1 /* $NetBSD: pkcs11-hmacmd5.c,v 1.1.1.4 2014/12/10 03:34:28 christos Exp $ */
4 * Copyright (C) 2014 Internet Systems Consortium, Inc. ("ISC")
6 * Permission to use, copy, modify, and/or distribute this software for any
7 * purpose with or without fee is hereby granted, provided that the above
8 * copyright notice and this permission notice appear in all copies.
10 * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
11 * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
12 * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
13 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
14 * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
15 * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
16 * PERFORMANCE OF THIS SOFTWARE.
20 * Portions copyright (c) 2008 Nominet UK. All rights reserved.
22 * Redistribution and use in source and binary forms, with or without
23 * modification, are permitted provided that the following conditions
25 * 1. Redistributions of source code must retain the above copyright
26 * notice, this list of conditions and the following disclaimer.
27 * 2. Redistributions in binary form must reproduce the above copyright
28 * notice, this list of conditions and the following disclaimer in the
29 * documentation and/or other materials provided with the distribution.
31 * THIS SOFTWARE IS PROVIDED BY THE AUTHOR ``AS IS'' AND ANY EXPRESS OR
32 * IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
33 * OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
34 * IN NO EVENT SHALL THE AUTHOR BE LIABLE FOR ANY DIRECT, INDIRECT,
35 * INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
36 * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
37 * DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
38 * THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
39 * (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
40 * THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
48 * Prints the MD5 HMAC of the standard input, using the PKCS#11 device.
51 * pkcs11-hmacmd5 [-m module] [-s $slot] [-n] [-p $pin]
52 * -m: PKCS#11 provider module. This must be the full
53 * path to a shared library object implementing the
54 * PKCS#11 API for a device.
57 * -n: don't log in to the PKCS#11 device
58 * -k: key name for the HMAC
70 #include <sys/types.h>
72 #include <isc/commandline.h>
73 #include <isc/result.h>
74 #include <isc/types.h>
76 #include <pk11/pk11.h>
77 #include <pk11/result.h>
79 #if !(defined(HAVE_GETPASSPHRASE) || (defined (__SVR4) && defined (__sun)))
80 #define getpassphrase(x) getpass(x)
83 /* Define static key template values */
84 static CK_BBOOL truevalue
= TRUE
;
85 static CK_BBOOL falsevalue
= FALSE
;
87 #define BLOCKSIZE 32768
89 char buffer
[BLOCKSIZE
+ 72];
93 main(int argc
, char *argv
[]) {
97 CK_SESSION_HANDLE hSession
;
98 CK_MECHANISM mech
= { CKM_MD5_HMAC
, NULL
, 0 };
100 CK_OBJECT_HANDLE hKey
= CK_INVALID_HANDLE
;
101 CK_OBJECT_CLASS keyClass
= CKO_SECRET_KEY
;
102 CK_KEY_TYPE keyType
= CKK_MD5_HMAC
;
103 CK_ATTRIBUTE keyTemplate
[] =
105 { CKA_CLASS
, &keyClass
, (CK_ULONG
) sizeof(keyClass
) },
106 { CKA_KEY_TYPE
, &keyType
, (CK_ULONG
) sizeof(keyType
) },
107 { CKA_TOKEN
, &falsevalue
, (CK_ULONG
) sizeof(falsevalue
) },
108 { CKA_PRIVATE
, &falsevalue
, (CK_ULONG
) sizeof(falsevalue
) },
109 { CKA_SIGN
, &truevalue
, (CK_ULONG
) sizeof(truevalue
) },
110 { CKA_VALUE
, NULL
, 0 }
113 pk11_optype_t op_type
= OP_DIGEST
;
114 char *lib_name
= NULL
;
117 isc_boolean_t logon
= ISC_TRUE
;
123 while ((c
= isc_commandline_parse(argc
, argv
, ":m:s:np:k:")) != -1) {
126 lib_name
= isc_commandline_argument
;
129 slot
= atoi(isc_commandline_argument
);
136 pin
= isc_commandline_argument
;
139 key
= isc_commandline_argument
;
143 "Option -%c requires an operand\n",
144 isc_commandline_option
);
149 fprintf(stderr
, "Unrecognised option: -%c\n",
150 isc_commandline_option
);
155 if (errflg
|| (key
== NULL
)) {
156 fprintf(stderr
, "Usage:\n");
158 "\tpkcs11-hmacmd5 [-m module] [-s slot] "
159 "[-n|-p pin] -k key\n");
164 for (i
= 0; i
< BLOCKSIZE
/ 2; i
++) {
165 switch (c
= *key
++) {
179 buffer
[i
>> 1] = (c
- '0') << 4;
181 buffer
[i
>> 1] |= c
- '0';
190 buffer
[i
>> 1] = (c
- 'A' + 10) << 4;
192 buffer
[i
>> 1] |= c
- 'A' + 10;
201 buffer
[i
>> 1] = (c
- 'a' + 10) << 4;
203 buffer
[i
>> 1] |= c
- 'a' + 10;
206 fprintf(stderr
, "Not hexdigit '%c' in key\n", c
);
212 fprintf(stderr
, "Even number of hexdigits in key\n");
216 keyTemplate
[5].pValue
= buffer
;
217 keyTemplate
[5].ulValueLen
= (CK_ULONG
) len
;
219 pk11_result_register();
221 /* Initialize the CRYPTOKI library */
222 if (lib_name
!= NULL
)
223 pk11_set_lib_name(lib_name
);
225 if (logon
&& pin
== NULL
)
226 pin
= getpassphrase("Enter Pin: ");
228 result
= pk11_get_session(&pctx
, op_type
, ISC_FALSE
, ISC_FALSE
, logon
,
229 (const char *) pin
, slot
);
230 if ((result
!= ISC_R_SUCCESS
) &&
231 (result
!= PK11_R_NORANDOMSERVICE
) &&
232 (result
!= PK11_R_NOAESSERVICE
)) {
233 fprintf(stderr
, "Error initializing PKCS#11: %s\n",
234 isc_result_totext(result
));
239 memset(pin
, 0, strlen((char *)pin
));
241 hSession
= pctx
.session
;
243 rv
= pkcs_C_CreateObject(hSession
, keyTemplate
, (CK_ULONG
) 6, &hKey
);
245 fprintf(stderr
, "C_CreateObject: Error = 0x%.8lX\n", rv
);
249 if (hKey
== CK_INVALID_HANDLE
) {
250 fprintf(stderr
, "C_CreateObject failed\n");
255 rv
= pkcs_C_SignInit(hSession
, &mech
, hKey
);
257 fprintf(stderr
, "C_SignInit: Error = 0x%.8lX\n", rv
);
266 n
= fread(buffer
+ sum
, 1, BLOCKSIZE
- sum
, stdin
);
268 if (sum
== BLOCKSIZE
)
272 fprintf(stderr
, "fread failed\n");
282 rv
= pkcs_C_SignUpdate(hSession
, (CK_BYTE_PTR
) buffer
,
283 (CK_ULONG
) BLOCKSIZE
);
286 "C_SignUpdate: Error = 0x%.8lX\n",
295 rv
= pkcs_C_SignUpdate(hSession
, (CK_BYTE_PTR
) buffer
,
299 "C_SignUpdate: Error = 0x%.8lX\n",
307 rv
= pkcs_C_SignFinal(hSession
, (CK_BYTE_PTR
) digest
, &len
);
309 fprintf(stderr
, "C_SignFinal: Error = 0x%.8lX\n", rv
);
314 fprintf(stderr
, "C_SignFinal: bad length = %lu\n", len
);
318 for (i
= 0; i
< 16; i
++)
319 printf("%02x", digest
[i
] & 0xff);
323 rv
= pkcs_C_DestroyObject(hSession
, hKey
);
324 if ((error
== 0) && (rv
!= CKR_OK
)) {
325 fprintf(stderr
, "C_DestroyObject: Error = 0x%.8lX\n", rv
);
330 pk11_return_session(&pctx
);
331 (void) pk11_finalize();