/* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththis
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */ #include"seccomon.h" #include"prio.h" #include"prprf.h" #include"plhash.h" #include"prenv.h"
static PRBool
userIsRoot()
{ /* this works for linux and all unixes that we know off
though it isn't stated as such in POSIX documentation */ return getuid() == 0;
}
f = fopen("/proc/sys/crypto/fips_enabled", "r"); if (!f) { /* if we don't have a proc flag, fall back to the
* environment variable */ return getFIPSEnv();
}
/* can't get any space */ if (module_list == NULL) { return NULL;
}
sysdb = getSystemDB();
userdb = getUserDB();
/* Don't open root's user DB */ if (userdb != NULL && !userIsRoot()) { /* return a list of databases to open. First the user Database */
module_list[next++] = PR_smprintf( "library= " "module=\"NSS User database\" " "parameters=\"configdir='sql:%s' %s tokenDescription='NSS user database'\" " "NSS=\"trustOrder=75 %sflags=internal%s\"",
userdb, stripped_parameters, nssflags,
isFIPS ? ",FIPS" : "");
/* now open the user's defined PKCS #11 modules */ /* skip the local user DB entry */
module_list[next++] = PR_smprintf( "library= " "module=\"NSS User database\" " "parameters=\"configdir='sql:%s' %s\" " "NSS=\"flags=internal,moduleDBOnly,defaultModDB,skipFirst\"",
userdb, stripped_parameters);
}
/* now the system database (always read only unless it's root) */ if (sysdb) { constchar *readonly = userCanModifySystemDB() ? "" : "flags=readonly";
module_list[next++] = PR_smprintf( "library= " "module=\"NSS system database\" " "parameters=\"configdir='sql:%s' tokenDescription='NSS system database' %s\" " "NSS=\"trustOrder=80 %sflags=internal,critical\"",
sysdb, readonly, nssflags);
}
/* that was the last module */
module_list[next] = 0;
/* determine what options the user was trying to open this database with */ /* filename is the directory pointed to by configdir= */ /* stripped is the rest of the parameters with configdir= stripped out */ static SECStatus
parse_parameters(constchar *parameters, char **filename, char **stripped)
{ constchar *sourcePrev; constchar *sourceCurr; char *targetCurr; char *newStripped;
*filename = NULL;
*stripped = NULL;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.