1 /* create.c - Create a new crypto container
2 * Copyright (C) 2009 Free Software Foundation, Inc.
4 * This file is part of GnuPG.
6 * GnuPG is free software; you can redistribute it and/or modify
7 * it under the terms of the GNU General Public License as published by
8 * the Free Software Foundation; either version 3 of the License, or
9 * (at your option) any later version.
11 * GnuPG is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
14 * GNU General Public License for more details.
16 * You should have received a copy of the GNU General Public License
17 * along with this program; if not, see <https://www.gnu.org/licenses/>.
36 #include "../common/call-gpg.h"
38 /* Create a new blob with all the session keys and other meta
39 information which are to be stored encrypted in the crypto
40 container header. On success the malloced blob is stored at R_BLOB
41 and its length at R_BLOBLEN. On error an error code is returned
42 and (R_BLOB,R_BLOBLEN) are set to (NULL,0).
44 The format of this blob is a sequence of tag-length-value tuples.
45 All tuples have this format:
47 2 byte TAG Big endian unsigned integer (0..65535)
48 described by the KEYBLOB_TAG_ constants.
49 2 byte LENGTH Big endian unsigned integer (0..65535)
50 giving the length of the value.
51 length bytes VALUE The value described by the tag.
53 The first tag in a keyblob must be a BLOBVERSION. The other tags
54 depend on the type of the container as described by the CONTTYPE
55 tag. See keyblob.h for details. */
57 create_new_keyblob (ctrl_t ctrl, int is_detached,
58 void **r_blob, size_t *r_bloblen)
61 unsigned char twobyte[2];
67 init_membuf_secure (&mb, 512);
69 append_tuple (&mb, KEYBLOB_TAG_BLOBVERSION, "\x01", 1);
71 twobyte[0] = (ctrl->conttype >> 8);
72 twobyte[1] = (ctrl->conttype);
73 append_tuple (&mb, KEYBLOB_TAG_CONTTYPE, twobyte, 2);
75 append_tuple (&mb, KEYBLOB_TAG_DETACHED, NULL, 0);
77 err = be_create_new_keys (ctrl->conttype, &mb);
81 /* Just for testing. */
82 append_tuple (&mb, KEYBLOB_TAG_FILLER, "filler", 6);
84 *r_blob = get_membuf (&mb, r_bloblen);
87 err = gpg_error_from_syserror ();
91 log_debug ("used keyblob size is %zu\n", *r_bloblen);
94 xfree (get_membuf (&mb, NULL));
100 /* Encrypt the keyblob (KEYBLOB,KEYBLOBLEN) and store the result at
101 (R_ENCBLOB, R_ENCBLOBLEN). Returns 0 on success or an error code.
102 On error R_EKYBLOB is set to NULL. Depending on the keys set in
103 CTRL the result is a single OpenPGP binary message, a single
104 special OpenPGP packet encapsulating a CMS message or a
105 concatenation of both with the CMS packet being the last. */
107 g13_encrypt_keyblob (ctrl_t ctrl, void *keyblob, size_t keybloblen,
108 void **r_encblob, size_t *r_encbloblen)
112 /* FIXME: For now we only implement OpenPGP. */
113 err = gpg_encrypt_blob (ctrl, opt.gpg_program, opt.gpg_arguments,
116 r_encblob, r_encbloblen);
122 /* Write a new file under the name FILENAME with the keyblob and an
123 appropriate header. This function is called with a lock file in
124 place and after checking that the filename does not exists. */
126 write_keyblob (const char *filename,
127 const void *keyblob, size_t keybloblen)
131 unsigned char packet[32];
132 size_t headerlen, paddinglen;
134 fp = es_fopen (filename, "wbx");
137 err = gpg_error_from_syserror ();
138 log_error ("error creating new container '%s': %s\n",
139 filename, gpg_strerror (err));
143 /* Allow for an least 8 times larger keyblob to accommodate for
144 future key changes. Round it up to 4096 byte. */
145 headerlen = ((32 + 8 * keybloblen + 16) + 4095) / 4096 * 4096;
146 paddinglen = headerlen - 32 - keybloblen;
147 assert (paddinglen >= 16);
149 packet[0] = (0xc0|61); /* CTB for the private packet type 0x61. */
150 packet[1] = 0xff; /* 5 byte length packet, value 20. */
155 memcpy (packet+6, "GnuPG/G13", 10); /* Packet subtype. */
156 packet[16] = 1; /* G13 packet format version. */
157 packet[17] = 0; /* Reserved. */
158 packet[18] = 0; /* Reserved. */
159 packet[19] = 0; /* OS Flag. */
160 packet[20] = (headerlen >> 24); /* Total length of header. */
161 packet[21] = (headerlen >> 16);
162 packet[22] = (headerlen >> 8);
163 packet[23] = (headerlen);
164 packet[24] = 1; /* Number of header copies. */
165 packet[25] = 0; /* Number of header copies at the end. */
166 packet[26] = 0; /* Reserved. */
167 packet[27] = 0; /* Reserved. */
168 packet[28] = 0; /* Reserved. */
169 packet[29] = 0; /* Reserved. */
170 packet[30] = 0; /* Reserved. */
171 packet[31] = 0; /* Reserved. */
173 if (es_fwrite (packet, 32, 1, fp) != 1)
176 if (es_fwrite (keyblob, keybloblen, 1, fp) != 1)
179 /* Write the padding. */
180 packet[0] = (0xc0|61); /* CTB for Private packet type 0x61. */
181 packet[1] = 0xff; /* 5 byte length packet, value 20. */
182 packet[2] = (paddinglen-6) >> 24;
183 packet[3] = (paddinglen-6) >> 16;
184 packet[4] = (paddinglen-6) >> 8;
185 packet[5] = (paddinglen-6);
186 memcpy (packet+6, "GnuPG/PAD", 10); /* Packet subtype. */
187 if (es_fwrite (packet, 16, 1, fp) != 1)
189 memset (packet, 0, 32);
190 for (paddinglen-=16; paddinglen >= 32; paddinglen -= 32)
191 if (es_fwrite (packet, 32, 1, fp) != 1)
194 if (es_fwrite (packet, paddinglen, 1, fp) != 1)
199 err = gpg_error_from_syserror ();
200 log_error ("error closing '%s': %s\n",
201 filename, gpg_strerror (err));
210 err = gpg_error_from_syserror ();
211 log_error ("error writing header to '%s': %s\n",
212 filename, gpg_strerror (err));
220 /* Create a new container under the name FILENAME and intialize it
221 using the current settings. If the file already exists an error is
224 g13_create_container (ctrl_t ctrl, const char *filename)
228 void *keyblob = NULL;
230 void *enckeyblob = NULL;
231 size_t enckeybloblen;
232 char *detachedname = NULL;
234 tupledesc_t tuples = NULL;
235 unsigned int dummy_rid;
237 if (!ctrl->recipients)
238 return gpg_error (GPG_ERR_NO_PUBKEY);
240 err = be_take_lock_for_create (ctrl, filename, &lock);
244 /* And a possible detached file or directory may not exist either. */
245 err = be_get_detached_name (ctrl->conttype, filename,
246 &detachedname, &detachedisdir);
253 if (!stat (detachedname, &sb))
255 err = gpg_error (GPG_ERR_EEXIST);
260 if (ctrl->conttype != CONTTYPE_DM_CRYPT)
262 /* Create a new keyblob. */
263 err = create_new_keyblob (ctrl, !!detachedname, &keyblob, &keybloblen);
267 /* Encrypt that keyblob. */
268 err = g13_encrypt_keyblob (ctrl, keyblob, keybloblen,
269 &enckeyblob, &enckeybloblen);
273 /* Put a copy of the keyblob into a tuple structure. */
274 err = create_tupledesc (&tuples, keyblob, keybloblen);
278 /* if (opt.verbose) */
279 /* dump_keyblob (tuples); */
281 /* Write out the header, the encrypted keyblob and some padding. */
282 err = write_keyblob (filename, enckeyblob, enckeybloblen);
287 /* Create and append the container. FIXME: We should pass the
288 estream object in addition to the filename, so that the backend
289 can append the container to the g13 file. */
290 err = be_create_container (ctrl, ctrl->conttype, filename, -1, tuples,
295 destroy_tupledesc (tuples);
296 xfree (detachedname);
299 dotlock_destroy (lock);