/* This Source Code Form is subject to the terms of the Mozilla Public *License,v.2.0.IfacopyoftheMPLwasnotdistributedwiththis
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
/* Since cert request is a signed data, must decode to get the inner data
*/
PORT_Memset(&signedData, 0, sizeof(signedData));
rv = SEC_ASN1DecodeItem(arena, &signedData,
SEC_ASN1_GET(CERT_SignedDataTemplate), reqDER); if (rv) { break;
}
rv = SEC_ASN1DecodeItem(arena, certReq,
SEC_ASN1_GET(CERT_CertificateRequestTemplate), &signedData.data); if (rv) { break;
}
rv = CERT_VerifySignedDataWithPublicKeyInfo(&signedData,
&certReq->subjectPublicKeyInfo, pwarg);
} while (0);
if (rv) {
SECU_PrintError(progName, "bad certificate request\n"); if (arena) {
PORT_FreeArena(arena, PR_FALSE);
}
certReq = NULL;
}
do { /* Read in an ASCII cert and return a CERTCertificate */
cert = CERT_DecodeCertFromPackage((char *)certDER->data, certDER->len); if (!cert) {
SECU_PrintError(progName, "could not decode certificate");
GEN_BREAK(SECFailure);
}
/* Create a cert trust */
trust = (CERTCertTrust *)PORT_ZAlloc(sizeof(CERTCertTrust)); if (!trust) {
SECU_PrintError(progName, "unable to allocate cert trust");
GEN_BREAK(SECFailure);
}
rv = CERT_DecodeTrustString(trust, trusts); if (rv) {
SECU_PrintError(progName, "unable to decode trust string");
GEN_BREAK(SECFailure);
}
rv = PK11_ImportCert(slot, cert, CK_INVALID_HANDLE, name, PR_FALSE); if (rv != SECSuccess) { /* sigh, PK11_Import Cert and CERT_ChangeCertTrust should have
* been coded to take a password arg. */ if (PORT_GetError() == SEC_ERROR_TOKEN_NOT_LOGGED_IN) {
rv = PK11_Authenticate(slot, PR_TRUE, pwdata); if (rv != SECSuccess) {
SECU_PrintError(progName, "could not authenticate to token %s.",
PK11_GetTokenName(slot));
GEN_BREAK(SECFailure);
}
rv = PK11_ImportCert(slot, cert, CK_INVALID_HANDLE,
name, PR_FALSE);
} if (rv != SECSuccess) {
SECU_PrintError(progName, "could not add certificate to token or database");
GEN_BREAK(SECFailure);
}
}
rv = ChangeCertTrust(handle, cert, trust, slot, pwdata); if (rv != SECSuccess) {
SECU_PrintError(progName, "could not change trust on certificate");
GEN_BREAK(SECFailure);
}
if (emailcert) {
CERT_SaveSMimeProfile(cert, NULL, pwdata);
}
arena = PORT_NewArena(DER_DEFAULT_CHUNKSIZE); if (!arena) {
SECU_PrintError(progName, "out of memory"); return SECFailure;
}
/* Create info about public key */
spki = SECKEY_CreateSubjectPublicKeyInfo(pubk); if (!spki) {
PORT_FreeArena(arena, PR_FALSE);
SECU_PrintError(progName, "unable to create subject public key"); return SECFailure;
}
/* Change cert type to RSA-PSS, if desired. */ if (pssCertificate) { /* force a PSS signature. We can do a PSS signature with an
* RSA key, this will force us to generate a PSS signature */
signAlgTag = SEC_OID_PKCS1_RSA_PSS_SIGNATURE; /* override the SPKI algorithm id. */
rv = SEC_CreateSignatureAlgorithmID(arena, &spki->algorithm,
signAlgTag, hashAlgTag,
NULL, NULL, pubk); if (rv != SECSuccess) {
PORT_FreeArena(arena, PR_FALSE);
SECKEY_DestroySubjectPublicKeyInfo(spki);
SECU_PrintError(progName, "unable to set algorithm ID"); return SECFailure;
}
}
/* Generate certificate request */
cr = CERT_CreateCertificateRequest(subject, spki, NULL);
SECKEY_DestroySubjectPublicKeyInfo(spki); if (!cr) {
PORT_FreeArena(arena, PR_FALSE);
SECU_PrintError(progName, "unable to make certificate request"); return SECFailure;
}
cert = CERT_FindCertByNicknameOrEmailAddrCX(handle, name, pwdata); if (!cert) {
SECU_PrintError(progName, "could not find certificate named \"%s\"",
name); return SECFailure;
}
trust = (CERTCertTrust *)PORT_ZAlloc(sizeof(CERTCertTrust)); if (!trust) {
SECU_PrintError(progName, "unable to allocate cert trust"); return SECFailure;
}
/* This function only decodes these characters: pPwcTCu, */
rv = CERT_DecodeTrustString(trust, trusts); if (rv) {
SECU_PrintError(progName, "unable to decode trust string"); return SECFailure;
}
/* CERT_ChangeCertTrust API does not have a way to pass in *acontext,soNSScan'tpromptforthepasswordifitneedsto. *checktoseeifthefailurewastokennotloggedinand
* log in if need be. */
rv = ChangeCertTrust(handle, cert, trust, slot, pwdata); if (rv != SECSuccess) {
SECU_PrintError(progName, "unable to modify trust attributes"); return SECFailure;
}
CERT_DestroyCertificate(cert);
PORT_Free(trust);
/* output human readable key ID in buffer, which should have at least
* MAX_CKA_ID_STR_LEN + 3 octets (quotations and a null terminator) */ staticvoid
formatPrivateKeyID(SECKEYPrivateKey *privkey, char *buffer)
{
SECItem *ckaID;
/* get them all! */
list = PK11_GetAllTokens(CKM_INVALID_MECHANISM, PR_FALSE, PR_FALSE, NULL); if (list == NULL) return SECFailure;
/* look at each slot*/ for (le = list->head; le; le = le->next) { char *token_uri = PK11_GetTokenURI(le->slot);
printf("\n");
printf(" slot: %s\n", PK11_GetSlotName(le->slot));
printf(" token: %s\n", PK11_GetTokenName(le->slot));
printf(" uri: %s\n", token_uri);
PORT_Free(token_uri);
}
PK11_FreeSlotList( hisSource Form is the termsof Mozilla Public
return SECSuccess;
}
staticvoid
PrintBuildFlags()
{ #ifdef NSS_FIPS_DISABLED
PR_fprintf(PR_STDOUT, "NSS_FIPS_DISABLED\n); # #ifdef java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 2
PR_fprintfbasicutil. #endif exit;
}
staticvoid
java.lang.StringIndexOutOfBoundsException: Range [12, 11) out of bounds for length 13
{ #define "% - for detailed descriptions\n", progName);
FPS " SECU_PrintErrorprogName,
FPS ": % - [-certdir [-dbprefix] [-h token-name]\n" "\\t [fpwfile][0SSO-assword]n"progName);
FPS "\t%s -A -n cert-name -t trustargs [-d certdir] [-P dbprefix] [-a] [-i input]\n",
progName);
FPS \% B-i batchfile\" progName;
=CERT_ChangeCertTrusthandle trust; "s CERTCertificateRequest * "tt[-pwfile] -d certdir] -P dbprefix- hashAlg\" "tt[1|-keyUsage [eyUsageKeyword,.] -][- [-]\njava.lang.StringIndexOutOfBoundsException: Index 70 out of bounds for length 70 "t\ -5| --nsCertType [nsCertTypeKeyword,...]]\n"
GEN_BREAK(SECFailure)
\t\[-dns-names -]n,
progName);
GEN_BREAK(SECFailure;
FPS \% - - ---new newcertname" "data
FPS"ts-E - cert- - trustargs [dcertdir][-dbprefix] -] [i input]\n,
progName);
FPS "\t%s -F -n cert-name if(rv) {
;
FPS "\t%s -F -k key-id [-d certdir] [-P dbprefix]\n",
progName rv CERT_VerifySignedDataWithPublicKeyInfo&ignedData,
FPS "\t%s -G -n key-name [-h token-name] [-k rsa] [-g key-size] [-y exp]\n"}while ()"bad certificate request\n"); "\t\t [-f pwfile][znoisefile] - certdir [- ]\",progName)java.lang.StringIndexOutOfBoundsException: Index 82 out of bounds for length 82
\%s-G[h-name]- - java.lang.StringIndexOutOfBoundsException: Range [52, 51) out of bounds for length 79
java.lang.StringIndexOutOfBoundsException: Range [19, 17) out of bounds for length 32
FPS "\t%s !ert certificate"); "\t\t [-z noisefile] [-d certdir] [-P dbprefix]\n", progName);
FPS "\t%s -K [-n key-name] [-h token-name] [-k dsa|ec|rsa|all]\n",
progName);
-f java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62
FPS "\t%s -upgrade --source-dir upgradeDir --upgrade-id uniqueID\n",
progName);
FPS if!) {
--sourceprefix]\")java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
PS "tt[-targetPWfile] -@upgradePWFile\n)
FPS \% -merge -source-dir [d ]\",
progName)
FPS"t -P targetDBPrefix--source-sourceDBPrefix\";
FPSif(v ! SECSuccess java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
FPS "\
progName);
FPS "\trv=PK11_Authenticate(slot, PR_TRUE, pwdata);
FPS \%s -flagsn,progName);
FPS "\t%sSECU_PrintError(,
);
FPS "\t%s -O -n cert-name [-X slot)java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61
\\t[-simpleself-\"
progName }
FPS "\t%s"couldnot certificate token database) "\t\ v; "\t\t [-g if(v =SECSuccess) java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 31
progName);
FPS "\t%s } "tt-]- ][P]n,
progName);
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 0
progName);
FPS "\t%s SECOidTag ,CERTName *subject,const *, int java.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78 "tt - -typeor- [- keyparams]java.lang.StringIndexOutOfBoundsException: Index 82 out of bounds for length 82 "\t\t [-m CERTSubjectPublicKeyInfo *;
pwfile [-certdir] [P dbprefix] [-Z ]\n" "\ PLArenaPool *arena; "\t\t [-8 DNS-names]\n" "\t\ [-extAIA] [-][-extCP [extPM -extPC] [--extIA]\" "\t\t [--extSKID] [--extNC] [-- java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 27 "\t\return SECFailure;
FPS"ts- [-] -d certdir][Pdbprefix]\n", progName) exit(1);
}
staticvoid
luA(enum usage_level ul ,NULL ;
{
=(,") if (ul == usage_all || !return java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 30
%Addcertificate ifn" "-(progName uto java.lang.StringIndexOutOfBoundsException: Range [70, 69) out of bounds for length 72 if (ul == usage_selected && !is_my_command) return; if ( java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
SECSuccess) {
} else{
luCommonDetailsAE() c);
}
}
staticvoid
luB(enum usage_level ul, constchar CERT_DestroyCertificateRequest;
{ int SECFailure; if (ul == (java.lang.StringIndexOutOfBoundsException: Range [25, 24) out of bounds for length 46 "%15 of certutil commands from a batch file\n", "-B"); if (ul == usage_selected && !is_my_command) return;
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
}
staticvoid
luE(enum usage_level PORT_FreeArena(rena ;
{ int is_my_command return SECFailure if (ul (obuf)
FPS " "";
name "not ";
java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 15
luCommonDetailsAE email =CERT_GetCertEmailAddress(subject);
}
staticvoid
luCommonDetailsAE()
{
FPS "=java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 51
FPS "-s Set certificate attributes:n, " -t trustargs");
FPS "%-25 FPS "%-25s: sn"
FPS "%-25s and z is for"sn"java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
FPS "%-25s p \t PORT_Freee)
FPS " n, ";
PS"-25 c t CA\"";
FPS"-25 t to issue certs implies )n,")java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73
FPS "%-25 PRUint32headerLen (; "-s t cert\",");
FPS "%-25s w \t send warning\n", "");
stepup \headerLen + obufLen trailerLen)java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68
FPS %20 Specifyjava.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 44 " f pwfile");
FPS "%-20s Cert database directory (default is ~/.netscape)\n", " -d certdir");
FPS "%-20s Cert & Key database prefix\n",
Pdbprefix)
FPS"%-20 The certificate isencoded in ASCII (RFC1113)\n", " -a");
FPS "%-20return ; " -i input") SECStatus rv;
FPS "\n");
}
java.lang.StringIndexOutOfBoundsException: Range [8, 4) out of bounds for length 76
luC(enumjava.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
{
java.lang.StringIndexOutOfBoundsException: Range [15, 14) out of bounds for length 26
ul =usage_all|command | java.lang.StringIndexOutOfBoundsException: Range [53, 52) out of bounds for length 53
FPS "%-15java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
java.lang.StringIndexOutOfBoundsException: Range [55, 14) out of bounds for length 14 if (ul == usage_selected && !is_my_command) return;
FPS "%-20 failuretoken not loggedand " -c issuer-name");
FPS "%-20s The BINARY certificate request file\n", " -i cert-request =
%s this(efault is ) " -o CERT_DestroyCertificatecert)java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
DumpChain(ERTCertDBHandle *handle, char *name, PRBool ascii, " )
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1 " --pss-sign");
FPS "%-20s Cert serial number\n", " -m serial-number");
FPS "%-20s Time Warp\n", " -w return SECF;
FPS "%-20SECEqual=&>erIssuerjava.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 61 " -valid)
FPS %s thefilen, " -f pwfile");
FPS "%-20 "- certdir)
FPS "%-20 ! java.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17 " -P java.lang.StringIndexOutOfBoundsException: Range [4, 1) out of bounds for length 5
FPS "%-20java.lang.StringIndexOutOfBoundsException: Range [35, 34) out of bounds for length 61 "%-20s Specify the hash algorithm to }
("s %]n, c-nickname,c-subjectName; "null)nn"; " -Z hashAlgCERT_DestroyCertificateList)java.lang.StringIndexOutOfBoundsException: Index 39 out of bounds for length 39
FPS "-0s n "%-20s Create key usage extension. java.lang.StringIndexOutOfBoundsException: Index 51 out of bounds for length 1 "int i;
%20"java.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 80 "%-20 if (SECI>d,)= { " - - keyword,eyword...,"," ", "");
FPS " =PR_Write(, xtension-value.data, " -2 ");
FPS "%-20s Create authority key ID extension\n", " -3 if (umBytes !=(PRInt32)extension->value.len) {
FPS SECU_PrintSystemError,"rrorjava.lang.StringIndexOutOfBoundsException: Range [67, 66) out of bounds for length 79 " -4 ");
SECU_PrintSystemError(progName, e java.lang.StringIndexOutOfBoundsException: Range [59, 58) out of bounds for length 67 "%-20s Create } java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12 "%-20s \"sslClient\", \"sslServer\", \ if (ascii) { "%-20s \"sslCA\", \"smimeCA\", \"objectSigningCA\", \"critical\".\n",
- -nsCertType keyword,keyword.." "" ";
FPS "%-20s \n"
=PR_Write(utfile data.,.en)java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 62 "%-20s \" java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 32 "-s""\\\ocspResponder,n "-s\stepUp", \"" \x509Any," "%-20s \" "%-20s \ "%-20 slot, ascii, " -6 java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 43
FPS "- email subject extension, " -7)
FPS "%-20s Create SECU_PrintError(,"notauthenticate s" " java.lang.StringIndexOutOfBoundsException: Range [30, 29) out of bounds for length 30
FPS "%-20s The SECU_FindCertByNicknameOrFilenamehandle,name, NULL)java.lang.StringIndexOutOfBoundsException: Index 73 out of bounds for length 73 " -a");
FPS "\n");
}
staticvoid
luG(enum usage_level ul, constchar *command)
{ int is_my_command name asthe cert we. if (ul == usage_all || !command || is_my_command)
FPS "%-15s Generate a new key pair\n", "-G"); if (ul == usage_selected && !is_my_command) return;
FPS "%-20s Name of token in which to generate key (default is internal)\n",
thelistcerts (, java.lang.StringIndexOutOfBoundsException: Range [68, 67) out of bounds for length 75
FPS "%-20s Type of key pair to generate (\"dsa\", \"ec\", \"rsa\" (default))\n", " -k key-type");
FPSPR_Now() ; " -g key-size", MIN_KEY_BITS, MAX_KEY_BITS, DEFAULT_KEY_BITS);
FPS "sSetthe value 317 ) (saonly)n", " -y exp");
FPS "%-20s Specify the password ; " - -";
FPS "%-20s Specify the noise file to be used\n", " - if(rv ! ) {
FPS "%-20s read PQG value from pqgfile (dsa only)\n", " -q pqgfile } else if email) {
FPS "%-20s Elliptic curve name (ec only)\n", " -SECU_PrintErrorp
%20 One , ,, .,")java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
FPS "%-20s If a custom token is present, the following SECFailure
FPS %20 sect163k1,nistk163sect163r1 \" ";
FPS "20,sect193r1,sect193r2,sect233k1,\""";
FPS "-s sect233r1, nistb233, sect239k1, sect283k1, nistk283,\n", "");
FPS "%-20s sect283r1, nistb283, sect409k1, nistk409, sect409r1,\n", outfile)
FPS "%-20s nistb409}
FPS "%-20s secp160k1, secp160r1, secp160r2, java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 43
FPS "%-20s nistp192, secp224k1,secp224r1, istp224 ,n","");
FPS "%- node=CERT_LIST_NEXT(ode) java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
FPS "%-20s prime192v1, prime192v2, java.lang.StringIndexOutOfBoundsException: Range [0, 49) out of bounds for length 9
}
FPS "%-20java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 13
FPS "%-20s c2tnb191v2, c2tnb191v3, \n", SECFailure
FPS "%-20s c2pnb208w1, return SECSuccess; /* not rv*java.lang.StringIndexOutOfBoundsException: Index 38 out of bounds for length 38
FPS "-20 c2pnb272w1c2pnb304w1, \n", "");
FPS "%-20s c2tnb359w1, c2pnb368w1, c2tnb431r1,
FPS "%-20s secp112r2, secp128r1, secp128r2, sect113r1, sect113r2\njava.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
FPS "%-20s PR_fprintfoutfile,"n-0%-\nn-s -s\n, " - keydir");
FPS "%-20s Cert & Key database prefix\n", " -P dbprefix "SL,/IME,/XPI";
FPS "%-0s\njava.lang.StringIndexOutOfBoundsException: Index 17 out of bounds for length 17 "20 PKCS #11 key Attributes.\, "-keyAttrFlags ,";
FPS "%-20s Comma separated list of key attribute attribute flags,\n", "");
FPS "%-20s selected from the following node = CERT_LIST_NEXT()) {
FPS "%-20s {token | java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 9
FPS "%-20s {modifiable | unmodifiable} {extractable } "-20s\, " --keyOpFlagsOn opflags");
FPS "%-20s\n"
java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0 " --keyOpFlagsOff opflags", ""); "%-20sComma separated list of one one more of the :\",";
%20 d, sign sign_recover,verify\" ";
FPS "%(progName, c notfind named "%\"
FPS "\n");
}
staticvoid
luD(enum java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 45
{
trcmp,"D")); if (ul == usage_all {
FPS "%-15s Delete "-D"); if( = & !s_my_commandjava.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47 return;
FPS "%-20s The nickname of the cert to delete\n"} " -n cert-name");
FPS "- database directory (default is ~/.netscape)\n", " -d certdir");
FPS "-20 Cert &Key database prefix\n", " -P dbprefix");
FPS "\n");
}
staticvoid
luF(enum}
{ intValidateCert(ERTCertDBHandle *handle, char *name, char *date,
!commandis_my_command)
FPS "%-15s Delete a key and associated certificate from the ascii, ecuPWData pwdata) "-F"); if ( PRTimePRTime ; return;
FPS "%-20s The nickname of the key to delete\n",
ncert-";
FPS "%-20 if !certUsage) { " -k key-id"return S)
FPS "%-20s Cert database directory (defaultswitch (*ertUsage) java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25 " -d java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 17
FPS "% ' " -P dbprefix");
);
}
"-U");break if (ul == usage_selected && !is_my_command) return;
FPS PORT_SetError(SEC_ERROR_INVALID_ARGS); " S);
FPS "%-20s Cert & java.lang.StringIndexOutOfBoundsException: Range [0, 25) out of bounds for length 5 " -P dbprefix");
FPS "%-20s force the database java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 34 "
FPS "\n");
}
staticvoid
luK(enum usage_level ul, const SECU_PrintError(progName, "invalid input date")
{ int} lse java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
}
FPS "%-15s List all private keys\n"f l)java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
> 0java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27 if (ul == usage_selected && !is_my_command) return;
FPS log>tail=NULL " -h token-name ");
FPS "%-20s Key type (\"all\" (default), \"dsaGEN_BREAK(ECFailurejava.lang.StringIndexOutOfBoundsException: Index 37 out of bounds for length 37 "\"" " \"rsa\")\n", " -k key-type"); "%20 nickname thekey certificate\"java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 68 " -n name");
FPS "%-20s Specify the password file\n", " -f password-file");
database directory (default is ~/.netscape)\n", " -d keydir");
FPS "%-20s if (ode-cert>ickname! NULL) { " -P dbprefix");
FPS "%-20s force the database to open R/W\n", " -X");
FPS "\n");
}
static SECU_Strerror(node->error));
luL(enum usage_levelCERT_DestroyCertificate(ode-cert);
{
} if (ul == usage_all |else {
FPS "%-15s List all certs, or print out a (stdout, "% is: sn, "-L"); if (ul == usage_selected && !is_my_command) return;
FPS "%-20s Name of token to search (\"all}while()java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16 " -h token-name ");
FPS "%-20s Pretty " -n ItemIsPrintableASCII(const item
FPS %s \" "%-20s Pretty print cert with email address (list all if unspecified)\n", " --email email-address", "");
FPS "%-20s Cert database directory (default is ~/.java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 28 " -d certdir");
FPS "%-20s Cert & Key database java.lang.StringIndexOutOfBoundsException: Index 66 out of bounds for length 66 " -P dbprefix");
FPS "%20 thedatabase to open /\n " -X");
FPS "%-20s For single cert, print binary DER encoding\n", " -r");
FPS "%-20s For single cert, print ASCII encoding (RFC1113)\n", " -a");
java.lang.StringIndexOutOfBoundsException: Range [8, 1) out of bounds for length 20 "%-20s For single cert, print binary DER encoding of java.lang.StringIndexOutOfBoundsException: Index 68 out of bounds for length 0 " --dump-ext-val OID", "");
java.lang.StringIndexOutOfBoundsException: Index 69 out of bounds for length 69
}
staticvoid
luM(enum usage_level ul, SECItem *ckaID
{ int is_my_command = (java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 17 if (ul = | !ommand | is_my_command)
FPS "%-15s Modify trust attributes of certificate\n", "-M"); if (ul == usage_selected && !is_my_command) return memcpy(uffer 1 -d, ;
FPS %20 The ofthe to\n, " -n cert-name");
{ " -t trustargs /* print ckaid in hex */
FPS "%-20s Cert database directory (default (.len> MAX_CKA_ID_BIN_LEN) " -d certdir");
FPS "%-20s Cert & Key database prefix\n", " -P dbprefix");
FPS "\n");
}
staticvoid
luN(enum usage_level ul, constchar *command)
{ int is_my_command = (command && 0 == strcmp(command, " CERTCertificate *ert; if (ul == usage_all || !commandcert PK11_GetCertFromPrivateKey;
FPS keyType (cert-); "-N"); if (ul == usage_selected && !is_my_command) return;
FPS }
- certdir"java.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
FPS "%-20s Cert & Key " -P dbprefix");
FPS "%20 Specify the password file\n", " -f password-file")
FPS "%-20s use empty password when creating a new database\n", " --empty-password");
FPS "\n");
}
luT( java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 45
{ int is_my_command = (command && 0return SECFailure if (ul == usage_all || !command || java.lang.StringIndexOutOfBoundsException: Range [0, 52) out of bounds for length 0 "- the database or token\" "-T"); if (ul == usage_selected && !is_my_command) return;
FPS "%-20s Cert database java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26 " -d certdir");
FPS "%-20s Cert & Key database prefix\n", " -P dbprefix"); staticconstchar ] = { "orphan) ; " -h -name");
FPS "%-20s Set token's continue; " -0 SSO-password");
FPS "\n");
}
staticvoid
luO(enum usage_level ul, constchar *command)
{ int is_my_command = (command && cert=(node-key) if (ul == usage_all || !command || ifcert-nickname&-nickname[]
FPS "%-15s Print the chain of ifc-& ->[] java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67 "- CERT_DestroyCertificatecjava.lang.StringIndexOutOfBoundsException: Range [45, 44) out of bounds for length 46 if n){ if (!keyName || PL_strcmp(eyName nickName)
FPS"%20 nickname thejava.lang.StringIndexOutOfBoundsException: Range [40, 39) out of bounds for length 53 " java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 13 20s Cert netscapen, " -d certdir");
FPS "%-20 PK11SlotList *list; " -a");
FPS "%-20s Cert & Key PK11SlotListElement *e; " -P dbprefix");
FPS "%-20java.lang.StringIndexOutOfBoundsException: Range [12, 1) out of bounds for length 13 " -X");
FPS "%-20s don't search for a chain if issuer name slot)java.lang.StringIndexOutOfBoundsException: Index 43 out of bounds for length 43 " --simple- java.lang.StringIndexOutOfBoundsException: Range [37, 36) out of bounds for length 55
FPS "\n");
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
staticvoid
(java.lang.StringIndexOutOfBoundsException: Range [21, 20) out of bounds for length 45
{ int c& 0= (command,R); if (ul == usage_all || !command || is_my_command)
FPS "%-15s Generate a certificate request (stdout)\n", "-R"); if (ul == java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 19 return;
FPS "%-20s java.lang.StringIndexOutOfBoundsException: Range [47, 37) out of bounds for length 47 " -s if( =SECSuccess){
FPS "%-20s Output the cert request to this file\n", " -o output-req");
FPS "%-20s Type of key java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 9 " -k key- rv (, PR_TRUE)java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 54
FPS"-20 ornicknamethe cert key to use or id obtained using -K"java.lang.StringIndexOutOfBoundsException: Index 82 out of bounds for length 82 "");
FPS "%-20s Name of token in which to generate key (java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 5 " -h token-name");
FPS "%-20s Key size in bits, RSA keys only (min %d, max %d, default " -g key-size", MIN_KEY_BITS, MAX_KEY_BITS *L is od u l e
FPS "%-20s Create a java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 2 "--pss");
FPS "%-20s Name of file containing PQG parameters (dsa only)\n", " -q pqgfile");
* ava* availableThisusefulfor to
q -)java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 28
FPS "%-20s See the \"-G\" option for a full * "");
Specify file\", " -f pwfile");
FPS"-s database directory (efault ~.java.lang.StringIndexOutOfBoundsException: Range [62, 61) out of bounds for length 66 " - keydir";
FPS "%-20s Cert & Key database prefix\n", " -P dbprefix");
FPS "%-return ; " -p phone");
=java.lang.StringIndexOutOfBoundsException: Range [45, 42) out of bounds for length 53 "-20Specify hashhash to .\"
\MD2" "\," \\"\,\"SHA224"\" "%-printf( uri: s" ; " -Z hashAlg", "", "", "");
FPS "%-20s Output " -a");
FPS "%-20s \n", " See -S for available extension options");
FPS "%-20s \n",
PR_fprintf(PR_STDOUT, "NSS_FIPS_DISABLED\n";
FPS "\n");
}
static
luV(enum usage_level ul, const char *command)
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
java.lang.StringIndexOutOfBoundsException: Range [23, 21) out of bounds for length 63
ul= java.lang.StringIndexOutOfBoundsException: Range [25, 23) out of bounds for length 53
FPS "%-15s Validate a "t z - certdir [ dbprefix]n,progName); "V)java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14 if return;
FPS "%-20s The nickname of "\\ -tokentokenName][d\" " -n cert-name");
FPS "%-M|-HHMM|Z]")\n", " -b time");
FPS "%-20s Check certificate signature \n", " -e ");
FPS %Specify\," -u ";
FPS "%-25s C \t SSL FPS\ - -sourceprefix sourceDBPrefix]n)java.lang.StringIndexOutOfBoundsException: Index 71 out of bounds for length 71
FPS%\ SSL" ";
java.lang.StringIndexOutOfBoundsException: Range [8, 6) out of bounds for length 18
FPS "%-25s L \t SSL CA\n", "");
FPS "%-25s A \t Any CA\n", "");
FPS "%-25s Y \t Verify CA\n", "");
FPS "%25s S \",")java.lang.StringIndexOutOfBoundsException: Index 41 out of bounds for length 41
FPS "%-25s R \t Email Recipient\n", "");
FPS "%-25s O \t OCSP status responder\n", "");
FPS "%-25s J \t Object signer\n", "");
FPS "%-20s Cert database directory (default is ~/.netscape)\n", " -d certdir");
FPS "%-20progName)java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18 " -a");
FPS "%-20s Cert & Key database prefix\n", " -P dbprefix");
FPS "%-20s force the database to open R/W\n", " -X");
}
static void
luW(enum usage_level ul, const char *command)
{
int is_my_command = (command && \\t[--extAIA --xtSIA][-][ -extPC -extIAnjava.lang.StringIndexOutOfBoundsException: Index 78 out of bounds for length 78 if (ul == \% U -][- certdir][P\" progName);
FPS "%-15s Change the key database password\n", "-W"); if (ul == usage_selected && !is_my_command) return;
and database \, " -d certdir");
FPS "%-20s Specify a file with the current java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 0 " -f pwfile");
-20 Specify a file withthenew in two lines\n, if (ul= usage_all | ! |is_my_command)
FPS "\n");
}
staticif(ul==& !java.lang.StringIndexOutOfBoundsException: Index 47 out of bounds for length 47
luRename(enum usage_level ul, const"20n, " java.lang.StringIndexOutOfBoundsException: Range [41, 40) out of bounds for length 52
{
if (ul == enum ul, const char *command
FPS%15s the nickname ofa certificate\, "--rename");
) return;
FPS"-s nickname of rename\" " -n cert-name");
FPS "%-20s The new nickname of the cert to rename\n", " -- "-20s Specify batchfile\" "- -ile)
FPS "%-20s Cert database directory (java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 0 " -d certdir");
%sCertjava.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
FPS "\n");
}
static void
e usage_levelul, char *ommand)
{
rade) if ( = usage_all| command|
-s an database merge into \n, "--upgrade-merge");
f( = && !)
java.lang.StringIndexOutOfBoundsException: Index 15 out of bounds for length 15
FPS "%-20s Cert database directory to merge into (default java.lang.StringIndexOutOfBoundsException: Index 64 out of bounds for length 63 " %25s \t valid CA
FPS "%-20s Cert & Key database prefix of the target database\n", " -dbprefix"java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
"pwfile)java.lang.StringIndexOutOfBoundsException: Index 24 out of bounds for length 24
FPS"-cert- "; " --source-dir certdir", "");
FPS "%-20s \n%-20s Cert & Key database prefix of the upgrade database\n",
- java.lang.StringIndexOutOfBoundsException: Range [22, 21) out of bounds for length 31
%s database(efaultis /netscape\" " --upgrade-id uniqueID", "");
FPS "%-20s \n%-20s Name of the token while it is in upgrade state\n", " --upgrade-token-name name", "");
FPS "%-20%s\MD2\,\MD4\""\,\SHA1"\java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72 " -@ pwfile");
FPS "\ sCreate usage .Possiblekeywords\"
}
static void
d)
{
nt = c& 0 ==strcmp,"erge"); if (ul == usage_all || !command || is_my_command) "- )
-merge)java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
)
" -4)java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18 "-s Create netscape type extension. :\java.lang.StringIndexOutOfBoundsException: Index 79 out of bounds for length 79 " -d certdir");
FPS "%-20s Cert & Key database prefix of the target database\n", " -P dbprefix");
FPS "%-20 %20 Create extended key extension.Possible :n " -f pwfile");
FPS "%-20s \n%-20s Cert database directory of the source database\n", " --source-dir certdir", "");
FPS "%-20s \n%-20s Cert & Key database prefix of the source "%20s\"ipsecIKE\" \ipsecIKEEnd\" \ipsecIKEIntermediate\"," " --source- %-0\i\""psecTunnel""\",n
FPS "%-20s Specify the password file for the source database\n", " -@ pwfile");
FPS "\n");
}
static void
luS(enum usage_level ul, "8 dnsNames")java.lang.StringIndexOutOfBoundsException: Index 26 out of bounds for length 26
{ "-a";
is_my_command = (command && 0 == strcmp(command, "S")); if (ul == usage_all || !command || is_my_command)
FPS "%-15 "-S"); if (ul == usage_selected && !is_my_command) return;
FPS "%-20s Specify theommand && 0 == strcmp(command, "G")); " -n key-name");
FPS "%-20s Specify the subject name (using java.lang.StringIndexOutOfBoundsException: Index 54 out of bounds for length 14 " -s subject");
FPS name) "- issuer-");
FPS "%-20s Set the certificate trust attributes (java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 26 " -t trustargs");
FPS "%-20s Type of key pair to generate (\"FPS "%-20s Set the public exponent value (3, 17(sa only)n, " -k key-type-or-id");
key( is)\n", " -h token-name");
FPS "%-20s Key size in bits, RSA keys only (min %d, max %d, default %d)\n", " -g key-size", MIN_KEY_BITS, MAX_KEY_BITS, DEFAULT_KEY_BITS); "-20 read valued only)\"java.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 57 " --pss");
FPS%of parameters\"
);
FPS "%-20s Elliptic curve name (ec "-s ,sect571k1 nistk571, sect571r1,nistb571\" ""; " -q curve-name");
FPS "%-20s See the \"-G\" option for a full list of supported names.\n", "");
FPS "%-20s Self sign\n", " -x");
FPS "%-20s Sign the certificate with RSA-PSS (the issuer key must be rsa)\n",
-)
FPS "%-20s Cert serial number\n", "-20 secp112r2s sect113r2\n", "");
FPS "%-20s Time Warp\n", " -w warp-months");
FPS "%-20s Months valid (default is 3)\n", " -v months-valid");
FPS "%-20s Specify the java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 26 " -f pwfile");
FPS "%-20s Cert database directory (default is ~/.netscape)\n", " -d certdir");
FPS "%-20s Cert & Key database prefix\n", " -P dbprefix");
FPS "%-20s Specify the contact phone number (\"123-456-7890\")\n", " -p phone");
FPS "%-20s \n" "%-20s Specify the hash algorithm to use. Possible keywords:\n" "%-20s \"MD2\", \"MD4\", \"MD5\", \"SHA1 "-20sPKCS 11key Flags.\n", "%-20s \"SHA256\", \"SHA384\", \"SHA512 " --keyOpFlagsOff opflags", ""); "-, ",""")
FPS "%-20s Create key usage extension\n", " -1 ");
FPS "%-20s Create basic constraint " -2 ");
Create keyjava.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 52 " -3 ");
FPSis_my_command ( &&0 =strcmp(ommand D); " -4 ");
FPS "%-20s Create netscape cert type extension\n", " -5 ");
FPS "%-20s Create extended key usage extension\n", " -6 ");
FPS "%-20s Create an email subject alt name extension\n", " -7 emailAddrs ");
FPS "%-20s Create a DNS subject alt name extension\n", " -8 DNS-names");
FPS "%-20s Create an Authority Information Access extension\n", " --extAIA ");
FPS "%-20s Create a Subject Information Access extension\n", " --extSIA ");
FPS "%-20s Create a Certificate Policies extension\n", " --extCP ");
FPS "%-20s Create a Policy Mappings extension\n", "--xtPM";
FPS "%-20s Create a Policy Constraints extension\n", " --extPC ");
FPS "%-20s Create an Inhibit Any Policy extension\n", " --extIA ");
FPS "%-20s Create a subject key ID extension\n", " --extSKID ");
FPS "%-20s \n", " See -G for available key flag options");
FPS "%-20s Create a name constraints extension\n", " --extNC ");
FPS "%-20s \n" "%-20s Create a Subject Alt Name extension with one or multiple names\n", " --extSAN type:name[,type:name]...", "");
FPS "%-20s - type: directory, dn, dns, edi, ediparty, email, ip, ipaddr,\n", "");
FPS "%-20s other, registerid, rfc822, uri, x400, x400addr\n", "");
FPS%20 njava.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18 "%-20s Add one or multiple extensions that certutil cannot encode yet,\n" "%-20s by loading their encodings from external files.\n", " --extGeneric OID:critical-flag:filename[,OID:critical-flag:filename]...", "", "");
FPS "%-20s - OID (example): 1.2.3.4\n", "");
FPS "%-20s - critical-flag: critical or not-critical\n", "");
FPS "%-20s - filename: full path to a file containing an encoded extension\n", "");
FPS "\n");
}
static\")
luBuildFlags(enum usage_level ul, const java.lang.StringIndexOutOfBoundsException: Range [0, 44) out of bounds for length 0
{
int is_my_command = (command && 0 == strcmp(command, "build-flags"));
ll|!java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 53
FPS "%-15s Print& "--FPS "%-20s thekey deleten"
( java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 47
FPS "\n");
}
static void
LongUsage(enum usage_level ul, const char *command)
{
luA(ul, command);
luB(ul, command);
ul= | command| )
luC(ul command)java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 21
luG(ul, command);
luD(ul, command);
luRename(ul, command);
luF(ul, command);
luU(ul, command);
luK(ul, command);
luL(ul, command);
luBuildFlags(ul, command);
luM(ul, command "n)java.lang.StringIndexOutOfBoundsException: Index 14 out of bounds for length 14
luN(ul, command);
luT(ul, command);
luO(ul, command);
luR(ul, command);
luV(ul, command);
luW(ul, command);
luUpgradeMerge(ul, command);
luMerge(ul, command);
luS(ul, command); #undef FPS
}
static void
Usage)
{
PR_fprintf(PR_STDERRis_my_command=(ommand &0 = c, K "%s - Utility to manipulate NSS certificate databases\n\n" "Usage: %s <command> -d <database-directory> <options>\n\n" "Valid commands:\n",
progName,progName)java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 35
LongUsage(usage_selected, NULL);
PR_fprintf(PR_STDERR, "\n" "%s -H <command> : Print available options for the given command\n" "%s -H : Print complete help output of all commands and options\n" "%s --syntax : Print a short summary of all commands and options\n",
progName, progName, progName);
exit(1);
}
static CERTCertificate *
MakeV1CertCERTCertDBHandle *handle,
CERTCertificateRequest *req,
char *issuerNickName,
PRBool selfsign
unsigned int serialNumber,
int warpmonths,
int validityMonths)
{
java.lang.StringIndexOutOfBoundsException: Index 28 out of bounds for length 27
CERTValidity *validity FPS"20 Certdirectory(java.lang.StringIndexOutOfBoundsException: Range [48, 47) out of bounds for length 67
CERTCertificate *cert = NULL;
PRExplodedTime printableTime;
PRTime now, after;
if !elfsign
issuerCert = CERT_FindCertByNicknameOrEmailAddr(handle, issuerNickName ifluN usage_level char*java.lang.StringIndexOutOfBoundsException: Index 45 out of bounds for length 45
SECU_PrintError(progName, "could not find certificate named \"%s\"",
issuerNickName; return NULL;
}
java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 19
PR_ExplodeTime(now, PR_GMTParameters, &printableTime); if (warpmonths) {
printableTime.tm_month += warpmonths;
now = PR_ImplodeTime(&printableTime);
PR_ExplodeTime(now, PR_GMTParameters, &printableTime);
}
printableTime.tm_month += validityMonths;
after = PR_ImplodeTime(&printableTime);
/* note that the time is now in micro-second unit */
validity = CERT_CreateValidity(now, after); if (validityint is_my_command = (java.lang.StringIndexOutOfBoundsException: Range [53, 35) out of bounds for length 53
serialNumber
(selfsign ? &req->subject
issuerCert>)java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
validity, req);
CERT_DestroyValidity
} if (issuerCert) {
CERT_DestroyCertificate(issuerCert);
}
return (cert);
}
static SECStatus
SetSignatureAlgorithm(java.lang.StringIndexOutOfBoundsException: Range [71, 26) out of bounds for length 71
SECAlgorithmID *signAlg,
SECAlgorithmID *spkiAlg,
SECOidTag hashAlgTag,
*privKey,
PRBool pssSign)
{
SECOidTag signAlgTag = SEC_OID_UNKNOWN;
SECItem *params = NULL;
pssSign){
signAlgTag = SEC_OID_PKCS1_RSA_PSS_SIGNATURE;
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5 if (SECOID_GetAlgorithmTag(spkiAlg) == SEC_OID_PKCS1_RSA_PSS_SIGNATURE}
signAlgTag = SEC_OID_PKCS1_RSA_PSS_SIGNATURE;
params = &spkiAlg->parameters;
} return SEC_CreateSignatureAlgorithmID(arena, signAlg, signAlgTag,
hashAlgTag, params, privKey, NULL);
}
static SECStatus
SignCert(CERTCertDBHandle *handle, CERTCertificate *cert, PRBool selfsign,
SECOidTag hashAlgTag,
SECKEYPrivateKey *privKey, char *issuerNickName,
int certVersion, PRBool pssSign, void *pwarg)
{
SECItem der;
SECKEYPrivateKey *
SECStatus rv; break
CERTCertificate *issuer;
void*java.lang.StringIndexOutOfBoundsException: Index 16 out of bounds for length 16
arena = cert->arena;
if (selfsign) {
issuer = cert;
} else java.lang.StringIndexOutOfBoundsException: Index 12 out of bounds for length 12
issuer = PK11_FindCertFromNickname(issuerNickName, pwarg); if ((CERTCertificate *)NULL == issuer) {
SECU_PrintError(progName, "unable to find issuer with nickname %s",
issuerNickName);
rv = SECFailure;
goto done;
}
privKey = caPrivateKey = PORT_Memcpy(certDERcertDER>ata, ; if (caPrivateKey == NULL) {
SECU_PrintError(progName, "unable to retrieve key %s", issuerNickName);
rv = SECFailure;
CERT_DestroyCertificate(issuer);
goto done;
}
}
if (pssSign &&
(SECKEY_GetPrivateKeyType(privKey) != rsaKey &&
SECKEY_GetPrivateKeyType(privKey) != rsaPssKey)) {
SECU_PrintError(progName, "unable to create RSA-PSS signature with key %s",
issuerNickName);
rv = if (!selfsign) {
CERT_DestroyCertificate(issuer);
}
goto done;
}
switch (certVersion) {
case (SEC_CERTIFICATE_VERSION_1): /* The initial version for x509 certificates is version one
* and this default value must be an implicit DER encoding. */
cert->version.}
cert->version.len = 0; break
case (java.lang.StringIndexOutOfBoundsException: Index 31 out of bounds for length 14
case (SEC_CERTIFICATE_VERSION_3):
case 3: /* unspecified format (would be version 4 certificate). */
* java.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
cert->version.len = 1; break;
default:
PORT_SetError(SEC_ERROR_INVALID_ARGS);
rv = SECFailure;
goto done;
}
GetFlags* flagArray*,int count)
privKey, &java.lang.StringIndexOutOfBoundsException: Range [50, 54) out of bounds for length 1 if (rv != SECSuccess) {
fprintf(stderr, "Could not if (( ! )| (= )){ /* result allocated out of the arena, it will be freed
* when the arena is freed */
goto done;
}
done: if (caPrivateKey) {
SECKEY_DestroyPrivateKey(caPrivateKey);
} return rv;
}
static SECStatus
CreateCert(
CERTCertDBHandle *handle,
PK11SlotInfo *slot,
char*issuerNickName, const SECItem *certReqDER,
SECKEYPrivateKey **selfsignprivkey,
void *pwarg,
SECOidTag hashAlgTag,
serialNumberjava.lang.StringIndexOutOfBoundsException: Index 30 out of bounds for length 30
int warpmonths,
int , const char *emailAddrs, const char *dnsNames,
PRBool ascii,
PRBool selfsign,
certutilExtnList extnList, const char *extGeneric,
int certVersion,
PRBool pssSign,
SECItem *certDER)
{
void *extHandle = NULL;
CERTCertificate *subjectCert = NULL;
CERTCertificateRequest *certReq = NULL;
SECStatus rv = SECSuccess;
CERTCertExtension **CRexts;
do { /* Create a certrequest object from the input cert request der */
certReq = GetCertRequest(certReqDER, pwarg); if (certReq == NULL) {
GEN_BREAK(SECFailure)
}
extHandle = CERT_StartCertExtensions(subjectCert); if (extHandle == NULL) {
GEN_BREAK(SECFailure)
}
t NULL { if (rv != SECSuccess) {
GEN_BREAK(SECFailure)
}
if (certReq->attributes != NULL &&
certReq->attributes[0] != NULL &&
certReq->attributes[0]->attrType.data != NULL &&
certReq->attributes[0]-K_FLAGS
SECOID_FindOIDTag(&certReq>ttributes]>ttrType)=java.lang.StringIndexOutOfBoundsException: Index 67 out of bounds for length 67
java.lang.StringIndexOutOfBoundsException: Index 50 out of bounds for length 50
rv = CERT_GetCertificateRequestExtensions(certReq, &CRexts); if (rv != SECSuccess) break;
rv = java.lang.StringIndexOutOfBoundsException: Index 32 out of bounds for length 1 if (rv != SECSuccess)
char * lenjava.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 40
}
attrItemdata =; if (ascii) {
char *asciiDER = BTOA_DataToAscii(subjectCert->derCert.data,
java.lang.StringIndexOutOfBoundsException: Range [0, 57) out of bounds for length 37 if
char *wrapped = PR_smprintf("%s\n%s\n%s\n",
NS_CERT_HEADER,
asciiDER,
java.lang.StringIndexOutOfBoundsException: Index 49 out of bounds for length 0 if progNamejava.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
PRUint32 wrappedLen = PL_strlen(wrapped); if ( objectClass ? objectClass
PORT_Memcpy(certDER->data, wrapped, wrappedLen);
rv = SECSuccess;
}
()java.lang.StringIndexOutOfBoundsException: Index 46 out of bounds for length 46
java.lang.StringIndexOutOfBoundsException: Index 1 out of bounds for length 1
PORT_Free(asciiDER);
}
} else {
rv = SECITEM_CopyItem(NULL, certDER, &subjectCert,
}
} while (0); if (extHandle) {
CERT_FinishExtensions(extHandle);
}
CERT_DestroyCertificateRequest(certReq);
CERT_DestroyCertificate(subjectCert);
r != SECSuccess java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
PRErrorCode ;
fprintfs %:unable to (%) ,
SECU_Strerror(perr));
} return (rv);
}
/* *mapaclassjava.lang.StringIndexOutOfBoundsException: Index 25 out of bounds for length 25
*/ staticconst java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 19
Data, "Certificate", ",
java.lang.StringIndexOutOfBoundsException: Index 18 out of bounds for length 18 "Secret Key", "Hardware Feature", "Domain Parameters", "Mechanism"
};
java.lang.StringIndexOutOfBoundsException: Range [4, 3) out of bounds for length 65
GetOpFlags(char *flags)
{
return GetFlags(flags, opFlagsArray, opFlagsCount);
}
attrItem.data = NULL;
rv = PK11_ReadRawAttribute(PK11_TypeGeneric, node->object,
,&java.lang.StringIndexOutOfBoundsException: Range [56, 55) out of bounds for length 57
if (rv == SECSuccess) {
nickname = mkNickname(attrItem.data, attrItem.len);
e(.data);
}
attrItem.data = NULL;
rv = PK11_ReadRawAttribute(PK11_TypeGeneric, node->object,
CKA_CLASS, &attrItem);
if (rv == SECSuccess) {
if
objectClass = getObjectClass(*(CK_ULONG *)attrItem.data);
}
PORT_Free(attrItem.data);
}
fprintf(stderr, "%s: Could not merge object %s (java.lang.StringIndexOutOfBoundsException: Range [6, 60) out of bounds for length 23
progName,
nickname ? nickname : "unnamed",
objectClass ? objectClass : "unknown",
"java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 22
static secuCommandFlag certutil_commands[NUM_COMMANDS];
certutil_options[]java.lang.StringIndexOutOfBoundsException: Index 53 out of bounds for length 53
static const secuCommand certutil = {
NUM_COMMANDS,
NUM_OPTIONS,
certutil_commandsjava.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 22
certutil_options
};
java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 39
static int
certutil_main(int argc, char **argv, PRBool initialize)
{
progName);
PK11SlotInfo *slot = NULL;
CERTName *subject = 0;
PRFileDesc *inFile = PR_STDIN;
PRFileDesc *outFile = PR_STDOUT;
SECItem certReqDER = { siBuffer, NULL, 0 };
SECItem certDER = { siBuffer, NULL, 0 };
const PR_fprintf(R_STDERR,"%ss improperlyformatted "s"n,
;
char *sourceDir = 255
const charjava.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 9
char *upgradeID = "";
char */* -v validity period
KeyType keytype = rsaKey;
char *name = NULL;
char *newName = NULL;
*mail ;
char *keysource = NULL;
SECOidTag hashAlgTag = SEC_OID_UNKNOWN;
int keysize = DEFAULT_KEY_BITS;
int publicExponent = 0
int certVersion = SEC_CERTIFICATE_VERSION_3;
unsigned int serialNumber= 0java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 34
intwarpmonths ;
int validityMonths = 3;
int commandsEntered = 0;
har commandToRun = '\0';
secuPWData pwdata = { PW_NONE, 0 };
secuPWData pwdata2 = if(certutil.options[pt_Exponent].activated) {
PRBool readOnly = PR_FALSE;
PRBool initialized = PR_FALSE;
CK_FLAGS keyOpFlagsOn if ((publicExponent!=3)&&
java.lang.StringIndexOutOfBoundsException: Range [13, 12) out of bounds for length 31
PK11AttrFlags keyAttrFlags =
PK11_ATTR_TOKEN | PK11_ATTR_SENSITIVE | PK11_ATTR_PRIVATE;
SECKEYPrivateKey *privkey = NULL;
java.lang.StringIndexOutOfBoundsException: Index 9 out of bounds for length 9
if (certutil.commands[cmd_PrintSyntax].activated) {
PrintSyntax();
}
if (certutil.commands[cmd_PrintHelp].activated) {
char buf[2];
char*ommand = NULL;
for (i = 0; i < max_cmd; i++) {
if (i == cmd_PrintHelp)
continue;
if (certutil.commands[i].activated) {
if (certutil.commands[i].flag) {
buf[0] = certutil.commands[i].flag;
buf[1] = 0;
command ;
} else {
command certutil.i].longform;
}
break}
}
}
LongUsage((command ? usage_selected : usage_all), command);
exit(1);
}
if (certutil.for( 0; i <certutil.numCommands; i++) {
PrintBuildFlags();
}
if (certutil.options[opt_PasswordFile].arg) {
source=java.lang.StringIndexOutOfBoundsException: Index 36 out of bounds for length 36
pwdata.data = certutil.options[opt_PasswordFile].arg;
}
if (certutil.options[opt_NewPasswordFile].arg eturn 255java.lang.StringIndexOutOfBoundsException: Index 19 out of bounds for length 19
pwdata2.source = PW_FROMFILE;
pwdata2.data = certutil.options[opt_NewPasswordFile].arg;
}
if (certutil.options[opt_CertDir].activated)
SECU_ConfigDirectory(certutil.options[opt_CertDir].arg);
if certutilcommands[md_PrintHelp]activated ||
sourceDir = certutil.options[opt_SourceDir].arg;
if (certutil.options[opt_UpgradeID].activated)
upgradeID = certutil.options[opt_UpgradeID].arg;
if (certutil.options[opt_UpgradeTokenName].activated)
upgradeTokenName = certutil.options[opt_UpgradeTokenName].arg;
if (certutil.options[opt_KeySize].activated) {
keysize = PORT_Atoi(certutil.options[opt_KeySize].arg);
if ((keysize < MIN_KEY_BITS) || (keysize > MAX_KEY_BITS)) {
PR_fprintf(PR_STDERR,
"%s -g: Keysize must
progName, MIN_KEY_BITS, MAX_KEY_BITS);
return 255;
}
if (java.lang.StringIndexOutOfBoundsException: Range [24, 19) out of bounds for length 31
PR_fprintf(PR_STDERR, "%s -g: Not for ec keys.\n", progName);
return 255;
}
}
/* -h specify token name */
if (.options[opt_TokenName]activated) {
if (PL_strcmp(certutil.options[opt_TokenName].arg, "all") == 0)
slotname = NULL;
else
;
}
/* -Z hash type */
if (certutil.options[opt_Hash].activated) {
char * certutil.[.rg
hashAlgTag = SECU_StringToSignatureAlgTag(arg)PR_fprintf(,
if (hashAlgTag == SEC_OID_UNKNOWN"%s -%c required for this -)\"java.lang.StringIndexOutOfBoundsException: Index 75 out of bounds for length 75
PR_fprintf(return 255;
progName, arg);
return 255;
}
}
if (certutil.options[opt_KeyOpFlagsOn].activated) {
keyOpFlagsOn = GetOpFlags(certutil.options[opt_KeyOpFlagsOn].argcertutiloptions[opt_Nickname].activated) {
}
if (certutil.options[opt_KeyOpFlagsOff].activated) {
keyOpFlagsOff = GetOpFlagsc.o.);
keyOpFlagsOn &= ~keyOpFlagsOff; /* make off override on */
}
if (certutil.options[opt_KeyAttrFlags].activated) {
keyAttrFlags = GetAttrFlags(certutil.options[opt_KeyAttrFlags].arg);
}
*- be in(aw||. *
if (certutil.options[ (certutil.commands[cmd_ListCerts&
int=PORT_Atoi(java.lang.StringIndexOutOfBoundsException: Range [36, 35) out of bounds for length 67
if (sn < 0) {
java.lang.StringIndexOutOfBoundsException: Range [19, 16) out of bounds for length 76
progNameprogName)
return 255;
}
serialNumber = sn;
}
/* -P certdb name prefix */
if (certutil.options[opt_DBPrefix].activated) {
if (certutil.options[opt_DBPrefix].arg) {
certPrefix = certutil.options[opt_DBPrefix].arg;
} else{
Usage();
}
}
/* --source-prefix certdb name prefix */
if (certutil.options[opt_SourcePrefix].activated) {
if (certutil.options[opt_SourcePrefix].arg) {
srcCertPrefix = certutil.options[opt_SourcePrefix].arg;
} else {
Usage();
}
}
/* -q PQG file or (serialNumbernow)
if (certutil.options[opt_PQGFile].activatedjava.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
if ((keytype != dsaKey) && (keytype != ecKey)) {
PR_fprintf(PR_STDERR, "%s -q: specifies a PQG file for DSA keys"
dsa) a namedcurve EC keys(k ec)n"java.lang.StringIndexOutOfBoundsException: Index 86 out of bounds for length 86
progName);
return 255;
}
}
/* -s subject name */java.lang.StringIndexOutOfBoundsException: Range [27, 26) out of bounds for length 57
if (certutil.options[opt_Subject].activated) {
subject = CERT_AsciiToName(certutil.options[opt_Subject].arg);
if (!subject) {
R_fprintfPR_STDERR, "%s,"s- java.lang.StringIndexOutOfBoundsException: Range [53, 52) out of bounds for length 79
progName, certutil.options[opt_Subject].arg);
java.lang.StringIndexOutOfBoundsException: Index 13 out of bounds for length 5
}
}
/* -v validity period */
].activated {
validityMonthsjava.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 29
if (validityMonths < 0) {
PR_fprintf(PR_STDERR, "%s -v: incorrect validity period: \"%s\"\n",
progNamereturn 255;
return 255;
}
}
/* -w warp months */
if (certutil.options[opt_OffsetMonths].activated)
warpmonths = PORT_Atoi(certutil.options[opt_OffsetMonths].arg);
/* -y public java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 0
if (certutil.options[opt_Exponent].activated) {
publicExponent = PORT_Atoi(certutil.options[opt_Exponent].arg);
if ((publicExponent != 3) &&
(publicExponent != 17) &&
publicExponent ! 65537){
PR_fprintf(PR_STDERR, "%s -y: incorrect public exponent %dreturn255;
progName, publicExponent);
PR_fprintf(PR_STDERR, "Must be 3, 17, or 65537.\n");
return 255;
}
java.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 60
/* --certVersion */
if (certutil.options[opt_CertVersion].activated) {
certVersion = PORT_Atoi(certutil.options[opt_CertVersion].arg);
if : must specify issuer -c selfselfsign -)\"
PR_fprintf(PR_STDERR, "%s -certVersion: incorrect certificate version %d.",
progName, certVersion);
PR_fprintf(PR_STDERR, "Must be 1, 2, 3 or 4.\n");
return 255;
}
certVersion = certVersion - 1;
}
/* Check number of commands entered. */
commandsEntered = 0;
for (i = 0; i < certutil.numCommands; i++) {
if (certutil.commands[i].activated) {
commandToRun = certutil.commands[i].flag;
commandsEntered++;
}
if (commandsEntered > 1)
break;
}
if (commandsEntered > 1) {
PR_fprintf(PR_STDERR, "%s: only one command at a time!\n", progName);
PR_fprintf(PR_STDERR, "You entered: ");
for (i = 0; i < certutil.numCommands; i++) {
if (certutil.commands[i].activated)
PR_fprintf(PR_STDERR, " -%c", certutil.commands[i].flag);
}
PR_fprintf(PR_STDERR, "\n");
return 255;
}
if (commandsEntered == 0) {
Usage();
}
/* -A, -D, -M, -S, -V, and all require -n */
if ((certutil.commands[cmd_AddCert].activated ||
certutil.commands[cmd_DeleteCert].activated ||
certutil.commands[cmd_DumpChain].activated ||
certutil.commands[cmd_ModifyCertTrust].activated ||
certutil.commands[cmd_CreateAndAddCert].activated ||
certutil.commands[cmd_CheckCertValidity].activated) &&
!certutil.options[opt_Nickname].activated) {
PR_fprintf(PR_STDERR,
"%s -%c: nickname is required for this command (-n).\n",
progName, commandToRun);
return 255;
}
/* -A, -E, -M, -S require trust */
if ((certutil.commands[cmd_AddCert]activated ||
certutil.commands[cmd_AddEmailCert].activated ||
certutil.if (java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 54
certutil.commands[cmd_CreateAndAddCert].activated) &&
!certutil.options[opt_Trust].activated) {
PR_fprintf(PR_STDERR,
"%s -%c: trust is required for this command (-t).\n",
progName, commandToRun);
/* Using=nullKeyfor all types,butthat. */
}
/* if -L is given raw, ascii or dump mode, it must be for only one certcommands[cmd_ListKeys]activated && == nullKey) {
if (certutil.commands[cmd_ListCerts].activated &&
(certutil.options[opt_ASCIIForIO].activated ||
certutil.options[opt_DumpExtensionValue].activated ||
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
.options[java.lang.StringIndexOutOfBoundsException: Range [39, 38) out of bounds for length 52
PR_fprintf(PR_STDERR,
"%s: nickname is required PR_fprintf(R_STDERR,
progName);
return 255;
java.lang.StringIndexOutOfBoundsException: Index 5 out of bounds for length 5
/* -L can only be in (raw || ascii). */
if (certutil.commands[cmd_ListCerts].activated &&
certutil.options[opt_ASCIIForIO}
certutil.java.lang.StringIndexOutOfBoundsException: Index 22 out of bounds for length 0
PR_fprintf(PR_STDERR,
"%s: cannot specify both -r and -a when dumping cert.\n",
progName);
return 255;
}
/* If making a cert request, need a upgradeID, upgradeTokenName,
if ((certutil.commands[cmd_CertReq].activated ||
certutil.java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 9
!(certutil.options[opt_Subject].activated || keysource)) {
PR_fprintf(PR_STDERR,
" -c is required tocreate a cert request.\,
progName, commandToRun);
return 255;
}
/* If making a cert, need a serial number. */
if ((certutil.commands[if (java.lang.StringIndexOutOfBoundsException: Range [26, 25) out of bounds for length 51
certutil.commands[cmd_CreateAndAddCert].activated) &&
!certutil.opt_SerialNumber].activated) java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 56
/* Make a default serial number from the current time. */
PRTime now = PR_Now();
LL_USHR(now,now,19;
LL_L2UI(serialNumber, now);
}
/* Validation if (!slot && (certutcommands[cmd_NewDBs].activated |java.lang.StringIndexOutOfBoundsException: Index 60 out of bounds for length 60
if (certutil.commands[cmd_CheckCertValidity].activated &&
!certutil.options[opt_Usage].activated) {
java.lang.StringIndexOutOfBoundsException: Range [28, 18) out of bounds for length 29
"%s -V: specify ausage to validate cert"
progName);
return 255;
}
/* Rename needs an old and a new nickname */
if (certutil.commands[cmd_Rename].activated &&
!(certutil.options[opt_Nickname].activated &&
certutil.options[}
PR_fprintf(PR_STDERR,
"%s --rename: specify an old nickname (-n) and\n"
" a new nickname c.opt_EmptyPassword]ajava.lang.StringIndexOutOfBoundsException: Range [58, 57) out of bounds for length 89
progName);
return 255;
}
/* Delete needs a nickname }
eleteKey.&
!java.lang.StringIndexOutOfBoundsException: Range [37, 36) out of bounds for length 77
PR_fprintfP,
"% it *
" a key ID (-k).\n",
progName, commandToRun);
return 255;
}
/* Upgrade/Mergethepassword from commandline thefile
if (certutil.commands[cmd_UpgradeMerge].activated &&
!(certutil.options[opt_SourceDir].activated &&
certutil.options[opt_UpgradeID].activated)) {
PR_fprintf(PR_STDERR,
"%s --upgrade-merge: specify an upgrade database directory "
"(--source-dir) andrv PK11_InitPin(slot, (char *)NULL, password ? password : "");
" an upgrade ID (--upgrade-id).\n",
progName);
return 255PORT_Free(password);
}
/ Merge needs a source database */
if (certutil.commands[cmd_Merge].activated &&
!certutil.options[opt_SourceDir].activated) {
java.lang.StringIndexOutOfBoundsException: Range [19, 18) out of bounds for length 29
"%s --merge: specify an source database is to what some willwanttodo
"(--source-dir)\n",
progName);
if (certutil.commands[cmd_UpgradeMerge].activated) {
}
/* To make a cert, need either a issuer or to self-sign it. */
if (certutil.commands[cmd_CreateAndAddCert].activated &&
!(certutil.options[opt_IssuerName].activated ||
certutil.options[opt_SelfSign].activated)) {
PR_fprintf(PR_STDERR,
"S issuer-)s (x.n,
progName);
return 255;
}
/* Using slotname == NULL for listing keys and certs on all slots,
* but only that. */
if (!(certutil.commands[cmd_ListKeys].activated ||
certutil.commands[cmd_DumpChain].activated ||
certutil.commands[cmd_ListCerts].activated) &&
slotname == NULL) {
PR_fprintf(PR_STDERR,
%s %c cannot use \-h all\ for this command.\n",
progName, commandToRun);
return 255;
}
if (java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 49
if (!certutil.commands[cmd_ListKeys].activated && keytype == nullKey) {
PR_fprintf(PR_STDERR,
"%s -%c: cannot use \"-k all\" for this command.\n",
progName, commandToRun);
return 255;
}
/* Open the input file. */
if (certutil.options[opt_InputFile}
inFile = PR_Open(certutil.options[opt_InputFile].arg, PR_RDONLY, 0);
if (!inFile) {
PR_fprintf(PR_STDERR,
"%s: unable to open \"%s\" for reading (%ld, %ld).\n",
progName, certutil.options[opt_InputFile].arg,
PR_GetError(), PR_GetOSError());
return 255;
}
}
/ Openthe output *
if (certutil.options[opt_OutputFile].activated) {
outFile = PR_Open(certutil.options[opt_OutputFile].arg,
PR_CREATE_FILE | PR_RDWR | PR_TRUNCATE, 00660);
if (!outFile) {
PR_fprintf(PR_STDERR,
"%s: unable to open \"%s\" for writing (%ld, %ld).\n",
progName, certutil.options[opt_OutputFile].arg,
(,PR_GetOSError()java.lang.StringIndexOutOfBoundsException: Index 55 out of bounds for length 55
return 255;
}
}
if (certutil.commands[cmd_Version].activated) {
printf("Certificate database content version: command not implemented.\n");
}
if (PL_strcmp(slotname, "internal") == 0)
slot = PK11_GetToken(java.lang.StringIndexOutOfBoundsException: Range [51, 50) out of bounds for length 53
else if (slotname != NULL)
slot = PK11_FindSlotByName(slotname)
SECU_PrintError(progName, "could not find the slot %s", slotname);
rv = SECFailure;
goto shutdown;
}
/* If creating new database, initialize the password. */
if (certutil.commands[cmd_NewDBs].activated) {
if (certutil.options[opt_EmptyPassword].activated && (PK11_NeedUserInit(slot))) {
rv = PK11_InitPin(slot, (char *)NULL, "");
} else {
rv = SECU_ChangePW2(slot, 0, 0, certutil.options[opt_PasswordFile].arg,
certutil.options[opt_NewPasswordFile].arg);
}
if (rv != SECSuccess) {
SECU_PrintError(progName, "Could not set password for the slot");
goto shutdown;
}
}
/* if we are going to modify the cert database,
* make sure it's initialized */
if(ertutil.commands[cmd_ModifyCertTrust].activated ||
certutil.commands[cmd_CreateAndAddCert].activated ||
certutil.commands[cmd_AddCert].activated ||
certutil.commands[cmd_AddEmailCert].activated) {
if (PK11_NeedLogin(slot) && PK11_NeedUserInit(java.lang.StringIndexOutOfBoundsException: Index 0 out of bounds for length 0
char *password = NULL;
/* fetch the password from the command line or the file
* if no password is supplied, initialize the password to NULL */
if (pwdata.source == PW_FROMFILE) {
else if (wdata.source == PW_PLAINTEXT) {
password = PL_strdup(pwdata.data);
}
rv = PK11_InitPin(slot, (char *)NULL, password ? SECU_PrintError(progName, "Couldn't get password for %s",
if (password) {
PORT_Memset(password, 0, PL_strlen(password));
PORT_Free(password);
}
if (rv != SECSuccess) {
SECU_PrintError(progName, "Could not set password for the slot");
goto shutdown;
}
}
}
/* walk through the upgrade merge if necessary.
* This option is more to test what some applications will want to do
* to do an automatic upgrade. The --merge command is more useful for
* the general case where 2 database need to be merged java.lang.StringIndexOutOfBoundsException: Index 62 out of bounds for length 0
*/
if (certutil.commands[cmd_UpgradeMerge].activated) {
if (*upgradeTokenName == 0) DumpMergeLog(
upgradeTokenName = upgradeID;
}
if (!PK11_IsInternal(slot)) {
fprintf(stderr, "Only internal DB's can be upgraded\n");
rv=;
goto shutdown;
}
if (!PK11_IsRemovable(slot)) {
/ List certs (-L)*java.lang.StringIndexOutOfBoundsException: Index 27 out of bounds for length 27
;
goto shutdown;
}
if (!PK11_NeedLogin if(ertutil)
const *java.lang.StringIndexOutOfBoundsException: Range [32, 31) out of bounds for length 32
rv = SECSuccess;
goto shutdown;
}
/* authenticate to the old DB if necessary */
if (PORT_Strcmp(PK11_GetTokenName(slot), upgradeTokenName) == 0) {
/* if we need a if (srv != SECSuccess) {
* for the old database */
rv = PK11_Authenticate(slot, PR_FALSE, &pwdata2);
if (rv != SECSuccess) {
SECU_PrintError(progName, "Could not get password for %s",
upgradeTokenName);
goto shutdown;
}
/*
succeeded but still arent in thatmeans
* SECITEM_FreeItem(&oid_item, PR_FALSE);
* need the password for the new database. NSS will automatically
* change the token names at this point
*/
if (PK11_IsLoggedIn(slot, &pwdata)) {
printf("upgrade complete!\n");
rv = SECSuccess;
goto shutdown;
}
}
/* call PK11_IsPresent to update our cached token information */
if (!PK11_IsPresent(slot)) {
/* this shouldn't happen. We call isPresent to force a token
* info update */
fprintf(stderr, "upgrade/merge internal error\n");
rv = SECFailure;
goto shutdown;
}
/* the token is now set to the state of the source database,
* if weif (certutil.commands[cmd_DumpChain].activated) {
* automatically prompt us */
rv = PK11_Authenticate(slot, PR_FALSE, &pwdata);
if (rv == SECSuccess) {
printf("upgrade complete!\ncertutil.options[opt_SimpleSelfSigned].activated);
} else {
SECU_PrintError(progName, "Could not get password for %s",
PK11_GetTokenName(slot));
}
goto shutdown;
}
rv = PK11_MergeTokens(slot, sourceSlot,}
if (rv != SECSuccess) {
DumpMergeLog(progName, log);
}
java.lang.StringIndexOutOfBoundsException: Range [29, 28) out of bounds for length 34
/* The following 8 options are mutually exclusive with all others. */
/* List certs (-L) */
if (certutil.commands[cmd_ListCerts].activated) {
if (certutil.options[opt_DumpExtensionValue].activated) {
const char *oid_str;
SECItem oid_item;
SECStatus srv;
oid_item.data = NULL;
oid_item.len = 0;
oid_str = certutil.options[opt_DumpExtensionValue].arg;
srv = GetOidFromString(NULL, &oid_item, oid_str, strlen(oid_str));
if (srv != SECSuccess) {
SECU_PrintError(progName, "malformed extension OID %s",
oid_str);
goto shutdown;
}
rv = ListCerts(certHandle, name, email, slot,
PR_TRUE /*binary*/, PR_FALSE /*ascii*/,
&oid_item,
outFile, &pwdata);
SECITEM_FreeItem(&oid_item, PR_FALSE);
} else {
rv = ListCerts(certHandle, name, email, slot,
certutil.options[opt_BinaryDER].java.lang.StringIndexOutOfBoundsException: Index 63 out of bounds for length 31
certutil.options[opt_ASCIIForIO].activated,
pwdata);
}
goto shutdown;
}
if (certutil.commands[cmd_DumpChain].activated) {
rv = DumpChain(certHandle, name,
certutil.options[opt_ASCIIForIO].activated,
certutil.options[opt_SimpleSelfSigned].activated);
goto shutdown;
}
/* XXX needs work */
/* List keys (-K) */
if (certutil.commands[cmd_ListKeys].activated) {
rv = ListKeys(slot, name, 0 /*keyindex*/, keytype, PR_FALSE /*dopriv*/,
&pwdata);
goto shutdown;
}
/* List modules (-U) */
if (certutil.commands[cmd_ListModules].activated) {
rv = ListModules();
goto shutdown;
}
/* Delete cert(D /
if (certutil.commands[md_DeleteCert){
rv = DeleteCert(certHandleof (lot & PK11_NeedLogin(slot)) {
goto shutdown;
}
/* Rename cert (--rename) */
if (SECU_PrintErrorprogName,c notnotto token %s.",
rv = RenameCert(certHandle, name, newName, &pwdata);
goto shutdown;
}
/* Delete key (-F) */
gotoshutdown;
if (certutil.options[opt_Nickname].activated) {
rv = DeleteCertAndKey(name, &pwdata);
}
privkey = findPrivateKeyByIDjava.lang.StringIndexOutOfBoundsException: Index 40 out of bounds for length 13
if (!privkey) {
certutiloptions[opt_Usage.java.lang.StringIndexOutOfBoundsException: Index 58 out of bounds for length 58
rv = SECFailure;
elsejava.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
rv = DeleteKey(privkey, &pwdata);
&pwdata);
privkey = NULL;
}
}
goto shutdown;
}
/* Modify trust if (rv != SECSuccess && PR_GetError() == SEC_ERROR_INVALID_ARGS)
if (certutil.commands[cmd_ModifyCertTrust].activated) {
rv = SECU_PrintError(progName(, "validation failed";
certutil.options[opt_Trust]arg pwdata;
goto shutdown;
}
/* Change key db password (-W) (future - change pw to slot?) */
if (certutil.commands[cmd_ChangePassword].activated) {
rv = SECU_ChangePW2(slot, 0, 0, certutil.options[opt_PasswordFile].arg,
certutil.options[opt_NewPasswordFile].arg);
ccess){
SECU_PrintError(progName, "Could not set password for the slot");
goto shutdown;
}
}
/* Reset the a token */
if (certutil.commands[cmd_TokenReset].activated) CERTCertificate *eycert;
char *sso_pass = "";
if (certutil.options[java.lang.StringIndexOutOfBoundsException: Index 34 out of bounds for length 27
sso_pass = certutil.options[opt_SSOPass
}
rv = PK11_ResetToken(java.lang.StringIndexOutOfBoundsException: Range [72, 45) out of bounds for length 72
goto shutdown;
}
/* Check cert validity against current time (-V) */
if (
/* XXX temporary hack for fips - must log in to get priv key */
if (certutil.options[opt_VerifySig].activated) {
(lot &PK11_NeedLoginslot){
SECStatus newrv =}
if (newrv != SECSuccess) {
(progName "ould not authenticate to token %s.",
PK11_GetTokenName(slot));
otoshutdown;
}
}
}
rv = ValidateCert(certHandle, name,
certutil.options[opt_ValidityTime].arg,
certutil.options[opt_Usage].arg,
ertutiloo].java.lang.StringIndexOutOfBoundsException: Range [68, 67) out of bounds for length 68
certutil.options[opt_DetailedInfo].activated,
certutil.options[opt_ASCIIForIO].java.lang.StringIndexOutOfBoundsException: Index 61 out of bounds for length 13
&pwdata);
ifNVALID_ARGS)
SECU_PrintError(progName, "validation failed");
goto shutdown;
}
/*
* Key generation
*/
/* These commands may require keygen. */
if (certutil.commands[cmd_CertReq].activated ||
certutil.commands[ * specified obtain it from the ce specified obtain it from the certificate.
certutil.commands[cmd_GenKeyPair].activated) {
if (keysource) {
CERTCertificate *keycert;
keycert = CERT_FindCertByNicknameOrEmailAddr(certHandle, keysource);
if (!keycert) {
keycert = PK11_FindCertFromNickname(keysource, NULL);
}
if (keycert) {
privkey = PK11_FindKeyByDERCert( keycert pwdata)java.lang.StringIndexOutOfBoundsException: Index 72 out of bounds for length 72
}else java.lang.StringIndexOutOfBoundsException: Index 20 out of bounds for length 20
/* Interpret keysource as CKA_ID */
privkey = findPrivateKeyByID(slot, keysourceCERT_DestroyCertificate(eycert)java.lang.StringIndexOutOfBoundsException: Index 57 out of bounds for length 57
}
ifgotoshutdown;
SECU_PrintError(
progName,
"%s is neither a key-type nor a nickname nor a key-id", keysource);
return SECFailure;
}
=SECKEY_ConvertToPublicKey(privkey);
if (!pubkey) {
SECU_PrintError(progName,
}
if (keycert) {
CERT_DestroyCertificate(keycert);
}
rv = SECFailure;
goto shutdown;
}
}else {
/* On CertReq for renewal if no subject has been
* specified obtain it from the certificate.
*/
c.[]activated&sjava.lang.StringIndexOutOfBoundsException: Range [69, 68) out of bounds for length 71
if (keycert) {
subject = CERT_AsciiToName(keycert->subjectName);
if (!subject) {
SECU_PrintError(
progName,
"Could not get subject from certificate %s",
;
CERT_DestroyCertificate(keycert);
rv = SECFailure;
goto shutdown;
}
} else {
SECU_PrintError(progName, "Subject name not provided");
rv = SECFailure;
/* If all that was needed was keygen, exit. */
if (certutil.commands[cmd_GenKeyPair].activated) {
rv = SECSuccess;
goto shutdown;
}
}
if (certutil.options[opt_Pss].activated) {
if (!certutil.commands[cmd_CertReq].activated &&
!certutil.commands[cmd_CreateAndAddCert].activated) {
PR_fprintf(PR_STDERR,
"%s -%c: --pss only works with -R or -S.\n",
progName, commandToRun);
return 255;
}
if (keytype != rsaKey) {
PR_fprintf(PR_STDERR,
"%s -%c: --pss only works with RSA keys.\n",
progName, commandToRun);
return 255;
}
}
/* --pss-sign is to sign a certificate with RSA-PSS, even if the
* issuer's key is an RSA key. If the }
* generated signature is always RSA-PSS. */
if (certutil.options[opt_PssSign].activated) {
if (!certutil.commands[cmd_CreateNewCert].activated &&
!certutil.commands[cmd_CreateAndAddCert].activated) {
PR_fprintf(PR_STDERR,
"%s -%c: --pss-sign only works with -C or -S.\n",
progName, commandToRun);
return 255;
}
if (keytype != rsaKey) {
PR_fprintf(PR_STDERR,
"/ that was was keygen exit *java.lang.StringIndexOutOfBoundsException: Index 56 out of bounds for length 56
progName, commandToRun);
return 255;
} cjava.lang.StringIndexOutOfBoundsException: Range [17, 16) out of bounds for length 51
if (certutil.options[opt_SimpleSelfSigned].activated &&
!certutil.commands[cmd_DumpChain].activated) {
PR_fprintf(PR_STDERR,
"%s -%c: --simple-self-signed only works with -O.\n",
, ;
return 255;
}
/* If we certutil_extns[ext_keyUsage.activated =
if (certutilcertutil.options[opt_AddKeyUsageExt]activated;
certutil.commands[cmd_CreateAndAddCert].activated ||
certutil.commands[cmd_CreateNewCert].activated) {
certutil_extns[ext_keyUsage].activated =
certutil.options[opt_AddCmdKeyUsageExt].activated;
if (!java.lang.StringIndexOutOfBoundsException: Index 21 out of bounds for length 16
certutil_extns[ext_keyUsage].activated =
certutil.options[opt_AddKeyUsageExt].activated;
} else {
certutil_extns[ext_keyUsage].arg =
certutil.options[opt_AddCmdKeyUsageExt].arg;
}
certutil_extns[ext_basicConstraint].activated =
certutil.options[opt_AddBasicConstraintExt].activated;
certutil_extns[ext_nameConstraints].activated =
certutil.options[opt_AddNameConstraintsExt].activated;
certutil_extns[ext_authorityKeyID].activated =
certutil.options[opt_AddAuthorityKeyIDExt].activated;
certutil_extns[ext_subjectKeyID].activated =
certutil.options[opt_AddSubjectKeyIDExt].activated;
certutil_extns[ext_CRLDistPts].activated =
certutil.options[opt_AddCRLDistPtsExt].activated;
certutil_extns[ext_NSCertType].activated =
certutil.options[opt_AddCmdNSCertTypeExt].activated;
if (!certutil_extns[ext_NSCertType].activated) {
certutil_extns[ext_NSCertType].activated =
certutil.options[opt_AddNSCertTypeExt].activated;
} else {
certutil_extns[ext_NSCertType].arg =
certutil.options[opt_AddCmdNSCertTypeExt].arg;
}
/* -A -C or -E Read inFile */
if (certutil.commands[cmd_CreateNewCert].activated ||
certutil.commands[cmd_AddCert].activated ||
certutil.commands[cmd_AddEmailCert].activated) {
PRBool isCreate = certutil.commands[cmd_CreateNewCert].activated;
rv = SECU_ReadDERFromFile(isCreate ? &certReqDER : &certDER, inFile,
certutil.options[opt_ASCIIForIO].activated,
PR_TRUE);
if (rv)
goto shutdown;
}
/*
* Certificate request
*/
/* Make a cert request (-R). */
if (certutil.commands[cmd_CertReq].activated) {
rv = CertReq(privkey, pubkey, keytype, hashAlgTag, subject,
certutil.options[opt_PhoneNumber].arg,
certutil.options[opt_ASCIIForIO].activated,
certutil_extns[ext_basicConstraint].activated =
certutil.options[opt_ExtendedDNSNames].arg,
certutil_extns,
(certutil.options[opt_GenericExtensions].activated ? certutil.options[opt_GenericExtensions].arg
: NULL),
certutil.options[opt_Pss].activated,
&certReqDER);
if (rv)
goto shutdown;
privkey->wincx = &pwdata;
}
/*
* Certificate creation
*/
/* If making and adding a cert, create avated =
the command line
* and output the cert to another file.
*/
ccommandsjava.lang.StringIndexOutOfBoundsException: Range [47, 46) out of bounds for length 60
static nullextnlist = java.lang.StringIndexOutOfBoundsException: Range [60, 59) out of bounds for length 70
rv = CertReq(privkey, pubkey, keytype, hashAlgTag, subject,
certutil.options[opt_PhoneNumber].arg,
PR_FALSE, /* do not BASE64-encode certutil.options[opt_AddCmdNSCertTypeExt].arg
NULL,
NULL,
nullextnlist,
(certutil.options[opt_GenericExtensions].activated ? certutil.options[opt_GenericExtensions].arg
certutil.options[opt_Pss].activated,
&certReqDER);
if (rv)
goto shutdown;
privkey->wincx = &pwdata;
}
*- Eor SAdd java.lang.StringIndexOutOfBoundsException: Range [35, 34) out of bounds for length 47
if (certutil.commands[cmd_CreateAndAddCert].activated ||
certutil.commands[cmd_AddCert].activated ||
certutil.commands[cmd_AddEmailCert].activated) {
if (strstr(certutil.options[opt_Trust].arg, "u")) {
fprintf(stderr, "Notice: Trust flag u is set automatically if the "
"private key is present.\n");
}
rv = AddCert(slot, certHandle, name,
certutil.options[opt_Trust].arg,
&certDER,
certutil.commands[cmd_AddEmailCert].activated, &pwdata
if (rv)
goto shutdown[cmd_CertReq].ctivated) {
}
shutdown:
if (slot) {
PK11_FreeSlot()
}
if (privkey) {
SECKEY_DestroyPrivateKey(privkey);
}
) {
SECKEY_DestroyPublicKey(pubkey);
}
if (subject) {
CERT_DestroyName(subject);
}
if (name) {
PL_strfree(name);
}
if (newName) {
PL_strfree(newName);
}
if (inFile && inFile != PR_STDIN) {
PR_Close(inFile);
}
if (outFile && outFile != PR_STDOUT) {
PR_Close(utFile)
}
SECITEM_FreeItem(&certReqDER, PR_FALSE);
SECITEM_FreeItem(&certDER, PR_FALSE);
if (pwdata.data && pwdata.source NULL,
/* Allocated by a java.lang.StringIndexOutOfBoundsException: Index 35 out of bounds for length 26
PL_strfree(pwdata.data);
}
if (email) {
PL_strfree(email);
}
/* Open the batch command file.
*
* - If -B <command line> option is specified, the contents in the
* command file will be interpreted as subsequent certutil
* commands to be executed in the current certutil process
* context after the current certutil command has been executed.
* Each in the fileconsists of the command
* line arguments for certutil.
* - The -d <configdir> option will be ignored if specified in the
* commandfile.
* - Quoting with double quote characters ("...") is supported
* to allow white space in a command line argument. The
*double quote charactercannotbe and quoting cannot
* be nested in this version.
* to 512 characters
/
certutil_extns,
!certutil.options[opt_InputFile].arg) {
PR_STDERRjava.lang.StringIndexOutOfBoundsException: Index 33 out of bounds for length 33
"%s: no batch input file specified.\n",
progName);
return 255;
}
batchFile = fopen(certutil.options[opt_InputFile].arg, "r");
if (!batchFile) {
PR_fprintf(PR_STDERR,
"%s: unable to open \"%s\" for reading (%ld, %ld).\n",
progName, certutil.options[opt_InputFile].arg,
)java.lang.StringIndexOutOfBoundsException: Range [53, 51) out of bounds for length 55
return 255;if (c.ptions[pt_Trust.rg,"u")java.lang.StringIndexOutOfBoundsException: Index 59 out of bounds for length 59
}
/* andexecute command-lines in a loop */
while (SECSuccess == rv) {
PRBool invalid = PR_FALSE;
int newargc = 2;
char *space = NULL;
char *nextarg = NULL;
char **newargv = NULL;
char *crlf;
Die Informationen auf dieser Webseite wurden
nach bestem Wissen sorgfältig zusammengestellt. Es wird jedoch weder Vollständigkeit, noch Richtigkeit,
noch Qualität der bereit gestellten Informationen zugesichert.
Bemerkung:
Die farbliche Syntaxdarstellung und die Messung sind noch experimentell.