Introduce keyring unlock key concept.
* Rename fKeyMessage to fUnlockKey and the KeyMessage() getter to UnlockKey(). * Keep track of whether the keyring has an unlock key set. * Store and restore that info separately. * En- and decryption will depend on unlock key presence later. * Add functions to set and remove an unlock key and query for it.
This commit is contained in:
committed by
Ryan Leavengood
parent
bec02d0c2f
commit
a82011ff96
@@ -350,7 +350,7 @@ KeyStoreServer::MessageReceived(BMessage* message)
|
|||||||
break;
|
break;
|
||||||
|
|
||||||
BString secondaryIdentifier = keyring->Name();
|
BString secondaryIdentifier = keyring->Name();
|
||||||
BMessage keyMessage = keyring->KeyMessage();
|
BMessage keyMessage = keyring->UnlockKey();
|
||||||
keyMessage.RemoveName("identifier");
|
keyMessage.RemoveName("identifier");
|
||||||
keyMessage.AddString("identifier", kKeyringKeysIdentifier);
|
keyMessage.AddString("identifier", kKeyringKeysIdentifier);
|
||||||
keyMessage.RemoveName("secondaryIdentifier");
|
keyMessage.RemoveName("secondaryIdentifier");
|
||||||
@@ -720,6 +720,9 @@ KeyStoreServer::_RemoveKeyring(const BString& name)
|
|||||||
status_t
|
status_t
|
||||||
KeyStoreServer::_UnlockKeyring(Keyring& keyring)
|
KeyStoreServer::_UnlockKeyring(Keyring& keyring)
|
||||||
{
|
{
|
||||||
|
if (!keyring.HasUnlockKey())
|
||||||
|
return keyring.Unlock(NULL);
|
||||||
|
|
||||||
// If we are accessing a keyring that has been added to master access we
|
// If we are accessing a keyring that has been added to master access we
|
||||||
// get the key from the master keyring and unlock with that.
|
// get the key from the master keyring and unlock with that.
|
||||||
BMessage keyMessage;
|
BMessage keyMessage;
|
||||||
@@ -727,7 +730,7 @@ KeyStoreServer::_UnlockKeyring(Keyring& keyring)
|
|||||||
if (fMasterKeyring->FindKey(kKeyringKeysIdentifier, keyring.Name(),
|
if (fMasterKeyring->FindKey(kKeyringKeysIdentifier, keyring.Name(),
|
||||||
false, &keyMessage) == B_OK) {
|
false, &keyMessage) == B_OK) {
|
||||||
// We found a key for this keyring, try to unlock with it.
|
// We found a key for this keyring, try to unlock with it.
|
||||||
if (keyring.Unlock(keyMessage) == B_OK)
|
if (keyring.Unlock(&keyMessage) == B_OK)
|
||||||
return B_OK;
|
return B_OK;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -737,7 +740,7 @@ KeyStoreServer::_UnlockKeyring(Keyring& keyring)
|
|||||||
if (result != B_OK)
|
if (result != B_OK)
|
||||||
return result;
|
return result;
|
||||||
|
|
||||||
return keyring.Unlock(keyMessage);
|
return keyring.Unlock(&keyMessage);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
|
|||||||
@@ -9,6 +9,7 @@
|
|||||||
|
|
||||||
Keyring::Keyring()
|
Keyring::Keyring()
|
||||||
:
|
:
|
||||||
|
fHasUnlockKey(false),
|
||||||
fUnlocked(false),
|
fUnlocked(false),
|
||||||
fModified(false)
|
fModified(false)
|
||||||
{
|
{
|
||||||
@@ -18,6 +19,7 @@ Keyring::Keyring()
|
|||||||
Keyring::Keyring(const char* name)
|
Keyring::Keyring(const char* name)
|
||||||
:
|
:
|
||||||
fName(name),
|
fName(name),
|
||||||
|
fHasUnlockKey(false),
|
||||||
fUnlocked(false),
|
fUnlocked(false),
|
||||||
fModified(false)
|
fModified(false)
|
||||||
{
|
{
|
||||||
@@ -36,6 +38,10 @@ Keyring::ReadFromMessage(const BMessage& message)
|
|||||||
if (result != B_OK)
|
if (result != B_OK)
|
||||||
return result;
|
return result;
|
||||||
|
|
||||||
|
result = message.FindBool("hasUnlockKey", &fHasUnlockKey);
|
||||||
|
if (result != B_OK)
|
||||||
|
return result;
|
||||||
|
|
||||||
ssize_t size;
|
ssize_t size;
|
||||||
const void* data;
|
const void* data;
|
||||||
result = message.FindData("data", B_RAW_TYPE, &data, &size);
|
result = message.FindData("data", B_RAW_TYPE, &data, &size);
|
||||||
@@ -68,18 +74,29 @@ Keyring::WriteToMessage(BMessage& message)
|
|||||||
if (result != B_OK)
|
if (result != B_OK)
|
||||||
return result;
|
return result;
|
||||||
|
|
||||||
|
result = message.AddBool("hasUnlockKey", fHasUnlockKey);
|
||||||
|
if (result != B_OK)
|
||||||
|
return result;
|
||||||
|
|
||||||
return message.AddString("name", fName);
|
return message.AddString("name", fName);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
status_t
|
status_t
|
||||||
Keyring::Unlock(const BMessage& keyMessage)
|
Keyring::Unlock(const BMessage* keyMessage)
|
||||||
{
|
{
|
||||||
fKeyMessage = keyMessage;
|
if (fUnlocked)
|
||||||
|
return B_OK;
|
||||||
|
|
||||||
|
if (fHasUnlockKey == (keyMessage == NULL))
|
||||||
|
return B_BAD_VALUE;
|
||||||
|
|
||||||
|
if (keyMessage != NULL)
|
||||||
|
fUnlockKey = *keyMessage;
|
||||||
|
|
||||||
status_t result = _DecryptFromFlatBuffer();
|
status_t result = _DecryptFromFlatBuffer();
|
||||||
if (result != B_OK) {
|
if (result != B_OK) {
|
||||||
fKeyMessage.MakeEmpty();
|
fUnlockKey.MakeEmpty();
|
||||||
return result;
|
return result;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -96,7 +113,7 @@ Keyring::Lock()
|
|||||||
|
|
||||||
_EncryptToFlatBuffer();
|
_EncryptToFlatBuffer();
|
||||||
|
|
||||||
fKeyMessage.MakeEmpty();
|
fUnlockKey.MakeEmpty();
|
||||||
fData.MakeEmpty();
|
fData.MakeEmpty();
|
||||||
fApplications.MakeEmpty();
|
fApplications.MakeEmpty();
|
||||||
fUnlocked = false;
|
fUnlocked = false;
|
||||||
@@ -110,10 +127,43 @@ Keyring::IsUnlocked() const
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
const BMessage&
|
bool
|
||||||
Keyring::KeyMessage() const
|
Keyring::HasUnlockKey() const
|
||||||
{
|
{
|
||||||
return fKeyMessage;
|
return fHasUnlockKey;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
const BMessage&
|
||||||
|
Keyring::UnlockKey() const
|
||||||
|
{
|
||||||
|
return fUnlockKey;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
status_t
|
||||||
|
Keyring::SetUnlockKey(const BMessage& keyMessage)
|
||||||
|
{
|
||||||
|
if (!fUnlocked)
|
||||||
|
return B_NOT_ALLOWED;
|
||||||
|
|
||||||
|
fHasUnlockKey = true;
|
||||||
|
fUnlockKey = keyMessage;
|
||||||
|
fModified = true;
|
||||||
|
return B_OK;
|
||||||
|
}
|
||||||
|
|
||||||
|
|
||||||
|
status_t
|
||||||
|
Keyring::RemoveUnlockKey()
|
||||||
|
{
|
||||||
|
if (!fUnlocked)
|
||||||
|
return B_NOT_ALLOWED;
|
||||||
|
|
||||||
|
fUnlockKey.MakeEmpty();
|
||||||
|
fHasUnlockKey = false;
|
||||||
|
fModified = true;
|
||||||
|
return B_OK;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
@@ -430,7 +480,9 @@ Keyring::_EncryptToFlatBuffer()
|
|||||||
if (result != B_OK)
|
if (result != B_OK)
|
||||||
return result;
|
return result;
|
||||||
|
|
||||||
// TODO: Actually encrypt the flat buffer...
|
if (fHasUnlockKey) {
|
||||||
|
// TODO: Actually encrypt the flat buffer...
|
||||||
|
}
|
||||||
|
|
||||||
fModified = false;
|
fModified = false;
|
||||||
return B_OK;
|
return B_OK;
|
||||||
@@ -443,7 +495,9 @@ Keyring::_DecryptFromFlatBuffer()
|
|||||||
if (fFlatBuffer.BufferLength() == 0)
|
if (fFlatBuffer.BufferLength() == 0)
|
||||||
return B_OK;
|
return B_OK;
|
||||||
|
|
||||||
// TODO: Actually decrypt the flat buffer...
|
if (fHasUnlockKey) {
|
||||||
|
// TODO: Actually decrypt the flat buffer...
|
||||||
|
}
|
||||||
|
|
||||||
BMessage container;
|
BMessage container;
|
||||||
fFlatBuffer.Seek(0, SEEK_SET);
|
fFlatBuffer.Seek(0, SEEK_SET);
|
||||||
|
|||||||
@@ -20,10 +20,15 @@ public:
|
|||||||
status_t ReadFromMessage(const BMessage& message);
|
status_t ReadFromMessage(const BMessage& message);
|
||||||
status_t WriteToMessage(BMessage& message);
|
status_t WriteToMessage(BMessage& message);
|
||||||
|
|
||||||
status_t Unlock(const BMessage& keyMessage);
|
status_t Unlock(const BMessage* keyMessage);
|
||||||
void Lock();
|
void Lock();
|
||||||
bool IsUnlocked() const;
|
bool IsUnlocked() const;
|
||||||
const BMessage& KeyMessage() const;
|
|
||||||
|
bool HasUnlockKey() const;
|
||||||
|
const BMessage& UnlockKey() const;
|
||||||
|
|
||||||
|
status_t SetUnlockKey(const BMessage& keyMessage);
|
||||||
|
status_t RemoveUnlockKey();
|
||||||
|
|
||||||
status_t GetNextApplication(uint32& cookie,
|
status_t GetNextApplication(uint32& cookie,
|
||||||
BString& signature, BString& path);
|
BString& signature, BString& path);
|
||||||
@@ -61,7 +66,8 @@ private:
|
|||||||
BMallocIO fFlatBuffer;
|
BMallocIO fFlatBuffer;
|
||||||
BMessage fData;
|
BMessage fData;
|
||||||
BMessage fApplications;
|
BMessage fApplications;
|
||||||
BMessage fKeyMessage;
|
BMessage fUnlockKey;
|
||||||
|
bool fHasUnlockKey;
|
||||||
bool fUnlocked;
|
bool fUnlocked;
|
||||||
bool fModified;
|
bool fModified;
|
||||||
};
|
};
|
||||||
|
|||||||
Reference in New Issue
Block a user