1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
|
package com.netscape.cmstools.key;
import java.io.FileInputStream;
import java.io.FileNotFoundException;
import javax.xml.bind.JAXBContext;
import javax.xml.bind.JAXBException;
import javax.xml.bind.Unmarshaller;
import org.apache.commons.cli.CommandLine;
import org.apache.commons.cli.Option;
import org.apache.commons.cli.ParseException;
import com.netscape.certsrv.key.KeyArchivalRequest;
import com.netscape.certsrv.key.KeyRequestResponse;
import com.netscape.cmstools.cli.CLI;
import com.netscape.cmstools.cli.MainCLI;
import com.netscape.cmsutil.util.Utils;
public class KeyArchiveCLI extends CLI {
public KeyCLI keyCLI;
public KeyArchiveCLI(KeyCLI keyCLI) {
super("archive", "Archive a secret at the DRM.", keyCLI);
this.keyCLI = keyCLI;
}
public void printHelp() {
formatter.printHelp(getFullName() + " [OPTIONS]", options);
}
public void execute(String[] args) {
Option option = new Option(null, "clientKeyId", true, "Unique client key identifier.");
option.setArgName("Client Key Identifier");
options.addOption(option);
option = new Option(null, "passphrase", true, "Passphrase to be stored.");
option.setArgName("Passphrase");
options.addOption(option);
option = new Option(null, "input", true,
"Location of the request template file.\nUsed for archiving already encrypted data.");
option.setArgName("Input file path");
options.addOption(option);
CommandLine cmd = null;
try {
cmd = parser.parse(options, args);
} catch (ParseException e) {
System.err.println("Error: " + e.getMessage());
printHelp();
System.exit(1);
}
String requestFile = cmd.getOptionValue("input");
KeyRequestResponse response = null;
if ((requestFile != null) && (requestFile.trim().length() != 0)) {
// Case where the request template file is used. For pre-encrypted data.
try {
JAXBContext context = JAXBContext.newInstance(KeyArchivalRequest.class);
Unmarshaller unmarshaller = context.createUnmarshaller();
FileInputStream fis = new FileInputStream(requestFile);
KeyArchivalRequest req = (KeyArchivalRequest) unmarshaller.unmarshal(fis);
if (req.getPKIArchiveOptions() != null) {
response = keyCLI.keyClient.archivePKIOptions(req.getClientKeyId(), req.getDataType(),
req.getKeyAlgorithm(), req.getKeySize(), Utils.base64decode(req.getPKIArchiveOptions()));
} else {
response = keyCLI.keyClient.archiveEncryptedData(req.getClientKeyId(), req.getDataType(),
req.getKeyAlgorithm(), req.getKeySize(), req.getAlgorithmOID(),
Utils.base64decode(req.getSymmetricAlgorithmParams()),
Utils.base64decode(req.getWrappedPrivateData()),
Utils.base64decode(req.getTransWrappedSessionKey()));
}
} catch (JAXBException e) {
System.err.println("Error: Cannot parse the request file.");
if (verbose)
e.printStackTrace();
System.exit(-1);
} catch (FileNotFoundException e) {
System.err.println("Error: Cannot locate file at path: " + requestFile);
if (verbose)
e.printStackTrace();
System.exit(-1);
}
} else {
// Simple case for archiving a passphrase
String clientKeyId = cmd.getOptionValue("clientKeyId");
String passphrase = cmd.getOptionValue("passphrase");
if (clientKeyId == null) {
System.err.println("Error: Client Key Id is not specified.");
printHelp();
System.exit(-1);
}
if (passphrase == null) {
System.err.println("Error: No passphrase provided to archive.");
printHelp();
System.exit(-1);
}
try {
response = keyCLI.keyClient.archivePassphrase(clientKeyId, passphrase);
} catch (Exception e) {
System.err.println(e.getMessage());
if (verbose)
e.printStackTrace();
System.exit(-1);
}
}
MainCLI.printMessage("Archival request details");
KeyCLI.printKeyRequestInfo(response.getRequestInfo());
}
}
|