gencertbuf.pl 7.9 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246
  1. #!/usr/bin/perl
  2. # gencertbuf.pl
  3. # version 1.1
  4. # Updated 07/01/2014
  5. #
  6. # Copyright (C) 2006-2015 wolfSSL Inc.
  7. #
  8. use strict;
  9. use warnings;
  10. # ---- SCRIPT SETTINGS -------------------------------------------------------
  11. # output C header file to write cert/key buffers to
  12. my $outputFile = "./wolfssl/certs_test.h";
  13. # ecc keys and certs to be converted
  14. # Used with HAVE_ECC && USE_CERT_BUFFERS_256
  15. my @fileList_ecc = (
  16. [ "./certs/ecc-client-key.der", "ecc_clikey_der_256" ],
  17. [ "./certs/ecc-client-keyPub.der", "ecc_clikeypub_der_256" ],
  18. [ "./certs/client-ecc-cert.der", "cliecc_cert_der_256" ],
  19. [ "./certs/ecc-key.der", "ecc_key_der_256" ],
  20. [ "./certs/ecc-keyPub.der", "ecc_key_pub_der_256" ],
  21. [ "./certs/server-ecc-comp.der", "serv_ecc_comp_der_256" ],
  22. [ "./certs/server-ecc-rsa.der", "serv_ecc_rsa_der_256" ],
  23. [ "./certs/server-ecc.der", "serv_ecc_der_256" ],
  24. [ "./certs/ca-ecc-key.der", "ca_ecc_key_der_256" ],
  25. [ "./certs/ca-ecc-cert.der", "ca_ecc_cert_der_256" ],
  26. [ "./certs/ca-ecc384-key.der", "ca_ecc_key_der_384" ],
  27. [ "./certs/ca-ecc384-cert.der", "ca_ecc_cert_der_384" ]
  28. );
  29. # ed25519 keys and certs
  30. # Used with HAVE_ED25519 define.
  31. my @fileList_ed = (
  32. [ "./certs/ed25519/server-ed25519.der", "server_ed25519_cert" ],
  33. [ "./certs/ed25519/ca-ed25519.der", "ca_ed25519_cert" ]
  34. );
  35. # 1024-bit certs/keys to be converted
  36. # Used with USE_CERT_BUFFERS_1024 define.
  37. my @fileList_1024 = (
  38. [ "./certs/1024/client-key.der", "client_key_der_1024" ],
  39. [ "./certs/1024/client-keyPub.der", "client_keypub_der_1024" ],
  40. [ "./certs/1024/client-cert.der", "client_cert_der_1024" ],
  41. [ "./certs/1024/dh1024.der", "dh_key_der_1024" ],
  42. [ "./certs/1024/dsa1024.der", "dsa_key_der_1024" ],
  43. [ "./certs/1024/rsa1024.der", "rsa_key_der_1024" ],
  44. [ "./certs/1024/ca-key.der", "ca_key_der_1024"],
  45. [ "./certs/1024/ca-cert.der", "ca_cert_der_1024" ],
  46. [ "./certs/1024/server-key.der", "server_key_der_1024" ],
  47. [ "./certs/1024/server-cert.der", "server_cert_der_1024" ]
  48. );
  49. # 2048-bit certs/keys to be converted
  50. # Used with USE_CERT_BUFFERS_2048 define.
  51. my @fileList_2048 = (
  52. [ "./certs/client-key.der", "client_key_der_2048" ],
  53. [ "./certs/client-keyPub.der", "client_keypub_der_2048" ],
  54. [ "./certs/client-cert.der", "client_cert_der_2048" ],
  55. [ "./certs/dh2048.der", "dh_key_der_2048" ],
  56. [ "./certs/dsa2048.der", "dsa_key_der_2048" ],
  57. [ "./certs/rsa2048.der", "rsa_key_der_2048" ],
  58. [ "./certs/ca-key.der", "ca_key_der_2048" ],
  59. [ "./certs/ca-cert.der", "ca_cert_der_2048" ],
  60. [ "./certs/ca-cert-chain.der", "ca_cert_chain_der" ],
  61. [ "./certs/server-key.der", "server_key_der_2048" ],
  62. [ "./certs/server-cert.der", "server_cert_der_2048" ]
  63. );
  64. my @fileList_3072 = (
  65. [ "./certs/dh3072.der", "dh_key_der_3072" ],
  66. [ "./certs/dsa3072.der", "dsa_key_der_3072" ],
  67. [ "./certs/rsa3072.der", "rsa_key_der_3072" ],
  68. );
  69. # ----------------------------------------------------------------------------
  70. my $num_ecc = @fileList_ecc;
  71. my $num_ed = @fileList_ed;
  72. my $num_1024 = @fileList_1024;
  73. my $num_2048 = @fileList_2048;
  74. my $num_3072 = @fileList_3072;
  75. # open our output file, "+>" creates and/or truncates
  76. open OUT_FILE, "+>", $outputFile or die $!;
  77. print OUT_FILE "/* certs_test.h */\n\n";
  78. print OUT_FILE "#ifndef WOLFSSL_CERTS_TEST_H\n";
  79. print OUT_FILE "#define WOLFSSL_CERTS_TEST_H\n\n";
  80. # convert and print 1024-bit cert/keys
  81. print OUT_FILE "#ifdef USE_CERT_BUFFERS_1024\n\n";
  82. for (my $i = 0; $i < $num_1024; $i++) {
  83. my $fname = $fileList_1024[$i][0];
  84. my $sname = $fileList_1024[$i][1];
  85. print OUT_FILE "/* $fname, 1024-bit */\n";
  86. print OUT_FILE "static const unsigned char $sname\[] =\n";
  87. print OUT_FILE "{\n";
  88. file_to_hex($fname);
  89. print OUT_FILE "};\n";
  90. print OUT_FILE "static const int sizeof_$sname = sizeof($sname);\n\n";
  91. }
  92. print OUT_FILE "#endif /* USE_CERT_BUFFERS_1024 */\n\n";
  93. # convert and print 2048-bit certs/keys
  94. print OUT_FILE "#ifdef USE_CERT_BUFFERS_2048\n\n";
  95. for (my $i = 0; $i < $num_2048; $i++) {
  96. my $fname = $fileList_2048[$i][0];
  97. my $sname = $fileList_2048[$i][1];
  98. print OUT_FILE "/* $fname, 2048-bit */\n";
  99. print OUT_FILE "static const unsigned char $sname\[] =\n";
  100. print OUT_FILE "{\n";
  101. file_to_hex($fname);
  102. print OUT_FILE "};\n";
  103. print OUT_FILE "static const int sizeof_$sname = sizeof($sname);\n\n";
  104. }
  105. print OUT_FILE "#endif /* USE_CERT_BUFFERS_2048 */\n\n";
  106. # convert and print 3072-bit certs/keys
  107. print OUT_FILE "#ifdef USE_CERT_BUFFERS_3072\n\n";
  108. for (my $i = 0; $i < $num_3072; $i++) {
  109. my $fname = $fileList_3072[$i][0];
  110. my $sname = $fileList_3072[$i][1];
  111. print OUT_FILE "/* $fname, 3072-bit */\n";
  112. print OUT_FILE "static const unsigned char $sname\[] =\n";
  113. print OUT_FILE "{\n";
  114. file_to_hex($fname);
  115. print OUT_FILE "};\n";
  116. print OUT_FILE "static const int sizeof_$sname = sizeof($sname);\n\n";
  117. }
  118. print OUT_FILE "#endif /* USE_CERT_BUFFERS_3072 */\n\n";
  119. # convert and print 256-bit cert/keys
  120. print OUT_FILE "#if defined(HAVE_ECC) && defined(USE_CERT_BUFFERS_256)\n\n";
  121. for (my $i = 0; $i < $num_ecc; $i++) {
  122. my $fname = $fileList_ecc[$i][0];
  123. my $sname = $fileList_ecc[$i][1];
  124. print OUT_FILE "/* $fname, ECC */\n";
  125. print OUT_FILE "static const unsigned char $sname\[] =\n";
  126. print OUT_FILE "{\n";
  127. file_to_hex($fname);
  128. print OUT_FILE "};\n";
  129. print OUT_FILE "static const int sizeof_$sname = sizeof($sname);\n\n";
  130. }
  131. print OUT_FILE "#endif /* HAVE_ECC && USE_CERT_BUFFERS_256 */\n\n";
  132. print OUT_FILE "/* dh1024 p */
  133. static const unsigned char dh_p[] =
  134. {
  135. 0xE6, 0x96, 0x9D, 0x3D, 0x49, 0x5B, 0xE3, 0x2C, 0x7C, 0xF1, 0x80, 0xC3,
  136. 0xBD, 0xD4, 0x79, 0x8E, 0x91, 0xB7, 0x81, 0x82, 0x51, 0xBB, 0x05, 0x5E,
  137. 0x2A, 0x20, 0x64, 0x90, 0x4A, 0x79, 0xA7, 0x70, 0xFA, 0x15, 0xA2, 0x59,
  138. 0xCB, 0xD5, 0x23, 0xA6, 0xA6, 0xEF, 0x09, 0xC4, 0x30, 0x48, 0xD5, 0xA2,
  139. 0x2F, 0x97, 0x1F, 0x3C, 0x20, 0x12, 0x9B, 0x48, 0x00, 0x0E, 0x6E, 0xDD,
  140. 0x06, 0x1C, 0xBC, 0x05, 0x3E, 0x37, 0x1D, 0x79, 0x4E, 0x53, 0x27, 0xDF,
  141. 0x61, 0x1E, 0xBB, 0xBE, 0x1B, 0xAC, 0x9B, 0x5C, 0x60, 0x44, 0xCF, 0x02,
  142. 0x3D, 0x76, 0xE0, 0x5E, 0xEA, 0x9B, 0xAD, 0x99, 0x1B, 0x13, 0xA6, 0x3C,
  143. 0x97, 0x4E, 0x9E, 0xF1, 0x83, 0x9E, 0xB5, 0xDB, 0x12, 0x51, 0x36, 0xF7,
  144. 0x26, 0x2E, 0x56, 0xA8, 0x87, 0x15, 0x38, 0xDF, 0xD8, 0x23, 0xC6, 0x50,
  145. 0x50, 0x85, 0xE2, 0x1F, 0x0D, 0xD5, 0xC8, 0x6B,
  146. };
  147. /* dh1024 g */
  148. static const unsigned char dh_g[] =
  149. {
  150. 0x02,
  151. };\n\n";
  152. # convert and print ed25519 cert/keys
  153. print OUT_FILE "#if defined(HAVE_ED25519)\n\n";
  154. for (my $i = 0; $i < $num_ed; $i++) {
  155. my $fname = $fileList_ed[$i][0];
  156. my $sname = $fileList_ed[$i][1];
  157. print OUT_FILE "/* $fname, ED25519 */\n";
  158. print OUT_FILE "static const unsigned char $sname\[] =\n";
  159. print OUT_FILE "{\n";
  160. file_to_hex($fname);
  161. print OUT_FILE "};\n";
  162. print OUT_FILE "static const int sizeof_$sname = sizeof($sname);\n\n";
  163. }
  164. print OUT_FILE "#endif /* HAVE_ED25519 */\n\n";
  165. print OUT_FILE "#endif /* WOLFSSL_CERTS_TEST_H */\n\n";
  166. # close certs_test.h file
  167. close OUT_FILE or die $!;
  168. # print file as hex, comma-separated, as needed by C buffer
  169. sub file_to_hex {
  170. my $fileName = $_[0];
  171. open my $fp, "<", $fileName or die $!;
  172. binmode($fp);
  173. my $fileLen = -s $fileName;
  174. my $byte;
  175. for (my $i = 0, my $j = 1; $i < $fileLen; $i++, $j++)
  176. {
  177. if ($j == 1) {
  178. print OUT_FILE "\t";
  179. }
  180. read($fp, $byte, 1) or die "Error reading $fileName";
  181. my $output = sprintf("0x%02X", ord($byte));
  182. print OUT_FILE $output;
  183. if ($i != ($fileLen - 1)) {
  184. print OUT_FILE ", ";
  185. }
  186. if ($j == 10) {
  187. $j = 0;
  188. print OUT_FILE "\n";
  189. }
  190. }
  191. print OUT_FILE "\n";
  192. close($fp);
  193. }