 | errx(1, "Couldn't load %s as an ID or attribute, ", opts->cert); |
---|
| 88 | } |
---|
[b19d1f0] | 89 | |
---|
[461541a] | 90 | void _print_info(abac_attribute_t *attr, int show_issuer, int show_subject, int show_validity, int show_roles, char *fname) |
---|
| 91 | { |
---|
| 92 | if (attr != NULL) { |
---|
| 93 | abac_id_t *issuer_id=abac_attribute_issuer_id(attr); |
---|
| 94 | if (show_issuer && issuer_id) { |
---|
| 95 | char *issuer = abac_id_issuer(issuer_id); |
---|
| 96 | printf("Issuer: %s\n", issuer); |
---|
| 97 | free(issuer); |
---|
| 98 | } |
---|
| 99 | if (show_subject && issuer_id) { |
---|
| 100 | char *subject = abac_id_subject(issuer_id); |
---|
| 101 | printf("Subject: %s\n", subject); |
---|
| 102 | free(subject); |
---|
| 103 | } |
---|
[405bba3] | 104 | if (show_validity) { |
---|
[461541a] | 105 | struct tm not_before, not_after; |
---|
| 106 | abac_attribute_validity(attr, ¬_before, ¬_after); |
---|
[405bba3] | 107 | _print_validity(not_before, not_after); |
---|
| 108 | } |
---|
[08e7235] | 109 | if (show_roles) { |
---|
[461541a] | 110 | char *role_string = abac_attribute_role_string(attr); |
---|
| 111 | if (role_string == NULL) errx(1, "Couldn't get attributes from %s", fname ); |
---|
| 112 | printf("Roles: %s\n", role_string); |
---|
| 113 | free(role_string); |
---|
[08e7235] | 114 | } |
---|
[0aaa651] | 115 | } |
---|
| 116 | } |
---|
[405bba3] | 117 | |
---|
| 118 | // display the validity period of a cert |
---|
[461541a] | 119 | void _print_validity(struct tm not_before, struct tm not_after) { |
---|
[405bba3] | 120 | char buf[256]; |
---|
| 121 | printf("Validity:\n"); |
---|
| 122 | |
---|
[461541a] | 123 | strftime(buf, sizeof(buf), "%F %T %Z", ¬_before); |
---|
| 124 | printf(" Not before: %s [%lld]\n", buf, (long long) mktime(¬_before)); |
---|
[405bba3] | 125 | |
---|
[461541a] | 126 | strftime(buf, sizeof(buf), "%F %T %Z", ¬_after); |
---|
| 127 | printf(" Not after: %s [%lld]\n", buf, (long long) mktime(¬_after)); |
---|
[405bba3] | 128 | } |
---|