diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml new file mode 100644 index 0000000..2263c2b --- /dev/null +++ b/.github/workflows/test.yml @@ -0,0 +1,34 @@ +name: Basic tests + +on: + pull_request: + branches: + - main + + push: + branches: + - main + +jobs: + build-and-test: + runs-on: ubuntu-latest + env: + PKCS11_MODULE: /usr/lib/softhsm/libsofthsm2.so + steps: + - uses: actions/checkout@v2 + # - name: SoftHSM installation + # run: | + # sudo apt-get install -f libsofthsm2 + # sudo usermod -a -G softhsm $USER + - name: build + run: cargo build + # - name: test + # run: | + # sg softhsm -c 'cargo test' + # - name: setup token + # run: | + # sg softhsm -c 'softhsm2-util --init-token --free --label lpc55-2ac0c213b4903b76 --pin 1234 --so-pin 1234' + - name: rustfmt + run: cargo fmt -- --check + - name: clippy + run: cargo clean && cargo clippy --all-targets --all-features -- -D warnings diff --git a/Cargo.toml b/Cargo.toml index 1d8fc77..56e7f47 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -3,6 +3,12 @@ name = "pkcs11-uri" version = "0.1.0" authors = ["Nicolas Stalder "] edition = "2018" +description = "PKCS #11 URI parser" +readme = "README.md" +license = "Apache-2.0 OR MIT" +documentation = "https://docs.rs/pkcs11-uri" +keywords = ["pkcs11", "cryptoki", "cryptography", "signatures", "hsm"] +categories = ["cryptography", "hardware-support"] # See more keys and their definitions at https://doc.rust-lang.org/cargo/reference/manifest.html @@ -11,7 +17,8 @@ anyhow = "1" log = "0.4.11" percent-encoding = "2.1.0" pkcs11 = "0.5.0" -uriparse = { git = "https://github.com/nickray/uriparse-rs", branch = "pkcs11-typo" } +uriparse = "0.6.3" +# uriparse = { git = "https://github.com/nickray/uriparse-rs", branch = "pkcs11-typo" } [dev-dependencies] serial_test = "0.5.1" diff --git a/LICENSE-APACHE b/LICENSE-APACHE new file mode 100644 index 0000000..cd482d8 --- /dev/null +++ b/LICENSE-APACHE @@ -0,0 +1,201 @@ +Apache License +Version 2.0, January 2004 +http://www.apache.org/licenses/ + +TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + +1. Definitions. + +"License" shall mean the terms and conditions for use, reproduction, +and distribution as defined by Sections 1 through 9 of this document. + +"Licensor" shall mean the copyright owner or entity authorized by +the copyright owner that is granting the License. + +"Legal Entity" shall mean the union of the acting entity and all +other entities that control, are controlled by, or are under common +control with that entity. For the purposes of this definition, +"control" means (i) the power, direct or indirect, to cause the +direction or management of such entity, whether by contract or +otherwise, or (ii) ownership of fifty percent (50%) or more of the +outstanding shares, or (iii) beneficial ownership of such entity. + +"You" (or "Your") shall mean an individual or Legal Entity +exercising permissions granted by this License. + +"Source" form shall mean the preferred form for making modifications, +including but not limited to software source code, documentation +source, and configuration files. + +"Object" form shall mean any form resulting from mechanical +transformation or translation of a Source form, including but +not limited to compiled object code, generated documentation, +and conversions to other media types. + +"Work" shall mean the work of authorship, whether in Source or +Object form, made available under the License, as indicated by a +copyright notice that is included in or attached to the work +(an example is provided in the Appendix below). + +"Derivative Works" shall mean any work, whether in Source or Object +form, that is based on (or derived from) the Work and for which the +editorial revisions, annotations, elaborations, or other modifications +represent, as a whole, an original work of authorship. For the purposes +of this License, Derivative Works shall not include works that remain +separable from, or merely link (or bind by name) to the interfaces of, +the Work and Derivative Works thereof. + +"Contribution" shall mean any work of authorship, including +the original version of the Work and any modifications or additions +to that Work or Derivative Works thereof, that is intentionally +submitted to Licensor for inclusion in the Work by the copyright owner +or by an individual or Legal Entity authorized to submit on behalf of +the copyright owner. For the purposes of this definition, "submitted" +means any form of electronic, verbal, or written communication sent +to the Licensor or its representatives, including but not limited to +communication on electronic mailing lists, source code control systems, +and issue tracking systems that are managed by, or on behalf of, the +Licensor for the purpose of discussing and improving the Work, but +excluding communication that is conspicuously marked or otherwise +designated in writing by the copyright owner as "Not a Contribution." + +"Contributor" shall mean Licensor and any individual or Legal Entity +on behalf of whom a Contribution has been received by Licensor and +subsequently incorporated within the Work. + +2. Grant of Copyright License. Subject to the terms and conditions of +this License, each Contributor hereby grants to You a perpetual, +worldwide, non-exclusive, no-charge, royalty-free, irrevocable +copyright license to reproduce, prepare Derivative Works of, +publicly display, publicly perform, sublicense, and distribute the +Work and such Derivative Works in Source or Object form. + +3. Grant of Patent License. Subject to the terms and conditions of +this License, each Contributor hereby grants to You a perpetual, +worldwide, non-exclusive, no-charge, royalty-free, irrevocable +(except as stated in this section) patent license to make, have made, +use, offer to sell, sell, import, and otherwise transfer the Work, +where such license applies only to those patent claims licensable +by such Contributor that are necessarily infringed by their +Contribution(s) alone or by combination of their Contribution(s) +with the Work to which such Contribution(s) was submitted. If You +institute patent litigation against any entity (including a +cross-claim or counterclaim in a lawsuit) alleging that the Work +or a Contribution incorporated within the Work constitutes direct +or contributory patent infringement, then any patent licenses +granted to You under this License for that Work shall terminate +as of the date such litigation is filed. + +4. Redistribution. You may reproduce and distribute copies of the +Work or Derivative Works thereof in any medium, with or without +modifications, and in Source or Object form, provided that You +meet the following conditions: + +(a) You must give any other recipients of the Work or +Derivative Works a copy of this License; and + +(b) You must cause any modified files to carry prominent notices +stating that You changed the files; and + +(c) You must retain, in the Source form of any Derivative Works +that You distribute, all copyright, patent, trademark, and +attribution notices from the Source form of the Work, +excluding those notices that do not pertain to any part of +the Derivative Works; and + +(d) If the Work includes a "NOTICE" text file as part of its +distribution, then any Derivative Works that You distribute must +include a readable copy of the attribution notices contained +within such NOTICE file, excluding those notices that do not +pertain to any part of the Derivative Works, in at least one +of the following places: within a NOTICE text file distributed +as part of the Derivative Works; within the Source form or +documentation, if provided along with the Derivative Works; or, +within a display generated by the Derivative Works, if and +wherever such third-party notices normally appear. The contents +of the NOTICE file are for informational purposes only and +do not modify the License. You may add Your own attribution +notices within Derivative Works that You distribute, alongside +or as an addendum to the NOTICE text from the Work, provided +that such additional attribution notices cannot be construed +as modifying the License. + +You may add Your own copyright statement to Your modifications and +may provide additional or different license terms and conditions +for use, reproduction, or distribution of Your modifications, or +for any such Derivative Works as a whole, provided Your use, +reproduction, and distribution of the Work otherwise complies with +the conditions stated in this License. + +5. Submission of Contributions. Unless You explicitly state otherwise, +any Contribution intentionally submitted for inclusion in the Work +by You to the Licensor shall be under the terms and conditions of +this License, without any additional terms or conditions. +Notwithstanding the above, nothing herein shall supersede or modify +the terms of any separate license agreement you may have executed +with Licensor regarding such Contributions. + +6. Trademarks. This License does not grant permission to use the trade +names, trademarks, service marks, or product names of the Licensor, +except as required for reasonable and customary use in describing the +origin of the Work and reproducing the content of the NOTICE file. + +7. Disclaimer of Warranty. Unless required by applicable law or +agreed to in writing, Licensor provides the Work (and each +Contributor provides its Contributions) on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or +implied, including, without limitation, any warranties or conditions +of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A +PARTICULAR PURPOSE. You are solely responsible for determining the +appropriateness of using or redistributing the Work and assume any +risks associated with Your exercise of permissions under this License. + +8. Limitation of Liability. In no event and under no legal theory, +whether in tort (including negligence), contract, or otherwise, +unless required by applicable law (such as deliberate and grossly +negligent acts) or agreed to in writing, shall any Contributor be +liable to You for damages, including any direct, indirect, special, +incidental, or consequential damages of any character arising as a +result of this License or out of the use or inability to use the +Work (including but not limited to damages for loss of goodwill, +work stoppage, computer failure or malfunction, or any and all +other commercial damages or losses), even if such Contributor +has been advised of the possibility of such damages. + +9. Accepting Warranty or Additional Liability. While redistributing +the Work or Derivative Works thereof, You may choose to offer, +and charge a fee for, acceptance of support, warranty, indemnity, +or other liability obligations and/or rights consistent with this +License. However, in accepting such obligations, You may act only +on Your own behalf and on Your sole responsibility, not on behalf +of any other Contributor, and only if You agree to indemnify, +defend, and hold each Contributor harmless for any liability +incurred by, or claims asserted against, such Contributor by reason +of your accepting any such warranty or additional liability. + +END OF TERMS AND CONDITIONS + +APPENDIX: How to apply the Apache License to your work. + +To apply the Apache License to your work, attach the following +boilerplate notice, with the fields enclosed by brackets "[]" +replaced with your own identifying information. (Don't include +the brackets!) The text should be enclosed in the appropriate +comment syntax for the file format. We also recommend that a +file or class name and description of purpose be included on the +same "printed page" as the copyright notice for easier +identification within third-party archives. + +Copyright [yyyy] [name of copyright owner] + +Licensed under the Apache License, Version 2.0 (the "License"); +you may not use this file except in compliance with the License. +You may obtain a copy of the License at + +http://www.apache.org/licenses/LICENSE-2.0 + +Unless required by applicable law or agreed to in writing, software +distributed under the License is distributed on an "AS IS" BASIS, +WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +See the License for the specific language governing permissions and +limitations under the License. diff --git a/LICENSE-MIT b/LICENSE-MIT new file mode 100644 index 0000000..96663fd --- /dev/null +++ b/LICENSE-MIT @@ -0,0 +1,25 @@ +Copyright (c) 2021 Nicolas Stalder + +Permission is hereby granted, free of charge, to any +person obtaining a copy of this software and associated +documentation files (the "Software"), to deal in the +Software without restriction, including without +limitation the rights to use, copy, modify, merge, +publish, distribute, sublicense, and/or sell copies of +the Software, and to permit persons to whom the Software +is furnished to do so, subject to the following +conditions: + +The above copyright notice and this permission notice +shall be included in all copies or substantial portions +of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF +ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED +TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A +PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT +SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY +CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION +OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR +IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER +DEALINGS IN THE SOFTWARE. diff --git a/Makefile b/Makefile new file mode 100644 index 0000000..4fc04cb --- /dev/null +++ b/Makefile @@ -0,0 +1,5 @@ +check: + cargo clean + cargo fmt -- --check + cargo clean + cargo clippy --all-targets --all-features -- -D warnings diff --git a/README.md b/README.md index 543ce47..2b84e11 100644 --- a/README.md +++ b/README.md @@ -1 +1,8 @@ API docs: + +### Getting started + +One way to generate URIs to feed into this library is the `p11tool` in GnuTLS. +Running `p11tool --list-tokens` returns the URIs for all available tokens. +Running `p11tool --list-all ` then lists all the objects in that token. +For private keys, use `GNUTLS_PIN= p11tool --login --list-all `. diff --git a/examples/lookup.rs b/examples/lookup.rs index 5140892..e8c7852 100644 --- a/examples/lookup.rs +++ b/examples/lookup.rs @@ -12,14 +12,11 @@ fn main() { fn try_main() -> anyhow::Result<()> { let uri_str = r"pkcs11: type=private; - slot-id=327; - serial=d2dcb3ad5e30674d; token=lpc55-2ac0c213b4903b76; - slot-manufacturer=SoftHSM%20project; object=lpc55-2ac0c213b4903b76%20@%202021-01-08T20:41:24 ?pin-value=1234 &module-path=/usr/lib/libsofthsm2.so"; - let uri = Pkcs11Uri::try_parse(uri_str)?; + let uri = Pkcs11Uri::try_from(uri_str)?; let (context, session, object) = uri.identify_object().unwrap(); // CKM_SHA256_RSA_PKCS diff --git a/examples/simple.rs b/examples/simple.rs index 026112e..faa1a69 100644 --- a/examples/simple.rs +++ b/examples/simple.rs @@ -11,7 +11,7 @@ fn try_main() -> anyhow::Result<()> { // let uri = "pkcs11:object=my-signing-key;type=private;serial=DECC0401648?pin-source=file:/etc/token&x=y"; // let uri = "pkcs11:object=my-signing-key;type=private;serial=DECC0401648"; // pkcs11_uri::identify(uri)?; - let uri = Pkcs11Uri::try_parse(uri_str)?; - dbg!(uri.clone()); + let uri = Pkcs11Uri::try_from(uri_str)?; + dbg!(uri); Ok(()) } diff --git a/src/lib.rs b/src/lib.rs index d63576d..accdc13 100644 --- a/src/lib.rs +++ b/src/lib.rs @@ -14,7 +14,7 @@ use core::convert::{TryFrom, TryInto}; use log::{debug, trace}; pub type Context = pkcs11::Ctx; pub type SessionHandle = pkcs11::types::CK_SESSION_HANDLE; -pub type ObjectHandle = pkcs11::types::CK_OBJECT_HANDLE; +pub type ObjectHandle = pkcs11::types::CK_OBJECT_HANDLE; pub type SlotId = pkcs11::types::CK_SLOT_ID; #[cfg(test)] @@ -22,23 +22,26 @@ mod tests; use anyhow::anyhow; -fn parse_slot_id<'a>(value: &'a str) -> Result { +fn parse_slot_id(value: &str) -> Result { Ok(value.parse().or(Err(value))?) } -fn percent_decode_string<'a>(value: &'a str) -> Result { - Ok(percent_encoding::percent_decode_str(value).decode_utf8().or(Err(value))?.into_owned()) +fn percent_decode_string(value: &str) -> Result { + Ok(percent_encoding::percent_decode_str(value) + .decode_utf8() + .or(Err(value))? + .into_owned()) } -fn percent_decode_bytes<'a>(value: &'a str) -> Result, &'a str> { +fn percent_decode_bytes(value: &str) -> Result, &str> { Ok(percent_encoding::percent_decode_str(value).collect()) } -fn parse_object_class<'a>(value: &'a str) -> Result { +fn parse_object_class(value: &str) -> Result { Ok(value.try_into().or(Err(value))?) } -fn parse_library_version<'a>(value: &'a str) -> Result { +fn parse_library_version(value: &str) -> Result { Ok(if value.contains('.') { let tuple: Vec<&str> = value.splitn(2, '.').collect(); let [major, minor]: [&str; 2] = tuple.as_slice().try_into().unwrap(); @@ -57,10 +60,10 @@ fn parse_library_version<'a>(value: &'a str) -> Result { // In rust-pkcs11, this is `pkcs11::types::padding::BlankPaddedString16`, even though the docs // claim it's a UTF-8 string -fn parse_serial_number<'a>(value: &'a str) -> Result<[u8; 16], &'a str> { +fn parse_serial_number(value: &str) -> Result<[u8; 16], &str> { let mut characters: Vec = percent_encoding::percent_decode_str(value).collect(); if characters.len() > 16 { - return Err(value) + Err(value) } else { characters.resize(16, b' '); Ok(characters.try_into().unwrap()) @@ -161,7 +164,7 @@ impl<'a> TryFrom<&'a str> for ObjectClass { "private" => PrivateKey, "public" => PublicKey, "secret-key" => SecretKey, - _ => Err(s)?, + _ => return Err(s), }) } } @@ -193,25 +196,16 @@ pub struct Pkcs11Uri { impl Pkcs11Uri { /// TryFrom as inherent method - pub fn try_parse(uri_str: &str) -> anyhow::Result { - Self::try_from(uri_str) - } -} - -impl<'a> TryFrom<&'a str> for Pkcs11Uri { - type Error = anyhow::Error; - - fn try_from(uri_str: &str) -> std::result::Result { - + pub fn try_from(uri_str: &str) -> anyhow::Result { // 0. strip whitespace let uri_string: String = uri_str.chars().filter(|c| !c.is_whitespace()).collect(); // 1. uriparse from string, check validity - let uri = uriparse::URIReference::try_from(uri_string.as_str())?; // dbg!(&uri); - if uri.scheme() != Some(&uriparse::Scheme::PKCS11) { + // if uri.scheme() != Some(&uriparse::Scheme::PKCS11) { + if uri.scheme() != Some(&uriparse::Scheme::PKCKS11) { return Err(anyhow!("URI should have PKCS11 scheme")); } if uri.authority().is_some() { @@ -233,14 +227,24 @@ impl<'a> TryFrom<&'a str> for Pkcs11Uri { let query_attributes = QueryAttributes::try_from(query).unwrap(); // 4. wrap up - let parsed_uri = Pkcs11Uri { path_attributes, query_attributes }; + let parsed_uri = Pkcs11Uri { + path_attributes, + query_attributes, + }; Ok(parsed_uri) } } -impl Pkcs11Uri { +impl<'a> TryFrom<&'a str> for Pkcs11Uri { + type Error = anyhow::Error; + + fn try_from(uri_str: &str) -> std::result::Result { + Self::try_from(uri_str) + } +} +impl Pkcs11Uri { fn matches_slot(&self, ctx: &pkcs11::Ctx, slot_id: pkcs11::types::CK_SLOT_ID) -> bool { // slot_id, slot_description, slot_manufacturer @@ -309,11 +313,12 @@ impl Pkcs11Uri { let ctx = self.context(); let slots: Vec = ctx - .get_slot_list(true).unwrap() - .iter().copied() + .get_slot_list(true) + .unwrap() + .iter() + .copied() .filter(|slot| self.matches_slot(&ctx, *slot)) - .collect() - ; + .collect(); Ok(slots) } @@ -322,12 +327,13 @@ impl Pkcs11Uri { let ctx = self.context(); let slots: Vec = ctx - .get_slot_list(true).unwrap() - .iter().copied() + .get_slot_list(true) + .unwrap() + .iter() + .copied() .filter(|slot| self.matches_slot(&ctx, *slot)) .filter(|slot| self.matches_token(&ctx, *slot)) - .collect() - ; + .collect(); Ok(slots) } @@ -337,16 +343,17 @@ impl Pkcs11Uri { // 1. find the slot let slots: Vec = ctx - .get_slot_list(true).unwrap() - .iter().copied() + .get_slot_list(true) + .unwrap() + .iter() + .copied() .filter(|slot| self.matches_slot(&ctx, *slot)) .filter(|slot| self.matches_token(&ctx, *slot)) - .collect() - ; + .collect(); debug!("slots: {:?}", slots); - if slots.len() == 0 { + if slots.is_empty() { return Err(anyhow!("No slots found")); } if slots.len() > 1 { @@ -358,10 +365,15 @@ impl Pkcs11Uri { // 2. create a logged-in session with the slot let flags = pkcs11::types::CKF_SERIAL_SESSION | pkcs11::types::CKF_RW_SESSION; - let session = ctx.open_session(slot, flags, /*application: */ None, /*notify: */ None).unwrap(); + let session = ctx + .open_session( + slot, flags, /*application: */ None, /*notify: */ None, + ) + .unwrap(); let maybe_pin: Option<&str> = self.query_attributes.pin_value.as_deref(); trace!("{:?}", maybe_pin); - ctx.login(session, pkcs11::types::CKU_USER, maybe_pin).unwrap(); + ctx.login(session, pkcs11::types::CKU_USER, maybe_pin) + .unwrap(); // 3. find the object // object_class: Option @@ -378,7 +390,8 @@ impl Pkcs11Uri { } if let Some(object_class) = &self.path_attributes.object_class { let raw_object_class = *object_class as u8 as _; - template.push(Attribute::new(pkcs11::types::CKA_CLASS).with_ck_ulong(&raw_object_class)); + template + .push(Attribute::new(pkcs11::types::CKA_CLASS).with_ck_ulong(&raw_object_class)); } ctx.find_objects_init(session, &template).unwrap(); @@ -388,7 +401,7 @@ impl Pkcs11Uri { debug!("objects: {:?}", objects); - if objects.len() == 0 { + if objects.is_empty() { return Err(anyhow!("No objects found")); } if objects.len() > 1 { @@ -398,5 +411,4 @@ impl Pkcs11Uri { let object = objects[0]; Ok((ctx, session, object)) } - } diff --git a/src/tests.rs b/src/tests.rs index 69c1ec4..6aab7fe 100644 --- a/src/tests.rs +++ b/src/tests.rs @@ -1,9 +1,10 @@ -use std::path::PathBuf; use pkcs11::Ctx; use serial_test::serial; +use std::path::PathBuf; fn pkcs11_module_name() -> PathBuf { - let path = std::env::var_os("PKCS11_MODULE").unwrap_or("/usr/lib/libsofthsm2.so".into()); + let path = + std::env::var_os("PKCS11_MODULE").unwrap_or_else(|| "/usr/lib/libsofthsm2.so".into()); let path_buf = PathBuf::from(path); if !path_buf.exists() { panic!("Set location of PKCS#11 module with `PKCS11_MODULE` environment variable"); @@ -21,7 +22,10 @@ fn new_then_initialize() { "failed to initialize session: {}", res.unwrap_err() ); - assert!(session.is_initialized(), "internal state is not initialized"); + assert!( + session.is_initialized(), + "internal state is not initialized" + ); } #[test]