summaryrefslogtreecommitdiffstats
path: root/base/java-tools/src/com/netscape/cmstools/key/KeyArchiveCLI.java
blob: 6789957c333edeab5d7bd071e9a36c23ed3678cb (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
package com.netscape.cmstools.key;

import java.io.FileInputStream;
import java.io.FileNotFoundException;
import java.util.Arrays;

import javax.xml.bind.JAXBContext;
import javax.xml.bind.JAXBException;
import javax.xml.bind.Unmarshaller;

import org.apache.commons.cli.CommandLine;
import org.apache.commons.cli.Option;

import com.netscape.certsrv.key.KeyArchivalRequest;
import com.netscape.certsrv.key.KeyClient;
import com.netscape.certsrv.key.KeyRequestResponse;
import com.netscape.cmstools.cli.CLI;
import com.netscape.cmstools.cli.MainCLI;
import com.netscape.cmsutil.util.Utils;

public class KeyArchiveCLI extends CLI {
    public KeyCLI keyCLI;

    public KeyArchiveCLI(KeyCLI keyCLI) {
        super("archive", "Archive a secret in the DRM.", keyCLI);
        this.keyCLI = keyCLI;

        createOptions();
    }

    public void printHelp() {
        formatter.printHelp(getFullName() + " [OPTIONS...]", options);
    }

    public void createOptions() {
        Option option = new Option(null, "clientKeyID", true, "Unique client key identifier.");
        option.setArgName("Client Key Identifier");
        options.addOption(option);

        option = new Option(null, "passphrase", true, "Passphrase to be stored.");
        option.setArgName("Passphrase");
        options.addOption(option);

        option = new Option(null, "input", true,
                "Location of the request template file.\nUsed for archiving already encrypted data.");
        option.setArgName("Input file path");
        options.addOption(option);

        option = new Option(null, "realm", true, "Authorization realm.");
        option.setArgName("Realm");
        options.addOption(option);
    }

    public void execute(String[] args) throws Exception {
        // Always check for "--help" prior to parsing
        if (Arrays.asList(args).contains("--help")) {
            printHelp();
            return;
        }

        CommandLine cmd = parser.parse(options, args);

        String[] cmdArgs = cmd.getArgs();

        if (cmdArgs.length != 0) {
            throw new Exception("Too many arguments specified.");
        }

        String requestFile = cmd.getOptionValue("input");

        KeyRequestResponse response = null;
        KeyClient keyClient = keyCLI.getKeyClient();

        if (requestFile != null) {
            // Case where the request template file is used. For pre-encrypted data.
            try {
                JAXBContext context = JAXBContext.newInstance(KeyArchivalRequest.class);
                Unmarshaller unmarshaller = context.createUnmarshaller();
                FileInputStream fis = new FileInputStream(requestFile);
                KeyArchivalRequest req = (KeyArchivalRequest) unmarshaller.unmarshal(fis);

                if (req.getPKIArchiveOptions() != null) {
                    response = keyClient.archivePKIOptions(req.getClientKeyId(), req.getDataType(),
                            req.getKeyAlgorithm(), req.getKeySize(), Utils.base64decode(req.getPKIArchiveOptions()),
                            req.getRealm());
                } else {
                    response = keyClient.archiveEncryptedData(req.getClientKeyId(), req.getDataType(),
                            req.getKeyAlgorithm(), req.getKeySize(), req.getAlgorithmOID(),
                            Utils.base64decode(req.getSymmetricAlgorithmParams()),
                            Utils.base64decode(req.getWrappedPrivateData()),
                            Utils.base64decode(req.getTransWrappedSessionKey()),
                            req.getRealm());
                }

            } catch (JAXBException e) {
                throw new Exception("Cannot parse the request file.", e);

            } catch (FileNotFoundException e) {
                throw new Exception("Cannot locate file at path: " + requestFile, e);
            }

        } else {
            // Simple case for archiving a passphrase
            String clientKeyId = cmd.getOptionValue("clientKeyID");
            String passphrase = cmd.getOptionValue("passphrase");
            if (clientKeyId == null) {
                throw new Exception("Client Key Id is not specified.");
            }
            if (passphrase == null) {
                throw new Exception("No passphrase provided to archive.");
            }
            String realm = cmd.getOptionValue("realm");

            response = keyClient.archivePassphrase(clientKeyId, passphrase, realm);
        }

        MainCLI.printMessage("Archival request details");
        KeyCLI.printKeyRequestInfo(response.getRequestInfo());
    }
}