<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN"> <html><head><meta http-equiv="Content-Type" content="text/html;charset=UTF-8"> <title>DTN Reference Implementation: SecurityCommand.cc Source File</title> <link href="doxygen.css" rel="stylesheet" type="text/css"> <link href="tabs.css" rel="stylesheet" type="text/css"> </head><body> <!-- Generated by Doxygen 1.5.6 --> <div class="navigation" id="top"> <div class="tabs"> <ul> <li><a href="main.html"><span>Main Page</span></a></li> <li><a href="namespaces.html"><span>Namespaces</span></a></li> <li><a href="annotated.html"><span>Classes</span></a></li> <li class="current"><a href="files.html"><span>Files</span></a></li> </ul> </div> <h1>SecurityCommand.cc</h1><a href="SecurityCommand_8cc.html">Go to the documentation of this file.</a><div class="fragment"><pre class="fragment"><a name="l00001"></a>00001 <span class="comment">/*</span> <a name="l00002"></a>00002 <span class="comment"> * Copyright 2007 BBN Technologies Corporation</span> <a name="l00003"></a>00003 <span class="comment"> *</span> <a name="l00004"></a>00004 <span class="comment"> * Licensed under the Apache License, Version 2.0 (the "License"); you</span> <a name="l00005"></a>00005 <span class="comment"> * may not use this file except in compliance with the License. You</span> <a name="l00006"></a>00006 <span class="comment"> * may obtain a copy of the License at</span> <a name="l00007"></a>00007 <span class="comment"> *</span> <a name="l00008"></a>00008 <span class="comment"> * http://www.apache.org/licenses/LICENSE-2.0</span> <a name="l00009"></a>00009 <span class="comment"> *</span> <a name="l00010"></a>00010 <span class="comment"> * Unless required by applicable law or agreed to in writing, software</span> <a name="l00011"></a>00011 <span class="comment"> * distributed under the License is distributed on an "AS IS" BASIS,</span> <a name="l00012"></a>00012 <span class="comment"> * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or</span> <a name="l00013"></a>00013 <span class="comment"> * implied.</span> <a name="l00014"></a>00014 <span class="comment"> */</span> <a name="l00015"></a>00015 <a name="l00016"></a>00016 <span class="comment">/*</span> <a name="l00017"></a>00017 <span class="comment"> * $Id$</span> <a name="l00018"></a>00018 <span class="comment"> */</span> <a name="l00019"></a>00019 <a name="l00020"></a>00020 <span class="preprocessor">#ifdef HAVE_CONFIG_H</span> <a name="l00021"></a>00021 <span class="preprocessor"></span><span class="preprocessor"># include <<a class="code" href="dtn-config_8h.html">dtn-config.h</a>></span> <a name="l00022"></a>00022 <span class="preprocessor">#endif</span> <a name="l00023"></a>00023 <span class="preprocessor"></span> <a name="l00024"></a>00024 <span class="preprocessor">#ifdef BSP_ENABLED</span> <a name="l00025"></a>00025 <span class="preprocessor"></span> <a name="l00026"></a>00026 <span class="preprocessor">#include <cstring></span> <a name="l00027"></a>00027 <span class="preprocessor">#include <cstdio></span> <a name="l00028"></a>00028 <span class="preprocessor">#include <oasys/util/Base16.h></span> <a name="l00029"></a>00029 <a name="l00030"></a>00030 <span class="preprocessor">#include "<a class="code" href="SecurityCommand_8h.html">SecurityCommand.h</a>"</span> <a name="l00031"></a>00031 <span class="preprocessor">#include "<a class="code" href="SPD_8h.html">security/SPD.h</a>"</span> <a name="l00032"></a>00032 <span class="preprocessor">#include "<a class="code" href="KeyDB_8h.html">security/KeyDB.h</a>"</span> <a name="l00033"></a>00033 <span class="preprocessor">#include "<a class="code" href="Ciphersuite_8h.html">security/Ciphersuite.h</a>"</span> <a name="l00034"></a>00034 <a name="l00035"></a>00035 <span class="keyword">namespace </span>dtn { <a name="l00036"></a>00036 <a name="l00037"></a>00037 SecurityCommand::SecurityCommand() <a name="l00038"></a>00038 : TclCommand(<span class="stringliteral">"security"</span>) <a name="l00039"></a>00039 { <a name="l00040"></a>00040 add_to_help(<span class="stringliteral">"setpolicy [in | out] [psb] [cb] [bab]"</span>, <a name="l00041"></a>00041 <span class="stringliteral">"Set inbound or outbound policy to require the specified\n"</span> <a name="l00042"></a>00042 <span class="stringliteral">"combination of PSB, CB, and/or BAB."</span>); <a name="l00043"></a>00043 add_to_help(<span class="stringliteral">"setkey <host> <cs_num> <key>"</span>, <a name="l00044"></a>00044 <span class="stringliteral">"Set the key to use for the specified host and ciphersuite\n"</span> <a name="l00045"></a>00045 <span class="stringliteral">"number. <host> may also be the wildcard symbol \"*\"."</span>); <a name="l00046"></a>00046 add_to_help(<span class="stringliteral">"dumpkeys"</span>, <a name="l00047"></a>00047 <span class="stringliteral">"Dump the contents of the keystore to the screen."</span>); <a name="l00048"></a>00048 add_to_help(<span class="stringliteral">"flushkeys"</span>, <a name="l00049"></a>00049 <span class="stringliteral">"Erase all keys from the keystore."</span>); <a name="l00050"></a>00050 } <a name="l00051"></a>00051 <a name="l00052"></a>00052 <span class="keywordtype">int</span> <a name="l00053"></a>00053 SecurityCommand::exec(<span class="keywordtype">int</span> argc, <span class="keyword">const</span> <span class="keywordtype">char</span>** argv, Tcl_Interp* interp) <a name="l00054"></a>00054 { <a name="l00055"></a>00055 (void)interp; <a name="l00056"></a>00056 <a name="l00057"></a>00057 <span class="keywordflow">if</span> (argc < 2) { <a name="l00058"></a>00058 resultf(<span class="stringliteral">"need a security subcommand"</span>); <a name="l00059"></a>00059 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00060"></a>00060 } <a name="l00061"></a>00061 <a name="l00062"></a>00062 <span class="keyword">const</span> <span class="keywordtype">char</span>* cmd = argv[1]; <a name="l00063"></a>00063 <a name="l00064"></a>00064 <span class="keywordflow">if</span> (strcmp(cmd, <span class="stringliteral">"setpolicy"</span>) == 0) { <a name="l00065"></a>00065 <span class="comment">// security setpolicy [in | out] [psb] [cb] [bab]</span> <a name="l00066"></a>00066 <span class="keywordflow">if</span> (argc < 3 || argc > 6) { <a name="l00067"></a>00067 wrong_num_args(argc, argv, 2, 3, 6); <a name="l00068"></a>00068 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00069"></a>00069 } <a name="l00070"></a>00070 <a name="l00071"></a>00071 SPD::spd_direction_t direction; <a name="l00072"></a>00072 <span class="keywordflow">if</span> (strcmp(argv[2], <span class="stringliteral">"in"</span>) == 0) <a name="l00073"></a>00073 direction = SPD::SPD_DIR_IN; <a name="l00074"></a>00074 <span class="keywordflow">else</span> <span class="keywordflow">if</span> (strcmp(argv[2], <span class="stringliteral">"out"</span>) == 0) <a name="l00075"></a>00075 direction = SPD::SPD_DIR_OUT; <a name="l00076"></a>00076 <span class="keywordflow">else</span> { <a name="l00077"></a>00077 resultf(<span class="stringliteral">"invalid direction argument \"%s\" (must be one of "</span> <a name="l00078"></a>00078 <span class="stringliteral">"\"in\" or \"out\")"</span>, argv[2]); <a name="l00079"></a>00079 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00080"></a>00080 } <a name="l00081"></a>00081 <a name="l00082"></a>00082 <span class="keywordtype">int</span> policy = SPD::SPD_USE_NONE; <a name="l00083"></a>00083 <span class="keywordflow">for</span> (<span class="keywordtype">int</span> i = 3; i < argc; i++) { <a name="l00084"></a>00084 <span class="keywordflow">if</span> (strcmp(argv[i], <span class="stringliteral">"psb"</span>) == 0) <a name="l00085"></a>00085 policy |= SPD::SPD_USE_PSB; <a name="l00086"></a>00086 <span class="keywordflow">else</span> <span class="keywordflow">if</span> (strcmp(argv[i], <span class="stringliteral">"cb"</span>) == 0) <a name="l00087"></a>00087 policy |= SPD::SPD_USE_CB; <a name="l00088"></a>00088 <span class="keywordflow">else</span> <span class="keywordflow">if</span> (strcmp(argv[i], <span class="stringliteral">"bab"</span>) == 0) <a name="l00089"></a>00089 policy |= SPD::SPD_USE_BAB; <a name="l00090"></a>00090 <span class="keywordflow">else</span> { <a name="l00091"></a>00091 resultf(<span class="stringliteral">"invalid argument \"%s\""</span>, argv[i]); <a name="l00092"></a>00092 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00093"></a>00093 } <a name="l00094"></a>00094 } <a name="l00095"></a>00095 <a name="l00096"></a>00096 SPD::set_global_policy(direction, (SPD::spd_policy_t)policy); <a name="l00097"></a>00097 <a name="l00098"></a>00098 <span class="keywordflow">return</span> TCL_OK; <a name="l00099"></a>00099 <a name="l00100"></a>00100 } <span class="keywordflow">else</span> <span class="keywordflow">if</span> (strcmp(cmd, <span class="stringliteral">"setkey"</span>) == 0) { <a name="l00101"></a>00101 <span class="comment">// security setkey <host> <cs_num> <key></span> <a name="l00102"></a>00102 <span class="keywordflow">if</span> (argc != 5) { <a name="l00103"></a>00103 wrong_num_args(argc, argv, 2, 5, 5); <a name="l00104"></a>00104 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00105"></a>00105 } <a name="l00106"></a>00106 <a name="l00107"></a>00107 <span class="keyword">const</span> <span class="keywordtype">char</span>* host_arg = argv[2]; <a name="l00108"></a>00108 <span class="keyword">const</span> <span class="keywordtype">char</span>* cs_num_arg = argv[3]; <a name="l00109"></a>00109 <span class="keyword">const</span> <span class="keywordtype">char</span>* key_arg = argv[4]; <a name="l00110"></a>00110 <a name="l00111"></a>00111 <span class="keywordtype">int</span> cs_num; <a name="l00112"></a>00112 <span class="keywordflow">if</span> (sscanf(cs_num_arg, <span class="stringliteral">"%i"</span>, &cs_num) != 1) { <a name="l00113"></a>00113 resultf(<span class="stringliteral">"invalid cs_num argument \"%s\""</span>, cs_num_arg); <a name="l00114"></a>00114 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00115"></a>00115 } <a name="l00116"></a>00116 <span class="keywordflow">if</span> (! KeyDB::validate_cs_num(cs_num)) { <a name="l00117"></a>00117 resultf(<span class="stringliteral">"invalid ciphersuite number %#x"</span>, cs_num); <a name="l00118"></a>00118 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00119"></a>00119 } <a name="l00120"></a>00120 <a name="l00121"></a>00121 <span class="keywordtype">size_t</span> key_arg_len = strlen(key_arg); <a name="l00122"></a>00122 <span class="keywordflow">if</span> ((key_arg_len % 2) != 0) { <a name="l00123"></a>00123 resultf(<span class="stringliteral">"invalid key argument (must be even length)"</span>); <a name="l00124"></a>00124 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00125"></a>00125 } <a name="l00126"></a>00126 <a name="l00127"></a>00127 <span class="keywordtype">size_t</span> key_len = key_arg_len / 2; <a name="l00128"></a>00128 <span class="keywordflow">if</span> (! KeyDB::validate_key_len(cs_num, &key_len)) { <a name="l00129"></a>00129 resultf(<span class="stringliteral">"wrong key length for ciphersuite (expected %d bytes)"</span>, <a name="l00130"></a>00130 (<span class="keywordtype">int</span>)key_len); <a name="l00131"></a>00131 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00132"></a>00132 } <a name="l00133"></a>00133 <a name="l00134"></a>00134 <span class="comment">// convert key from ASCII hexadecimal to raw bytes</span> <a name="l00135"></a>00135 u_char* key = <span class="keyword">new</span> u_char[key_len]; <a name="l00136"></a>00136 <span class="keywordflow">for</span> (<span class="keywordtype">int</span> i = 0; i < (int)key_len; i++) <a name="l00137"></a>00137 { <a name="l00138"></a>00138 <span class="keywordtype">int</span> b = 0; <a name="l00139"></a>00139 <a name="l00140"></a>00140 <span class="keywordflow">for</span> (<span class="keywordtype">int</span> j = 0; j <= 1; j++) <a name="l00141"></a>00141 { <a name="l00142"></a>00142 <span class="keywordtype">int</span> c = (int)key_arg[2*i+j]; <a name="l00143"></a>00143 b <<= 4; <a name="l00144"></a>00144 <a name="l00145"></a>00145 <span class="keywordflow">if</span> (c >= <span class="charliteral">'0'</span> && c <= <span class="charliteral">'9'</span>) <a name="l00146"></a>00146 b |= c - <span class="charliteral">'0'</span>; <a name="l00147"></a>00147 <span class="keywordflow">else</span> <span class="keywordflow">if</span> (c >= <span class="charliteral">'A'</span> && c <= <span class="charliteral">'F'</span>) <a name="l00148"></a>00148 b |= c - <span class="charliteral">'A'</span> + 10; <a name="l00149"></a>00149 <span class="keywordflow">else</span> <span class="keywordflow">if</span> (c >= <span class="charliteral">'a'</span> && c <= <span class="charliteral">'f'</span>) <a name="l00150"></a>00150 b |= c - <span class="charliteral">'a'</span> + 10; <a name="l00151"></a>00151 <span class="keywordflow">else</span> { <a name="l00152"></a>00152 resultf(<span class="stringliteral">"invalid character '%c' in key argument"</span>, <a name="l00153"></a>00153 (<span class="keywordtype">char</span>)c); <a name="l00154"></a>00154 <span class="keyword">delete</span> key; <a name="l00155"></a>00155 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00156"></a>00156 } <a name="l00157"></a>00157 } <a name="l00158"></a>00158 <a name="l00159"></a>00159 key[i] = (u_char)(b); <a name="l00160"></a>00160 } <a name="l00161"></a>00161 <a name="l00162"></a>00162 KeyDB::Entry new_entry = <a name="l00163"></a>00163 KeyDB::Entry(host_arg, cs_num, key, key_len); <a name="l00164"></a>00164 KeyDB::set_key(new_entry); <a name="l00165"></a>00165 <a name="l00166"></a>00166 <span class="keyword">delete</span> key; <a name="l00167"></a>00167 <span class="keywordflow">return</span> TCL_OK; <a name="l00168"></a>00168 <a name="l00169"></a>00169 } <span class="keywordflow">else</span> <span class="keywordflow">if</span> (strcmp(cmd, <span class="stringliteral">"dumpkeys"</span>) == 0) { <a name="l00170"></a>00170 <span class="comment">// security dumpkeys</span> <a name="l00171"></a>00171 <span class="keywordflow">if</span> (argc != 2) { <a name="l00172"></a>00172 wrong_num_args(argc, argv, 2, 2, 2); <a name="l00173"></a>00173 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00174"></a>00174 } <a name="l00175"></a>00175 <a name="l00176"></a>00176 oasys::StringBuffer <a class="code" href="num2sdnv_8c.html#a81cdcc7ff6987bc85c073253e32715f">buf</a>; <a name="l00177"></a>00177 KeyDB::dump_header(&buf); <a name="l00178"></a>00178 <a class="code" href="serialsource_8c.html#87b713d53023266d98d45b86312c26aa">KeyDB::dump</a>(&buf); <a name="l00179"></a>00179 set_result(buf.c_str()); <a name="l00180"></a>00180 <span class="keywordflow">return</span> TCL_OK; <a name="l00181"></a>00181 <a name="l00182"></a>00182 } <span class="keywordflow">else</span> <span class="keywordflow">if</span> (strcmp(cmd, <span class="stringliteral">"flushkeys"</span>) == 0) { <a name="l00183"></a>00183 <span class="comment">// security flushkeys</span> <a name="l00184"></a>00184 <span class="keywordflow">if</span> (argc != 2) { <a name="l00185"></a>00185 wrong_num_args(argc, argv, 2, 2, 2); <a name="l00186"></a>00186 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00187"></a>00187 } <a name="l00188"></a>00188 <a name="l00189"></a>00189 KeyDB::flush_keys(); <a name="l00190"></a>00190 <a name="l00191"></a>00191 } <span class="keywordflow">else</span> { <a name="l00192"></a>00192 resultf(<span class="stringliteral">"no such security subcommand %s"</span>, cmd); <a name="l00193"></a>00193 <span class="keywordflow">return</span> TCL_ERROR; <a name="l00194"></a>00194 } <a name="l00195"></a>00195 <a name="l00196"></a>00196 <span class="keywordflow">return</span> TCL_OK; <a name="l00197"></a>00197 } <a name="l00198"></a>00198 <a name="l00199"></a>00199 } <span class="comment">// namespace dtn</span> <a name="l00200"></a>00200 <a name="l00201"></a>00201 <span class="preprocessor">#endif </span><span class="comment">/* BSP_ENABLED */</span> </pre></div></div> <hr size="1"><address style="text-align: right;"><small>Generated on Mon Jul 21 14:09:46 2008 for DTN Reference Implementation by <a href="http://www.doxygen.org/index.html"> <img src="doxygen.png" alt="doxygen" align="middle" border="0"></a> 1.5.6 </small></address> </body> </html>