1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
|
// --- BEGIN COPYRIGHT BLOCK ---
// This program is free software; you can redistribute it and/or modify
// it under the terms of the GNU General Public License as published by
// the Free Software Foundation; version 2 of the License.
//
// This program is distributed in the hope that it will be useful,
// but WITHOUT ANY WARRANTY; without even the implied warranty of
// MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
// GNU General Public License for more details.
//
// You should have received a copy of the GNU General Public License along
// with this program; if not, write to the Free Software Foundation, Inc.,
// 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA.
//
// (C) 2012 Red Hat, Inc.
// All rights reserved.
// --- END COPYRIGHT BLOCK ---
package com.netscape.cmstools.cert;
import java.io.BufferedReader;
import java.io.InputStreamReader;
import netscape.security.x509.RevocationReason;
import org.apache.commons.cli.CommandLine;
import org.apache.commons.cli.Option;
import com.netscape.certsrv.cert.CertData;
import com.netscape.certsrv.cert.CertRequestInfo;
import com.netscape.certsrv.cert.CertRevokeRequest;
import com.netscape.certsrv.dbs.certdb.CertId;
import com.netscape.certsrv.request.RequestStatus;
import com.netscape.cmstools.cli.CLI;
import com.netscape.cmstools.cli.MainCLI;
/**
* @author Endi S. Dewata
*/
public class CertHoldCLI extends CLI {
public CertCLI parent;
public CertHoldCLI(CertCLI parent) {
super("hold", "Place certificate on-hold");
this.parent = parent;
}
public void printHelp() {
formatter.printHelp(parent.name + "-" + name + " <Serial Number> [OPTIONS...]", options);
}
public void execute(String[] args) throws Exception {
Option option = new Option(null, "comments", true, "Comments");
option.setArgName("comments");
options.addOption(option);
options.addOption(null, "force", false, "Force");
CommandLine cmd = null;
try {
cmd = parser.parse(options, args);
} catch (Exception e) {
System.err.println("Error: " + e.getMessage());
printHelp();
System.exit(1);
}
String[] cmdArgs = cmd.getArgs();
if (cmdArgs.length != 1) {
printHelp();
System.exit(1);
}
CertId certID = new CertId(cmdArgs[0]);
CertData certData = parent.client.reviewCert(certID);
if (!cmd.hasOption("force")) {
System.out.println("Placing certificate on-hold:");
CertCLI.printCertData(certData, false, false);
if (verbose) System.out.println(" Nonce: " + certData.getNonce());
System.out.print("Are you sure (Y/N)? ");
System.out.flush();
BufferedReader reader = new BufferedReader(new InputStreamReader(System.in));
String line = reader.readLine();
if (!line.equalsIgnoreCase("Y")) {
System.exit(1);
}
}
CertRevokeRequest request = new CertRevokeRequest();
request.setReason(RevocationReason.CERTIFICATE_HOLD);
request.setComments(cmd.getOptionValue("comments"));
request.setNonce(certData.getNonce());
CertRequestInfo certRequestInfo = parent.client.revokeCert(certID, request);
if (verbose) {
CertCLI.printCertRequestInfo(certRequestInfo);
}
if (certRequestInfo.getRequestStatus() == RequestStatus.COMPLETE) {
MainCLI.printMessage("Placed certificate \"" + certID.toHexString() + "\" on-hold");
certData = parent.client.getCert(certID);
CertCLI.printCertData(certData, false, false);
} else {
MainCLI.printMessage("Request \"" + certRequestInfo.getRequestId() + "\": " + certRequestInfo.getRequestStatus());
}
}
}
|