Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 1 | #include "config.h" |
| 2 | |
| 3 | #include "csr.hpp" |
| 4 | |
| 5 | #include <openssl/pem.h> |
| 6 | |
| 7 | #include <filesystem> |
| 8 | #include <phosphor-logging/elog-errors.hpp> |
| 9 | #include <phosphor-logging/elog.hpp> |
| 10 | #include <xyz/openbmc_project/Certs/error.hpp> |
| 11 | #include <xyz/openbmc_project/Common/error.hpp> |
| 12 | |
Nan Zhou | e1289ad | 2021-12-28 11:02:56 -0800 | [diff] [blame] | 13 | namespace phosphor::certs |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 14 | { |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 15 | using X509_REQ_Ptr = std::unique_ptr<X509_REQ, decltype(&::X509_REQ_free)>; |
| 16 | using BIO_Ptr = std::unique_ptr<BIO, decltype(&::BIO_free_all)>; |
| 17 | using InternalFailure = |
| 18 | sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure; |
| 19 | using namespace phosphor::logging; |
| 20 | namespace fs = std::filesystem; |
| 21 | |
| 22 | CSR::CSR(sdbusplus::bus::bus& bus, const char* path, |
| 23 | CertInstallPath&& installPath, const Status& status) : |
| 24 | CSRIface(bus, path, true), |
| 25 | bus(bus), objectPath(path), certInstallPath(std::move(installPath)), |
| 26 | csrStatus(status) |
| 27 | { |
| 28 | // Emit deferred signal. |
| 29 | this->emit_object_added(); |
| 30 | } |
| 31 | |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 32 | std::string CSR::csr() |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 33 | { |
| 34 | if (csrStatus == Status::FAILURE) |
| 35 | { |
| 36 | log<level::ERR>("Failure in Generating CSR"); |
| 37 | elog<InternalFailure>(); |
| 38 | } |
| 39 | fs::path csrFilePath = certInstallPath; |
Nan Zhou | 718eef3 | 2021-12-28 11:03:30 -0800 | [diff] [blame^] | 40 | csrFilePath = csrFilePath.parent_path() / defaultCSRFileName; |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 41 | if (!fs::exists(csrFilePath)) |
| 42 | { |
| 43 | log<level::ERR>("CSR file doesn't exists", |
| 44 | entry("FILENAME=%s", csrFilePath.c_str())); |
| 45 | elog<InternalFailure>(); |
| 46 | } |
| 47 | |
| 48 | FILE* fp = std::fopen(csrFilePath.c_str(), "r"); |
Nan Zhou | cfb5802 | 2021-12-28 11:02:26 -0800 | [diff] [blame] | 49 | X509_REQ_Ptr x509Req(PEM_read_X509_REQ(fp, nullptr, nullptr, nullptr), |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 50 | ::X509_REQ_free); |
Nan Zhou | cfb5802 | 2021-12-28 11:02:26 -0800 | [diff] [blame] | 51 | if (x509Req == nullptr || fp == nullptr) |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 52 | { |
Nan Zhou | cfb5802 | 2021-12-28 11:02:26 -0800 | [diff] [blame] | 53 | if (fp != nullptr) |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 54 | { |
| 55 | std::fclose(fp); |
| 56 | } |
Nan Zhou | bf3cf75 | 2021-12-28 11:02:07 -0800 | [diff] [blame] | 57 | log<level::ERR>("ERROR occurred while reading CSR file", |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 58 | entry("FILENAME=%s", csrFilePath.c_str())); |
| 59 | elog<InternalFailure>(); |
| 60 | } |
| 61 | std::fclose(fp); |
| 62 | |
| 63 | BIO_Ptr bio(BIO_new(BIO_s_mem()), ::BIO_free_all); |
| 64 | int ret = PEM_write_bio_X509_REQ(bio.get(), x509Req.get()); |
| 65 | if (ret <= 0) |
| 66 | { |
Nan Zhou | bf3cf75 | 2021-12-28 11:02:07 -0800 | [diff] [blame] | 67 | log<level::ERR>("Error occurred while calling PEM_write_bio_X509_REQ"); |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 68 | elog<InternalFailure>(); |
| 69 | } |
| 70 | |
Nan Zhou | cfb5802 | 2021-12-28 11:02:26 -0800 | [diff] [blame] | 71 | BUF_MEM* mem = nullptr; |
Patrick Williams | e129be3 | 2021-04-30 20:35:19 -0500 | [diff] [blame] | 72 | BIO_get_mem_ptr(bio.get(), &mem); |
| 73 | std::string pem(mem->data, mem->length); |
| 74 | return pem; |
| 75 | } |
| 76 | |
Nan Zhou | e1289ad | 2021-12-28 11:02:56 -0800 | [diff] [blame] | 77 | } // namespace phosphor::certs |