1 |
/* wptGPGME.cpp - WinPT GPGME interface |
/* wptGPGME.cpp - WinPT GPGME interface |
2 |
* Copyright (C) 2001-2005 Timo Schulz |
* Copyright (C) 2001-2006 Timo Schulz |
3 |
* |
* |
4 |
* This file is part of WinPT. |
* This file is part of WinPT. |
5 |
* |
* |
41 |
BOOL CALLBACK keycache_dlg_proc (HWND dlg, UINT msg, WPARAM wparam, LPARAM lparam); |
BOOL CALLBACK keycache_dlg_proc (HWND dlg, UINT msg, WPARAM wparam, LPARAM lparam); |
42 |
void progress_cleanup (progress_filter_s * pfx); |
void progress_cleanup (progress_filter_s * pfx); |
43 |
|
|
44 |
|
/* Global GPG key cache contexts. */ |
45 |
static gpg_keycache_t pub = NULL; |
static gpg_keycache_t pub = NULL; |
46 |
static gpg_keycache_t sec = NULL; |
static gpg_keycache_t sec = NULL; |
47 |
static char *gpg_secring = NULL; |
static char *gpg_secring = NULL; |
48 |
|
|
49 |
|
|
50 |
/* Reload the key cache. */ |
/* Return 1 if no cache is available. |
51 |
void |
This can be the case if WinPT were run in command line mode. */ |
52 |
keycache_reload (HWND dlg) |
int |
53 |
{ |
keycache_not_available (void) |
54 |
refresh_cache_s rcs; |
{ |
55 |
|
return pub == NULL; |
|
memset (&rcs, 0, sizeof rcs); |
|
|
rcs.kr_reload = rcs.kr_update = 1; |
|
|
rcs.tr_update = 0; |
|
|
DialogBoxParam (glob_hinst, (LPCSTR)IDD_WINPT_KEYCACHE, dlg, |
|
|
keycache_dlg_proc, (LPARAM)&rcs); |
|
56 |
} |
} |
57 |
|
|
|
|
|
58 |
/* Release both key cache objects. If @cleanup is 1, |
/* Release both key cache objects. If @cleanup is 1, |
59 |
also release other global structs. */ |
also release other global structs. */ |
60 |
void |
void |
61 |
keycache_release (int cleanup) |
keycache_release (int cleanup) |
62 |
{ |
{ |
|
int n = gpg_keycache_get_size (pub); |
|
63 |
char tmpbuf[64]; |
char tmpbuf[64]; |
64 |
|
int n = gpg_keycache_get_size (pub); |
65 |
|
|
66 |
/* XXX: update the value when the cache has changed. */ |
/* XXX: update the value when the cache has changed. */ |
67 |
sprintf (tmpbuf, "%d", n); |
_snprintf (tmpbuf, DIM (tmpbuf)-1, "%d", n); |
68 |
set_reg_key (HKEY_CURRENT_USER, "Software\\WinPT", "nKeys", tmpbuf); |
set_reg_key (HKEY_CURRENT_USER, "Software\\WinPT", "nKeys", tmpbuf); |
69 |
|
|
70 |
if (pub) { |
if (pub) { |
75 |
gpg_keycache_release (sec); |
gpg_keycache_release (sec); |
76 |
sec = NULL; |
sec = NULL; |
77 |
} |
} |
78 |
if (cleanup) { |
if (cleanup) |
79 |
if (gpg_secring) |
safe_free (gpg_secring); |
|
free (gpg_secring); |
|
|
gpg_secring = NULL; |
|
|
} |
|
80 |
} |
} |
81 |
|
|
82 |
|
|
110 |
if (secring != NULL) { |
if (secring != NULL) { |
111 |
free_if_alloc (gpg_secring); |
free_if_alloc (gpg_secring); |
112 |
gpg_secring = get_gnupg_keyring (0, NO_STRICT); |
gpg_secring = get_gnupg_keyring (0, NO_STRICT); |
113 |
|
log_debug ("keycache_init: secring path '%s'\r\n", gpg_secring); |
114 |
} |
} |
115 |
|
|
116 |
p = get_reg_entry (HKEY_CURRENT_USER, "Software\\WinPT", "nKeys"); |
p = get_reg_entry (HKEY_CURRENT_USER, "Software\\WinPT", "nKeys"); |
120 |
} |
} |
121 |
|
|
122 |
memset (&pfx, 0, sizeof (pfx)); |
memset (&pfx, 0, sizeof (pfx)); |
123 |
/* Release old contexts first. */ |
keycache_release (0); /* Release old contexts first. */ |
|
keycache_release (0); |
|
124 |
|
|
125 |
err = gpg_keycache_new (&pub); |
err = gpg_keycache_new (&pub); |
126 |
if (err) |
if (err) |
160 |
|
|
161 |
/* Get the GPG key with keyid @keyid from the cache. Return it |
/* Get the GPG key with keyid @keyid from the cache. Return it |
162 |
in @r_key on success. */ |
in @r_key on success. */ |
163 |
static int |
static gpgme_error_t |
164 |
get_key_from_cache (const char *keyid, gpgme_key_t *r_key, |
get_key_from_cache (const char *keyid, int secret, gpgme_key_t *r_key, |
165 |
struct keycache_s **c, int secret) |
struct keycache_s **c) |
166 |
{ |
{ |
167 |
gpg_keycache_t cache; |
gpg_keycache_t cache; |
168 |
gpgme_error_t err; |
gpgme_error_t err; |
169 |
int mode = secret? KEYCACHE_PRV : KEYCACHE_PUB; |
int mode = secret? KEYCACHE_PRV : KEYCACHE_PUB; |
170 |
|
|
171 |
if (!keyid) |
if (!keyid) |
172 |
return WPTERR_GENERAL; |
return gpg_error (GPG_ERR_INV_VALUE); |
173 |
if (r_key) |
if (r_key) |
174 |
*r_key = NULL; |
*r_key = NULL; |
175 |
cache = keycache_get_ctx (mode); |
cache = keycache_get_ctx (mode); |
|
if (!cache) |
|
|
BUG (0); |
|
176 |
if (!c) |
if (!c) |
177 |
err = gpg_keycache_find_key (cache, keyid, 0, r_key); |
err = gpg_keycache_find_key (cache, keyid, 0, r_key); |
178 |
else |
else |
179 |
err = gpg_keycache_find_key2 (cache, keyid, 0, r_key, c); |
err = gpg_keycache_find_key2 (cache, keyid, 0, r_key, c); |
180 |
return err? WPTERR_GENERAL : 0; |
return err; |
181 |
} |
} |
182 |
|
|
183 |
|
|
184 |
/* Get GPG key with keyid @keyid directly from GPG and return |
/* Release the internal key structure. |
185 |
it in @r_key on success. */ |
If allocated is 0, assume fixed cache item. */ |
186 |
static int |
void |
187 |
get_key_directly (const char *keyid, gpgme_key_t *r_key, int secret) |
winpt_release_pubkey (winpt_key_s *k) |
188 |
{ |
{ |
189 |
gpgme_ctx_t ctx; |
/*log_box ("debug", 0, "alloc %d", k->allocated);*/ |
190 |
gpgme_error_t err; |
if (!k->allocated) |
191 |
|
return; |
192 |
err = gpgme_new (&ctx); |
gpg_keycache_item_release (k->ext); |
193 |
if (err) |
k->ext = NULL; |
194 |
return WPTERR_GENERAL; |
k->allocated = 0; |
|
err = gpgme_get_key (ctx, keyid, r_key, secret); |
|
|
gpgme_release (ctx); |
|
|
return err? WPTERR_GENERAL : 0; |
|
195 |
} |
} |
196 |
|
|
197 |
|
|
198 |
/* Search the public key with @keyid as the keyid in the cache and |
/* Search the public key with @keyid as the keyid in the cache and |
199 |
return the item in @k. */ |
return the item in @k. */ |
200 |
int |
gpgme_error_t |
201 |
winpt_get_pubkey (const char *keyid, winpt_key_s *k) |
winpt_get_pubkey (const char *keyid, winpt_key_s *k) |
202 |
{ |
{ |
203 |
int rc; |
gpgme_error_t err = gpg_error (GPG_ERR_NO_ERROR); |
204 |
|
|
205 |
rc = get_key_from_cache (keyid, &k->ctx, &k->ext, 0); |
if (pub) |
206 |
if (rc) |
err = get_key_from_cache (keyid, 0, &k->ctx, &k->ext); |
207 |
return rc; |
else |
208 |
|
err = gpg_keycache_fetch_key (keyid, 0, &k->ctx, &k->ext); |
209 |
|
if (err) |
210 |
|
return err; |
211 |
k->is_v3 = k->ctx->subkeys->pubkey_algo == GPGME_PK_RSA && |
k->is_v3 = k->ctx->subkeys->pubkey_algo == GPGME_PK_RSA && |
212 |
strlen (k->ctx->subkeys->fpr) == 32; |
strlen (k->ctx->subkeys->fpr) == 32; |
213 |
k->is_protected = k->ext->gloflags.is_protected; |
k->is_protected = k->ext->gloflags.is_protected; |
214 |
k->keyid = k->ctx->subkeys->keyid; |
k->keyid = k->ctx->subkeys->keyid+8; |
215 |
k->uid = k->ctx->uids->uid; |
k->uid = k->ext->uids->uid; |
216 |
return rc; |
k->allocated = pub? 0 : 1; |
217 |
|
return 0; |
218 |
} |
} |
219 |
|
|
220 |
|
|
221 |
int |
gpgme_error_t |
222 |
winpt_get_seckey (const char *keyid, winpt_key_s *k) |
winpt_get_seckey (const char *keyid, winpt_key_s *k) |
223 |
{ |
{ |
224 |
int rc; |
gpgme_error_t err; |
225 |
rc = get_key_from_cache (keyid, &k->ctx, &k->ext, 1); |
|
226 |
if (rc) |
if (sec) |
227 |
return rc; |
err = get_key_from_cache (keyid, 1, &k->ctx, &k->ext); |
228 |
|
else |
229 |
|
err = gpg_keycache_fetch_key (keyid, 1, &k->ctx, &k->ext); |
230 |
|
if (err) |
231 |
|
return err; |
232 |
k->is_v3 = k->ctx->subkeys->pubkey_algo == GPGME_PK_RSA && |
k->is_v3 = k->ctx->subkeys->pubkey_algo == GPGME_PK_RSA && |
233 |
strlen (k->ctx->subkeys->fpr) == 32; |
strlen (k->ctx->subkeys->fpr) == 32; |
234 |
k->is_protected = k->ext->gloflags.is_protected; |
k->is_protected = k->ext->gloflags.is_protected; |
235 |
k->keyid = k->ctx->subkeys->keyid; |
k->keyid = k->ctx->subkeys->keyid+8; |
236 |
k->uid = k->ctx->uids->uid; |
k->uid = k->ext->uids->uid; |
237 |
return rc; |
k->allocated = sec? 0 : 1; |
238 |
|
return 0; |
239 |
} |
} |
240 |
|
|
241 |
|
|
242 |
int |
gpgme_error_t |
243 |
get_pubkey (const char *keyid, gpgme_key_t *ret_key) |
get_pubkey (const char *keyid, gpgme_key_t *ret_key) |
244 |
{ |
{ |
245 |
int rc; |
return get_key_from_cache (keyid, 0, ret_key, NULL); |
|
|
|
|
if (pub && sec) |
|
|
rc = get_key_from_cache (keyid, ret_key, NULL, 0); |
|
|
else |
|
|
rc = get_key_directly (keyid, ret_key, 0); |
|
|
return rc; |
|
246 |
} |
} |
247 |
|
|
248 |
|
|
249 |
int |
gpgme_error_t |
250 |
get_seckey (const char *keyid, gpgme_key_t *ret_skey) |
get_seckey (const char *keyid, gpgme_key_t *ret_skey) |
251 |
{ |
{ |
252 |
int rc; |
return get_key_from_cache (keyid, 1, ret_skey, NULL); |
|
|
|
|
if (pub && sec) |
|
|
rc = get_key_from_cache (keyid, ret_skey, NULL, 1); |
|
|
else |
|
|
rc = get_key_directly (keyid, ret_skey, 1); |
|
|
return rc; |
|
|
} |
|
|
|
|
|
|
|
|
/* Search for insecure ElGamal keys and return the |
|
|
number of founded keys. */ |
|
|
int |
|
|
count_insecure_elgkeys (void) |
|
|
{ |
|
|
gpg_keycache_t pc; |
|
|
gpgme_key_t key; |
|
|
int n=0; |
|
|
|
|
|
pc = keycache_get_ctx (1); |
|
|
if (!pc) |
|
|
BUG (0); |
|
|
while (!gpg_keycache_next_key (pc, 0, &key)) { |
|
|
if (key->subkeys->pubkey_algo == GPGME_PK_ELG) |
|
|
n++; |
|
|
} |
|
|
gpg_keycache_rewind (pc); |
|
|
return n; |
|
253 |
} |
} |
254 |
|
|
255 |
|
|
|
|
|
256 |
/* Map the signature summary in @sum to signature status table index. |
/* Map the signature summary in @sum to signature status table index. |
257 |
Return value: index to table. */ |
Return value: index to table. */ |
258 |
static int |
static int |
259 |
sigsum_to_index (gpgme_sigsum_t sum) |
sigsum_to_index (gpgme_sigsum_t sum) |
260 |
{ |
{ |
261 |
if ((sum & GPGME_SIGSUM_VALID) && (sum & GPGME_SIGSUM_KEY_REVOKED)) |
if (sum & GPGME_SIGSUM_RED) |
262 |
|
return 2; |
263 |
|
else if (sum & GPGME_SIGSUM_SIG_EXPIRED) |
264 |
|
return 8; |
265 |
|
else if (sum & GPGME_SIGSUM_KEY_REVOKED) |
266 |
return 7; |
return 7; |
267 |
if ((sum & GPGME_SIGSUM_VALID) && (sum & GPGME_SIGSUM_SIG_EXPIRED)) |
else if (sum & GPGME_SIGSUM_KEY_EXPIRED) |
268 |
return 6; |
return 6; |
269 |
if (sum & GPGME_SIGSUM_GREEN) |
else if (sum & GPGME_SIGSUM_GREEN) |
270 |
return 1; |
return 1; |
|
else if (sum & GPGME_SIGSUM_RED) |
|
|
return 2; |
|
271 |
else if (sum & GPGME_SIGSUM_KEY_MISSING) |
else if (sum & GPGME_SIGSUM_KEY_MISSING) |
272 |
return 3; |
return 3; |
273 |
return 0; |
return 0; |
274 |
} |
} |
275 |
|
|
276 |
|
|
277 |
/* Return a humand readable description for the signature status @sum. */ |
/* Return a humand readable description for the signature status @sum. |
278 |
|
Warning: this function does not consider the validity of the key. */ |
279 |
const char* |
const char* |
280 |
get_gpg_sigstat (gpgme_sigsum_t sum) |
get_gpg_sigstat (gpgme_sigsum_t sum) |
281 |
{ |
{ |
282 |
const char *gpg_sigstat[] = { |
const char *gpg_sigstat[] = { |
283 |
_("Error during verification process."), |
_("Error during verification process"), |
284 |
_("The signature is good."), |
_("The signature is good"), |
285 |
_("The signature is BAD!"), |
_("The signature is BAD!"), |
286 |
_("The signature could not be checked due to a missing key."), |
_("The signature could not be checked due to a missing key"), |
287 |
_("No valid OpenPGP signature."), |
_("No valid OpenPGP signature"), |
288 |
_("Signature Error"), |
_("Signature Error"), |
289 |
_("Good Signature (Expired Key)"), |
_("Good signature (Expired Key)"), |
290 |
_("Good Signature (Revoked Key)"), |
_("Good signature (Revoked Key)"), |
291 |
|
_("Good signature (Expired)"), |
292 |
NULL |
NULL |
293 |
}; |
}; |
294 |
const unsigned int mask = 8; |
const unsigned int mask = 9; |
295 |
|
|
296 |
return gpg_sigstat[sigsum_to_index (sum) % mask]; |
return gpg_sigstat[sigsum_to_index (sum) % mask]; |
297 |
} |
} |
298 |
|
|
299 |
|
|
300 |
/* Check if the secret keyring contains at least one |
/* Return true if at least one secret key is available. */ |
301 |
key with ultimate trust. |
bool |
302 |
Return value: 0 on success. */ |
secret_key_available (void) |
303 |
int |
{ |
304 |
check_ultimate_trusted_key (void) |
if (!sec || gpg_keycache_get_size (sec) == 0) |
305 |
{ |
return false; |
306 |
struct keycache_s *n; |
return true; |
|
|
|
|
for (n = sec->item; n; n = n->next) { |
|
|
if (n->pubpart && |
|
|
n->pubpart->key->owner_trust == GPGME_VALIDITY_ULTIMATE) |
|
|
return 0; |
|
|
} |
|
|
return -1; |
|
307 |
} |
} |