X-Git-Url: https://git.carlh.net/gitweb/?a=blobdiff_plain;f=src%2Fcertificate_chain.h;h=9d7ab47c1cf6e676f374a2a78b626ceaaec5dc08;hb=refs%2Fheads%2F1.0-templates;hp=b4cc24851f93ac994230550ca91288e9cd306a1c;hpb=0f09e4f7335fb125273aa3d1dc397797a2eba1dd;p=libdcp.git diff --git a/src/certificate_chain.h b/src/certificate_chain.h index b4cc2485..9d7ab47c 100644 --- a/src/certificate_chain.h +++ b/src/certificate_chain.h @@ -1,20 +1,34 @@ /* - Copyright (C) 2013-2015 Carl Hetherington + Copyright (C) 2013-2016 Carl Hetherington - This program is free software; you can redistribute it and/or modify + This file is part of libdcp. + + libdcp is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version. - This program is distributed in the hope that it will be useful, + libdcp is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. You should have received a copy of the GNU General Public License - along with this program; if not, write to the Free Software - Foundation, Inc., 675 Mass Ave, Cambridge, MA 02139, USA. - + along with libdcp. If not, see . + + In addition, as a special exception, the copyright holders give + permission to link the code of portions of this program with the + OpenSSL library under certain conditions as described in each + individual source file, and distribute linked combinations + including the two. + + You must obey the GNU General Public License in all respects + for all of the code used other than OpenSSL. If you modify + file(s) with this exception, you may extend this exception to your + version of the file(s), but you are not obligated to do so. If you + do not wish to do so, delete this exception statement from your + version. If you delete this exception statement from all source + files in the program, then also delete it here. */ /** @file src/signer_chain.h @@ -25,7 +39,13 @@ #define LIBDCP_CERTIFICATE_CHAIN_H #include "certificate.h" +#include "types.h" #include +#include + +namespace xmlpp { + class Node; +} namespace dcp { @@ -37,6 +57,25 @@ class CertificateChain public: CertificateChain () {} + /** Create a chain of certificates for signing things. + * @param openssl Name of openssl binary (if it is on the path) or full path. + * @return Directory (which should be deleted by the caller) containing: + * - ca.self-signed.pem self-signed root certificate + * - intermediate.signed.pem intermediate certificate + * - leaf.key leaf certificate private key + * - leaf.signed.pem leaf certificate + */ + CertificateChain ( + boost::filesystem::path openssl, + std::string organisation = "example.org", + std::string organisational_unit = "example.org", + std::string root_common_name = ".smpte-430-2.ROOT.NOT_FOR_PRODUCTION", + std::string intermediate_common_name = ".smpte-430-2.INTERMEDIATE.NOT_FOR_PRODUCTION", + std::string leaf_common_name = "CS.smpte-430-2.LEAF.NOT_FOR_PRODUCTION" + ); + + explicit CertificateChain (std::string); + void add (Certificate c); void remove (Certificate c); void remove (int); @@ -52,29 +91,27 @@ public: bool valid () const; bool attempt_reorder (); + void sign (xmlpp::Element* parent, Standard standard) const; + void add_signature_value (xmlpp::Node* parent, std::string ns) const; + + boost::optional key () const { + return _key; + } + + void set_key (std::string k) { + _key = k; + } + + std::string chain () const; + private: friend class ::certificates; List _certificates; + /** Leaf certificate's private key, if known */ + boost::optional _key; }; -/** Create a chain of certificates for signing things. - * @param openssl Name of openssl binary (if it is on the path) or full path. - * @return Directory (which should be deleted by the caller) containing: - * - ca.self-signed.pem self-signed root certificate - * - intermediate.signed.pem intermediate certificate - * - leaf.key leaf certificate private key - * - leaf.signed.pem leaf certificate - */ -boost::filesystem::path make_certificate_chain ( - boost::filesystem::path openssl, - std::string organisation = "example.org", - std::string organisational_unit = "example.org", - std::string root_common_name = ".smpte-430-2.ROOT.NOT_FOR_PRODUCTION", - std::string intermediate_common_name = ".smpte-430-2.INTERMEDIATE.NOT_FOR_PRODUCTION", - std::string leaf_common_name = "CS.smpte-430-2.LEAF.NOT_FOR_PRODUCTION" - ); - } #endif