Files
libreoffice/xmlsecurity/source/xmlsec/nss/seinitializer_nssimpl.cxx

448 lines
15 KiB
C++
Raw Normal View History

2004-07-12 12:15:31 +00:00
/*************************************************************************
*
* OpenOffice.org - a multi-platform office productivity suite
2004-07-12 12:15:31 +00:00
*
* $RCSfile: seinitializer_nssimpl.cxx,v $
2004-07-12 12:15:31 +00:00
*
* $Revision: 1.15 $
2004-07-12 12:15:31 +00:00
*
* last change: $Author: rt $ $Date: 2005-09-09 17:34:13 $
2004-07-12 12:15:31 +00:00
*
* The Contents of this file are made available subject to
* the terms of GNU Lesser General Public License Version 2.1.
2004-07-12 12:15:31 +00:00
*
*
* GNU Lesser General Public License Version 2.1
* =============================================
* Copyright 2005 by Sun Microsystems, Inc.
* 901 San Antonio Road, Palo Alto, CA 94303, USA
2004-07-12 12:15:31 +00:00
*
* This library is free software; you can redistribute it and/or
* modify it under the terms of the GNU Lesser General Public
* License version 2.1, as published by the Free Software Foundation.
2004-07-12 12:15:31 +00:00
*
* This library is distributed in the hope that it will be useful,
* but WITHOUT ANY WARRANTY; without even the implied warranty of
* MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
* Lesser General Public License for more details.
2004-07-12 12:15:31 +00:00
*
* You should have received a copy of the GNU Lesser General Public
* License along with this library; if not, write to the Free Software
* Foundation, Inc., 59 Temple Place, Suite 330, Boston,
* MA 02111-1307 USA
2004-07-12 12:15:31 +00:00
*
************************************************************************/
/*
* Turn off DEBUG Assertions
*/
#ifdef _DEBUG
#define _DEBUG_WAS_DEFINED _DEBUG
#undef _DEBUG
#else
#undef _DEBUG_WAS_DEFINED
#endif
/*
* and turn off the additional virtual methods which are part of some interfaces when compiled
* with debug
*/
#ifdef DEBUG
#define DEBUG_WAS_DEFINED DEBUG
#undef DEBUG
#else
#undef DEBUG_WAS_DEFINED
#endif
2004-07-12 12:15:31 +00:00
#include <sal/types.h>
#include <tools/debug.hxx>
#include <rtl/logfile.hxx>
2004-07-12 12:15:31 +00:00
#include "seinitializer_nssimpl.hxx"
#include "securityenvironment_nssimpl.hxx"
#ifndef _COM_SUN_STAR_MOZILLA_XMOZILLABOOTSTRAP_HPP_
#include <com/sun/star/mozilla/XMozillaBootstrap.hpp>
#endif
2004-07-12 12:15:31 +00:00
#include "nspr.h"
#include "prtypes.h"
#include "pk11func.h"
#ifdef SYSTEM_MOZILLA
#include "nssrenam.h"
#endif
2004-07-12 12:15:31 +00:00
#include "cert.h"
#include "cryptohi.h"
#include "certdb.h"
#include "nss.h"
namespace cssu = com::sun::star::uno;
namespace cssl = com::sun::star::lang;
namespace cssxc = com::sun::star::xml::crypto;
using namespace com::sun::star;
#define SERVICE_NAME "com.sun.star.xml.crypto.SEInitializer"
#define IMPLEMENTATION_NAME "com.sun.star.xml.security.bridge.xmlsec.SEInitializer_NssImpl"
#define SECURITY_ENVIRONMENT "com.sun.star.xml.crypto.SecurityEnvironment"
#define SECURITY_CONTEXT "com.sun.star.xml.crypto.XMLSecurityContext"
bool nsscrypto_initialize( const char* token ) {
static char initialized = 0 ;
//PR_Init( PR_SYSTEM_THREAD, PR_PRIORITY_NORMAL, 1 ) ;
if( !initialized ) {
PR_Init( PR_USER_THREAD, PR_PRIORITY_NORMAL, 1 ) ;
if( NSS_Init( token ) != SECSuccess )
return false ;
initialized = 1 ;
}
return true ;
}
void nsscrypto_finalize() {
PK11_LogoutAll();
NSS_Shutdown();
}
bool getMozillaCurrentProfile(
const com::sun::star::uno::Reference< com::sun::star::lang::XMultiServiceFactory > &rxMSF,
rtl::OUString& profilePath)
{
/*
* first, try to get the profile from "MOZILLA_CERTIFICATE_FOLDER"
*/
char * env = getenv("MOZILLA_CERTIFICATE_FOLDER");
if (env)
{
profilePath = rtl::OUString::createFromAscii( env );
RTL_LOGFILE_PRODUCT_TRACE1( "XMLSEC: Using env MOZILLA_CERTIFICATE_FOLDER: %s", rtl::OUStringToOString( profilePath, RTL_TEXTENCODING_ASCII_US ).getStr() );
return true;
}
else
{
RTL_LOGFILE_TRACE( "getMozillaCurrentProfile: Using MozillaBootstrap..." );
mozilla::MozillaProductType productTypes[4] = {
mozilla::MozillaProductType_Thunderbird,
mozilla::MozillaProductType_Mozilla,
mozilla::MozillaProductType_Firefox,
mozilla::MozillaProductType_Default };
int nProduct = 4;
uno::Reference<uno::XInterface> xInstance = rxMSF->createInstance(
::rtl::OUString( RTL_CONSTASCII_USTRINGPARAM("com.sun.star.mozilla.MozillaBootstrap")) );
OSL_ENSURE( xInstance.is(), "failed to create instance" );
uno::Reference<mozilla::XMozillaBootstrap> xMozillaBootstrap
= uno::Reference<mozilla::XMozillaBootstrap>(xInstance,uno::UNO_QUERY);
OSL_ENSURE( xMozillaBootstrap.is(), "failed to create instance" );
if (xMozillaBootstrap.is())
{
for (int i=0; i<nProduct; i++)
{
::rtl::OUString profile = xMozillaBootstrap->getDefaultProfile(productTypes[i]);
RTL_LOGFILE_TRACE2( "getMozillaCurrentProfile: getDefaultProfile [%i] returns %s", i, rtl::OUStringToOString( profile, RTL_TEXTENCODING_ASCII_US ).getStr() );
if (profile != NULL && profile.getLength()>0)
{
profilePath = xMozillaBootstrap->getProfilePath(productTypes[i],profile);
RTL_LOGFILE_PRODUCT_TRACE1( "XMLSEC: Using Mozilla Profile: %s", rtl::OUStringToOString( profilePath, RTL_TEXTENCODING_ASCII_US ).getStr() );
return true;
}
}
}
RTL_LOGFILE_PRODUCT_TRACE( "XMLSEC: No Mozilla Profile found!" );
return false;
}
}
2004-07-12 12:15:31 +00:00
SEInitializer_NssImpl::SEInitializer_NssImpl(
const com::sun::star::uno::Reference< com::sun::star::lang::XMultiServiceFactory > &rxMSF)
:mxMSF( rxMSF )
{
}
SEInitializer_NssImpl::~SEInitializer_NssImpl()
{
}
/* XSEInitializer */
cssu::Reference< cssxc::XXMLSecurityContext > SAL_CALL
SEInitializer_NssImpl::createSecurityContext(
const rtl::OUString& sCertDB )
throw (cssu::RuntimeException)
{
CERTCertDBHandle *pCertHandle = NULL ;
PK11SlotInfo *pSlot = NULL , *pInternalSlot = NULL ;
PK11SymKey *pSymKey = NULL ;
PRBool found;
2004-07-12 12:15:31 +00:00
rtl::OString sCertDir;
2004-07-23 07:34:25 +00:00
if( sCertDB.getLength() )
2004-07-12 12:15:31 +00:00
{
sCertDir = rtl::OString(sCertDB, sCertDB.getLength(), RTL_TEXTENCODING_ASCII_US);
}
else
{
2004-07-23 07:34:25 +00:00
static rtl::OString* pDefaultCertDir = NULL;
if ( !pDefaultCertDir )
{
2004-07-23 07:34:25 +00:00
pDefaultCertDir = new rtl::OString;
rtl::OUString ouCertDir;
if ( getMozillaCurrentProfile(mxMSF, ouCertDir) )
2004-07-23 07:34:25 +00:00
*pDefaultCertDir = rtl::OString(ouCertDir, ouCertDir.getLength(), RTL_TEXTENCODING_ASCII_US);
}
2004-07-23 07:34:25 +00:00
sCertDir = *pDefaultCertDir;
2004-07-23 07:34:25 +00:00
}
2004-07-23 07:34:25 +00:00
if( !sCertDir.getLength() )
{
RTL_LOGFILE_TRACE( "XMLSEC: Error - No certificate directory!" );
// return NULL;
}
2004-07-12 12:15:31 +00:00
/* Initialize NSPR and NSS */
/* Replaced with new methods by AF. ----
//PR_Init( PR_SYSTEM_THREAD, PR_PRIORITY_NORMAL, 1 ) ;
PR_Init( PR_USER_THREAD, PR_PRIORITY_NORMAL, 1 ) ;
2004-07-12 12:15:31 +00:00
if (NSS_Init(sCertDir.getStr()) != SECSuccess )
{
PK11_LogoutAll();
return NULL;
}
----*/
if( !nsscrypto_initialize( sCertDir.getStr() ) )
{
RTL_LOGFILE_TRACE( "XMLSEC: Error - nsscrypto_initialize() failed." );
if ( NSS_NoDB_Init(NULL) != SECSuccess )
{
RTL_LOGFILE_TRACE( "XMLSEC: NSS_NoDB_Init also failed, NSS Security not available!" );
return NULL;
}
else
{
RTL_LOGFILE_TRACE( "XMLSEC: NSS_NoDB_Init works, enough for verifying signatures..." );
}
}
else
atexit( nsscrypto_finalize ) ;
2004-07-12 12:15:31 +00:00
pCertHandle = CERT_GetDefaultCertDB() ;
/*- i39448 - we will get all slots defined in the profile
* ---------- and alloc them in each SecurityEnviroment .
* ---------- By CP/20050105
--------------------------*/
pInternalSlot = PK11_GetInternalKeySlot() ;
if (pInternalSlot == NULL)
2004-07-12 12:15:31 +00:00
{
// PK11_LogoutAll();
// NSS_Shutdown();
RTL_LOGFILE_TRACE( "XMLSEC: Error - pInternalSlot is NULL!" );
2004-07-12 12:15:31 +00:00
return NULL;
}
try
{
PK11SlotList* soltList ;
PK11SlotListElement* soltEle ;
2004-07-12 12:15:31 +00:00
/* Build XML Security Context */
const rtl::OUString sSecyrutyContext ( RTL_CONSTASCII_USTRINGPARAM( SECURITY_CONTEXT ) );
cssu::Reference< cssxc::XXMLSecurityContext > xSecCtx( mxMSF->createInstance ( sSecyrutyContext ), cssu::UNO_QUERY );
if( !xSecCtx.is() )
2004-07-12 12:15:31 +00:00
{
// PK11_LogoutAll();
// NSS_Shutdown();
2004-07-12 12:15:31 +00:00
return NULL;
}
soltList = PK11_GetAllTokens( CKM_INVALID_MECHANISM, PR_FALSE, PR_FALSE, NULL ) ;
if( soltList != NULL ) {
for( soltEle = soltList->head ; soltEle != NULL; soltEle = soltEle->next )
{
RTL_LOGFILE_TRACE( "XMLSEC: Trying token..." );
found = PR_FALSE;
2004-07-12 12:15:31 +00:00
pSlot = soltEle->slot ;
2004-07-12 12:15:31 +00:00
if(pSlot != NULL){
RTL_LOGFILE_TRACE2( "XMLSEC: Found a slot: SlotName=%s, TokenName=%s", PK11_GetSlotName(pSlot), PK11_GetTokenName(pSlot) );
pSymKey = PK11_KeyGen( pSlot , CKM_DES3_CBC, NULL, 128, NULL ) ;
if( pSymKey == NULL )
{
PK11_FreeSlot( pSlot ) ;
// PK11_LogoutAll();
// NSS_Shutdown();
RTL_LOGFILE_TRACE( "XMLSEC: Error - pSymKey is NULL" );
return NULL;
}
/* Build Security Environment */
const rtl::OUString sSecyrutyEnvironment ( RTL_CONSTASCII_USTRINGPARAM( SECURITY_ENVIRONMENT ) );
cssu::Reference< cssxc::XSecurityEnvironment > xSecEnv( mxMSF->createInstance ( sSecyrutyEnvironment ), cssu::UNO_QUERY );
if( !xSecEnv.is() )
{
PK11_FreeSymKey( pSymKey ) ;
PK11_FreeSlot( pSlot ) ;
// PK11_LogoutAll();
// NSS_Shutdown();
return NULL;
}
/* Setup key slot and certDb */
cssu::Reference< cssl::XUnoTunnel > xEnvTunnel( xSecEnv , cssu::UNO_QUERY ) ;
if( !xEnvTunnel.is() )
{
PK11_FreeSymKey( pSymKey ) ;
PK11_FreeSlot( pSlot ) ;
// PK11_LogoutAll();
// NSS_Shutdown();
return NULL;
}
SecurityEnvironment_NssImpl* pSecEnv = ( SecurityEnvironment_NssImpl* )xEnvTunnel->getSomething( SecurityEnvironment_NssImpl::getUnoTunnelId() ) ;
if( pSecEnv == NULL )
{
PK11_FreeSymKey( pSymKey ) ;
PK11_FreeSlot( pSlot ) ;
// PK11_LogoutAll();
// NSS_Shutdown();
return NULL;
}
// search the internal slot.
//PR_fprintf(PR_STDOUT, "Token:%s\n",PK11_GetSlotName(pSlot));
//found = PK11_IsInternal(pSlot) ; //This method will return two true result.
if((!strcmp(PK11_GetSlotName(pInternalSlot),PK11_GetSlotName(pSlot))&&(!strcmp(PK11_GetTokenName(pInternalSlot),PK11_GetTokenName(pSlot)))))
{
found = PR_TRUE;
}
pSecEnv->setCryptoSlot( pSlot ) ;
PK11_FreeSlot( pSlot ) ;
pSlot = NULL;
pSecEnv->setCertDb( pCertHandle ) ;
pSecEnv->adoptSymKey( pSymKey ) ;
PK11_FreeSymKey( pSymKey ) ;
pSymKey = NULL;
sal_Int32 n = xSecCtx->addSecurityEnvironment( xSecEnv ) ;
if(found != PR_FALSE)
{
RTL_LOGFILE_TRACE( "XMLSEC: Using this slot as the Default Security Environment." );
xSecCtx->setDefaultSecurityEnvironmentIndex( n ) ;
}
}// end of if(pSlot != NULL)
}// end of for
}// end of if( soltList != NULL )
if(pInternalSlot != NULL)
2004-07-12 12:15:31 +00:00
{
PK11_FreeSlot(pInternalSlot) ;
pInternalSlot = NULL ;
2004-07-12 12:15:31 +00:00
}
return xSecCtx;
}
catch( cssu::Exception& )
{
if (pSymKey != NULL)
{
PK11_FreeSymKey( pSymKey ) ;
}
if (pSlot != NULL)
{
PK11_FreeSlot( pSlot ) ;
}
if(pInternalSlot != NULL)
{
PK11_FreeSlot(pInternalSlot) ;
pInternalSlot = NULL ;
}
//PK11_LogoutAll();
//NSS_Shutdown();
2004-07-12 12:15:31 +00:00
return NULL;
}
}
void SAL_CALL SEInitializer_NssImpl::freeSecurityContext( const cssu::Reference< cssxc::XXMLSecurityContext >& securityContext )
throw (cssu::RuntimeException)
{
/*
* because the security context will free all its content when it
* is destructed, so here no free process for the security context
* is needed.
*/
//PK11_LogoutAll();
//NSS_Shutdown();
2004-07-12 12:15:31 +00:00
}
rtl::OUString SEInitializer_NssImpl_getImplementationName ()
throw (cssu::RuntimeException)
{
return rtl::OUString ( RTL_CONSTASCII_USTRINGPARAM ( IMPLEMENTATION_NAME ) );
}
sal_Bool SAL_CALL SEInitializer_NssImpl_supportsService( const rtl::OUString& ServiceName )
throw (cssu::RuntimeException)
{
return ServiceName.equalsAsciiL( RTL_CONSTASCII_STRINGPARAM ( SERVICE_NAME ));
}
cssu::Sequence< rtl::OUString > SAL_CALL SEInitializer_NssImpl_getSupportedServiceNames( )
throw (cssu::RuntimeException)
{
cssu::Sequence < rtl::OUString > aRet(1);
rtl::OUString* pArray = aRet.getArray();
pArray[0] = rtl::OUString ( RTL_CONSTASCII_USTRINGPARAM ( SERVICE_NAME ) );
return aRet;
}
#undef SERVICE_NAME
cssu::Reference< cssu::XInterface > SAL_CALL SEInitializer_NssImpl_createInstance( const cssu::Reference< cssl::XMultiServiceFactory > & rSMgr)
throw( cssu::Exception )
{
return (cppu::OWeakObject*) new SEInitializer_NssImpl(rSMgr);
}
/* XServiceInfo */
rtl::OUString SAL_CALL SEInitializer_NssImpl::getImplementationName( )
throw (cssu::RuntimeException)
{
return SEInitializer_NssImpl_getImplementationName();
}
sal_Bool SAL_CALL SEInitializer_NssImpl::supportsService( const rtl::OUString& rServiceName )
throw (cssu::RuntimeException)
{
return SEInitializer_NssImpl_supportsService( rServiceName );
}
cssu::Sequence< rtl::OUString > SAL_CALL SEInitializer_NssImpl::getSupportedServiceNames( )
throw (cssu::RuntimeException)
{
return SEInitializer_NssImpl_getSupportedServiceNames();
}