Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 1 | // Copyright (c) 2012 The Chromium OS Authors. All rights reserved. |
| 2 | // Use of this source code is governed by a BSD-style license that can be |
| 3 | // found in the LICENSE file. |
| 4 | |
| 5 | #include "shill/nss.h" |
| 6 | |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 7 | #include <base/string_number_conversions.h> |
| 8 | #include <base/string_util.h> |
| 9 | #include <base/stringprintf.h> |
| 10 | |
Christopher Wiley | b691efd | 2012-08-09 13:51:51 -0700 | [diff] [blame] | 11 | #include "shill/logging.h" |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 12 | #include "shill/minijail.h" |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 13 | |
Albert Chaulk | 0e1cdea | 2013-02-27 15:32:55 -0800 | [diff] [blame] | 14 | using base::FilePath; |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 15 | using base::HexEncode; |
| 16 | using base::StringPrintf; |
| 17 | using std::string; |
| 18 | using std::vector; |
| 19 | |
| 20 | namespace shill { |
| 21 | |
| 22 | namespace { |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 23 | |
Ben Chan | bbdef5f | 2012-04-23 13:58:15 -0700 | [diff] [blame] | 24 | base::LazyInstance<NSS> g_nss = LAZY_INSTANCE_INITIALIZER; |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 25 | const char kCertfileBasename[] = "/tmp/nss-cert."; |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 26 | const char kNSSGetCert[] = SHIMDIR "/nss-get-cert"; |
| 27 | const char kNSSGetCertUser[] = "chronos"; |
| 28 | |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 29 | } // namespace |
| 30 | |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 31 | NSS::NSS() |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 32 | : minijail_(Minijail::GetInstance()) { |
Ben Chan | fad4a0b | 2012-04-18 15:49:59 -0700 | [diff] [blame] | 33 | SLOG(Crypto, 2) << __func__; |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 34 | } |
| 35 | |
| 36 | NSS::~NSS() { |
Ben Chan | fad4a0b | 2012-04-18 15:49:59 -0700 | [diff] [blame] | 37 | SLOG(Crypto, 2) << __func__; |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 38 | } |
| 39 | |
| 40 | // static |
| 41 | NSS *NSS::GetInstance() { |
| 42 | return g_nss.Pointer(); |
| 43 | } |
| 44 | |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 45 | FilePath NSS::GetPEMCertfile(const string &nickname, const vector<char> &id) { |
| 46 | return GetCertfile(nickname, id, "pem"); |
| 47 | } |
| 48 | |
| 49 | FilePath NSS::GetDERCertfile(const string &nickname, const vector<char> &id) { |
| 50 | return GetCertfile(nickname, id, "der"); |
| 51 | } |
| 52 | |
| 53 | FilePath NSS::GetCertfile( |
| 54 | const string &nickname, const vector<char> &id, const string &type) { |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 55 | string filename = |
| 56 | kCertfileBasename + StringToLowerASCII(HexEncode(&id[0], id.size())); |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 57 | vector<char *> args; |
| 58 | args.push_back(const_cast<char *>(kNSSGetCert)); |
| 59 | args.push_back(const_cast<char *>(nickname.c_str())); |
| 60 | args.push_back(const_cast<char *>(type.c_str())); |
| 61 | args.push_back(const_cast<char *>(filename.c_str())); |
| 62 | args.push_back(NULL); |
| 63 | |
| 64 | struct minijail *jail = minijail_->New(); |
| 65 | minijail_->DropRoot(jail, kNSSGetCertUser); |
| 66 | |
| 67 | int status; |
| 68 | if (!minijail_->RunSyncAndDestroy(jail, args, &status)) { |
| 69 | LOG(ERROR) << "Unable to spawn " << kNSSGetCert << " in a jail."; |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 70 | return FilePath(); |
| 71 | } |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 72 | |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 73 | if (!WIFEXITED(status) || WEXITSTATUS(status)) { |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 74 | LOG(ERROR) << kNSSGetCert << " failed with status " << status; |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 75 | return FilePath(); |
| 76 | } |
Jorge Lucangeli Obes | ccd5c85 | 2012-12-19 18:08:40 -0800 | [diff] [blame] | 77 | |
Darin Petkov | 3c5e4dc | 2012-04-02 14:44:27 +0200 | [diff] [blame] | 78 | return FilePath(filename); |
| 79 | } |
| 80 | |
| 81 | } // namespace shill |