Move password repetition from gpg to gpg-agent.
[gnupg.git] / tools / gpgsm-gencert.sh
blobc66208e50b8e27a31f00a6906d194eb833e721b3
1 #!/bin/sh
2 # -*- sh -*-
3 # gpgsm-gencert.c - Generate X.509 certificates through GPGSM.
4 # Copyright (C) 2004, 2005 Free Software Foundation, Inc.
6 # This file is part of GnuPG.
8 # GnuPG is free software; you can redistribute it and/or modify
9 # it under the terms of the GNU General Public License as published by
10 # the Free Software Foundation; either version 3 of the License, or
11 # (at your option) any later version.
13 # GnuPG is distributed in the hope that it will be useful,
14 # but WITHOUT ANY WARRANTY; without even the implied warranty of
15 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
16 # GNU General Public License for more details.
18 # You should have received a copy of the GNU General Public License
19 # along with this program; if not, see <http://www.gnu.org/licenses/>.
21 set -e
23 ASSUAN_FP_IN=4
24 ASSUAN_FP_OUT=5
26 ASSUAN_COMMANDS="\
27 INPUT FD=$ASSUAN_FP_IN\n\
28 OUTPUT FD=$ASSUAN_FP_OUT --armor\n\
29 GENKEY\n\
30 BYE\n"
32 ANSWER=""
34 query_user()
36 message=$1; shift
38 echo "$message" >&2
39 echo -n "> " >&2
40 read answer
42 ANSWER=$answer;
45 query_user_menu()
47 message=$1; shift
48 i=0
50 echo "$message" >&2
51 for choice in "$@"; do
52 i=$(expr $i + 1)
53 echo " [$i] $choice" >&2
54 done
56 while true; do
57 j=1
58 echo -n "Your selection: " >&2
59 read idx
61 while [ $j -lt $i -o $j -eq $i ]; do
62 if [ "$idx" = $j ]; then
63 break
65 j=$(expr $j + 1)
66 done
67 if [ $j -lt $i -o $j -eq $i ]; then
68 break
70 done
72 i=0
73 for choice in "$@"; do
74 i=$(expr $i + 1)
75 if [ $i -eq $idx ]; then
76 ANSWER=$1
77 break;
79 shift
80 done
82 echo "You selected: $ANSWER" >&2
87 KEY_TYPE=""
88 while [ -z "$KEY_TYPE" ]; do
89 query_user_menu "Key type" "RSA" "Existing key" "Direct from card"
90 case "$ANSWER" in
91 RSA)
92 KEY_TYPE=$ANSWER
93 query_user_menu "Key length" "1024" "2048"
94 KEY_LENGTH=$ANSWER
95 KEY_GRIP=
97 Existing*)
98 # User requested to use an existing key; need to set some dummy defaults
99 query_user "Keygrip "
100 if [ -n "$ANSWER" ]; then
101 KEY_TYPE=RSA
102 KEY_LENGTH=1024
103 KEY_GRIP=$ANSWER
106 Direct*)
107 tmp=$(echo 'SCD SERIALNO' | gpg-connect-agent | \
108 awk '$2 == "SERIALNO" {print $3}')
109 if [ -z "$tmp" ]; then
110 echo "No card found" >&2
111 else
112 echo "Card with S/N $tmp found" >&2
113 tmp=$(echo 'SCD LEARN --force' | gpg-connect-agent | \
114 awk '$2 == "KEYPAIRINFO" {printf " %s", $4}')
115 sshid=$(echo 'SCD GETATTR $AUTHKEYID' | gpg-connect-agent | \
116 awk '$2 == "$AUTHKEYID" {print $3}')
117 [ -n "$sshid" ] && echo "gpg-agent uses $sshid as ssh key" >&2
118 query_user_menu "Select key " $tmp "back"
119 if [ "$ANSWER" != "back" ]; then
120 KEY_TYPE="card:$ANSWER"
121 KEY_LENGTH=
122 KEY_GRIP=
127 exit 1
129 esac
130 done
132 query_user_menu "Key usage" "sign, encrypt" "sign" "encrypt"
133 KEY_USAGE=$ANSWER
135 query_user "Name (DN)"
136 NAME=$ANSWER
138 EMAIL_ADDRESSES=
140 while : ; do
141 query_user "E-Mail addresses (end with an empty line)"
142 [ -z "$ANSWER" ] && break
143 EMAIL_ADDRESSES="${EMAIL_ADDRESSES}${LF}Name-Email: $ANSWER"
144 LF='
146 done
148 DNS_ADDRESSES=
150 while : ; do
151 query_user "DNS Names (optional; end with an empty line)"
152 [ -z "$ANSWER" ] && break
153 DNS_ADDRESSES="${DNS_ADDRESSES}${LF}Name-DNS: $ANSWER"
154 LF='
156 done
158 URI_ADDRESSES=
160 while : ; do
161 query_user "URIs (optional; end with an empty line)"
162 [ -z "$ANSWER" ] && break
163 URI_ADDRESSES="${URI_ADDRESSES}${LF}Name-URI: $ANSWER"
164 LF='
166 done
168 file_parameter=$(mktemp "/tmp/gpgsm.XXXXXX")
169 outfile=$(mktemp "/tmp/gpgsm.XXXXXX")
173 cat <<EOF
174 Key-Type: $KEY_TYPE
175 Key-Length: $KEY_LENGTH
176 Key-Usage: $KEY_USAGE
177 Name-DN: $NAME
179 [ -n "$KEY_GRIP" ] && echo "Key-Grip: $KEY_GRIP"
180 [ -n "$EMAIL_ADDRESSES" ] && echo "$EMAIL_ADDRESSES"
181 [ -n "$DNS_ADDRESSES" ] && echo "$DNS_ADDRESSES"
182 [ -n "$URI_ADDRESSES" ] && echo "$URI_ADDRESSES"
183 ) > "$file_parameter"
186 echo 'Parameters for certificate request to create:' >&2
187 cat -n "$file_parameter" >&2
188 echo >&2
190 query_user_menu "Really create such a CSR?" "yes" "no"
191 [ "$ANSWER" != "yes" ] && exit 1
194 printf "$ASSUAN_COMMANDS" | \
195 gpgsm --no-log-file --debug-level none --debug-none \
196 --server 4< "$file_parameter" 5>"$outfile" >/dev/null
198 cat "$outfile"
200 rm "$file_parameter" "$outfile"
201 exit 0