2 * Copyright (C) 2004, 2005, 2007, 2009 Internet Systems Consortium, Inc. ("ISC")
3 * Copyright (C) 2001 Internet Software Consortium.
5 * Permission to use, copy, modify, and/or distribute this software for any
6 * purpose with or without fee is hereby granted, provided that the above
7 * copyright notice and this permission notice appear in all copies.
9 * THE SOFTWARE IS PROVIDED "AS IS" AND ISC DISCLAIMS ALL WARRANTIES WITH
10 * REGARD TO THIS SOFTWARE INCLUDING ALL IMPLIED WARRANTIES OF MERCHANTABILITY
11 * AND FITNESS. IN NO EVENT SHALL ISC BE LIABLE FOR ANY SPECIAL, DIRECT,
12 * INDIRECT, OR CONSEQUENTIAL DAMAGES OR ANY DAMAGES WHATSOEVER RESULTING FROM
13 * LOSS OF USE, DATA OR PROFITS, WHETHER IN AN ACTION OF CONTRACT, NEGLIGENCE
14 * OR OTHER TORTIOUS ACTION, ARISING OUT OF OR IN CONNECTION WITH THE USE OR
15 * PERFORMANCE OF THIS SOFTWARE.
18 /* $Id: keycreate.c,v 1.18 2009/09/01 00:22:25 jinmei Exp $ */
26 #include <isc/base64.h>
27 #include <isc/entropy.h>
31 #include <isc/sockaddr.h>
32 #include <isc/socket.h>
34 #include <isc/timer.h>
37 #include <dns/dispatch.h>
38 #include <dns/fixedname.h>
39 #include <dns/keyvalues.h>
40 #include <dns/message.h>
42 #include <dns/request.h>
43 #include <dns/result.h>
48 #include <dst/result.h>
50 #define CHECK(str, x) { \
51 if ((x) != ISC_R_SUCCESS) { \
52 fprintf(stderr, "I:%s: %s\n", (str), isc_result_totext(x)); \
57 #define RUNCHECK(x) RUNTIME_CHECK((x) == ISC_R_SUCCESS)
62 static dst_key_t *ourkey;
63 static isc_mem_t *mctx;
64 static dns_tsigkey_t *tsigkey, *initialkey;
65 static dns_tsig_keyring_t *ring;
66 static unsigned char noncedata[16];
67 static isc_buffer_t nonce;
68 static dns_requestmgr_t *requestmgr;
69 static const char *ownername_str = ".";
72 recvquery(isc_task_t *task, isc_event_t *event) {
73 dns_requestevent_t *reqev = (dns_requestevent_t *)event;
75 dns_message_t *query, *response;
77 isc_buffer_t keynamebuf;
82 REQUIRE(reqev != NULL);
84 if (reqev->result != ISC_R_SUCCESS) {
85 fprintf(stderr, "I:request event result: %s\n",
86 isc_result_totext(reqev->result));
90 query = reqev->ev_arg;
93 result = dns_message_create(mctx, DNS_MESSAGE_INTENTPARSE, &response);
94 CHECK("dns_message_create", result);
96 result = dns_request_getresponse(reqev->request, response,
97 DNS_MESSAGEPARSE_PRESERVEORDER);
98 CHECK("dns_request_getresponse", result);
100 if (response->rcode != dns_rcode_noerror) {
101 result = ISC_RESULTCLASS_DNSRCODE + response->rcode;
102 fprintf(stderr, "I:response rcode: %s\n",
103 isc_result_totext(result));
107 result = dns_tkey_processdhresponse(query, response, ourkey, &nonce,
109 CHECK("dns_tkey_processdhresponse", result);
112 * Yes, this is a hack.
114 isc_buffer_init(&keynamebuf, keyname, sizeof(keyname));
115 result = dst_key_buildfilename(tsigkey->key, 0, "", &keynamebuf);
116 CHECK("dst_key_buildfilename", result);
117 printf("%.*s\n", (int)isc_buffer_usedlength(&keynamebuf),
118 (char *)isc_buffer_base(&keynamebuf));
119 type = DST_TYPE_PRIVATE | DST_TYPE_PUBLIC | DST_TYPE_KEY;
120 result = dst_key_tofile(tsigkey->key, type, "");
121 CHECK("dst_key_tofile", result);
123 dns_message_destroy(&query);
124 dns_message_destroy(&response);
125 dns_request_destroy(&reqev->request);
126 isc_event_free(&event);
132 sendquery(isc_task_t *task, isc_event_t *event) {
133 struct in_addr inaddr;
134 isc_sockaddr_t address;
137 dns_fixedname_t keyname;
138 dns_fixedname_t ownername;
139 isc_buffer_t namestr, keybuf;
140 unsigned char keydata[9];
141 dns_message_t *query;
142 dns_request_t *request;
143 static char keystr[] = "0123456789ab";
145 isc_event_free(&event);
147 result = ISC_R_FAILURE;
148 if (inet_pton(AF_INET, "10.53.0.1", &inaddr) != 1)
149 CHECK("inet_pton", result);
150 isc_sockaddr_fromin(&address, &inaddr, PORT);
152 dns_fixedname_init(&keyname);
153 isc_buffer_init(&namestr, "tkeytest.", 9);
154 isc_buffer_add(&namestr, 9);
155 result = dns_name_fromtext(dns_fixedname_name(&keyname), &namestr,
157 CHECK("dns_name_fromtext", result);
159 dns_fixedname_init(&ownername);
160 isc_buffer_init(&namestr, ownername_str, strlen(ownername_str));
161 isc_buffer_add(&namestr, strlen(ownername_str));
162 result = dns_name_fromtext(dns_fixedname_name(&ownername), &namestr,
164 CHECK("dns_name_fromtext", result);
166 isc_buffer_init(&keybuf, keydata, 9);
167 result = isc_base64_decodestring(keystr, &keybuf);
168 CHECK("isc_base64_decodestring", result);
170 isc_buffer_usedregion(&keybuf, &r);
173 result = dns_tsigkey_create(dns_fixedname_name(&keyname),
174 DNS_TSIG_HMACMD5_NAME,
175 isc_buffer_base(&keybuf),
176 isc_buffer_usedlength(&keybuf),
177 ISC_FALSE, NULL, 0, 0, mctx, ring,
179 CHECK("dns_tsigkey_create", result);
182 result = dns_message_create(mctx, DNS_MESSAGE_INTENTRENDER, &query);
183 CHECK("dns_message_create", result);
185 result = dns_tkey_builddhquery(query, ourkey,
186 dns_fixedname_name(&ownername),
187 DNS_TSIG_HMACMD5_NAME, &nonce, 3600);
188 CHECK("dns_tkey_builddhquery", result);
191 result = dns_request_create(requestmgr, query, &address,
192 0, initialkey, TIMEOUT, task,
193 recvquery, query, &request);
194 CHECK("dns_request_create", result);
198 main(int argc, char *argv[]) {
200 isc_taskmgr_t *taskmgr;
201 isc_timermgr_t *timermgr;
202 isc_socketmgr_t *socketmgr;
204 unsigned int attrs, attrmask;
205 isc_sockaddr_t bind_any;
206 dns_dispatchmgr_t *dispatchmgr;
207 dns_dispatch_t *dispatchv4;
212 isc_logconfig_t *logconfig;
217 RUNCHECK(isc_app_start());
220 fprintf(stderr, "I:no DH key provided\n");
223 ourkeyname = argv[1];
226 ownername_str = argv[2];
228 dns_result_register();
231 RUNCHECK(isc_mem_create(0, 0, &mctx));
234 RUNCHECK(isc_entropy_create(mctx, &ectx));
235 RUNCHECK(isc_entropy_createfilesource(ectx, "random.data"));
236 RUNCHECK(isc_hash_create(mctx, ectx, DNS_NAME_MAXWIRE));
240 RUNCHECK(isc_log_create(mctx, &log, &logconfig));
242 RUNCHECK(dst_lib_init(mctx, ectx, ISC_ENTROPY_GOODONLY));
245 RUNCHECK(isc_taskmgr_create(mctx, 1, 0, &taskmgr));
247 RUNCHECK(isc_task_create(taskmgr, 0, &task));
249 RUNCHECK(isc_timermgr_create(mctx, &timermgr));
251 RUNCHECK(isc_socketmgr_create(mctx, &socketmgr));
253 RUNCHECK(dns_dispatchmgr_create(mctx, NULL, &dispatchmgr));
254 isc_sockaddr_any(&bind_any);
255 attrs = DNS_DISPATCHATTR_UDP |
256 DNS_DISPATCHATTR_MAKEQUERY |
257 DNS_DISPATCHATTR_IPV4;
258 attrmask = DNS_DISPATCHATTR_UDP |
259 DNS_DISPATCHATTR_TCP |
260 DNS_DISPATCHATTR_IPV4 |
261 DNS_DISPATCHATTR_IPV6;
263 RUNCHECK(dns_dispatch_getudp(dispatchmgr, socketmgr, taskmgr,
264 &bind_any, 4096, 4, 2, 3, 5,
265 attrs, attrmask, &dispatchv4));
267 RUNCHECK(dns_requestmgr_create(mctx, timermgr, socketmgr, taskmgr,
268 dispatchmgr, dispatchv4, NULL,
272 RUNCHECK(dns_tsigkeyring_create(mctx, &ring));
274 RUNCHECK(dns_tkeyctx_create(mctx, ectx, &tctx));
277 RUNCHECK(dns_view_create(mctx, 0, "_test", &view));
278 dns_view_setkeyring(view, ring);
281 RUNCHECK(isc_socket_create(socketmgr, PF_INET, isc_sockettype_udp,
284 RUNCHECK(isc_app_onrun(mctx, task, sendquery, NULL));
287 type = DST_TYPE_PUBLIC | DST_TYPE_PRIVATE | DST_TYPE_KEY;
288 result = dst_key_fromnamedfile(ourkeyname, NULL, type, mctx, &ourkey);
289 CHECK("dst_key_fromnamedfile", result);
291 isc_buffer_init(&nonce, noncedata, sizeof(noncedata));
292 result = isc_entropy_getdata(ectx, noncedata, sizeof(noncedata),
293 NULL, ISC_ENTROPY_BLOCKING);
294 CHECK("isc_entropy_getdata", result);
295 isc_buffer_add(&nonce, sizeof(noncedata));
299 dns_requestmgr_shutdown(requestmgr);
300 dns_requestmgr_detach(&requestmgr);
301 dns_dispatch_detach(&dispatchv4);
302 dns_dispatchmgr_destroy(&dispatchmgr);
303 isc_task_shutdown(task);
304 isc_task_detach(&task);
305 isc_taskmgr_destroy(&taskmgr);
306 isc_socket_detach(&sock);
307 isc_socketmgr_destroy(&socketmgr);
308 isc_timermgr_destroy(&timermgr);
310 dst_key_free(&ourkey);
311 dns_tsigkey_detach(&initialkey);
312 dns_tsigkey_detach(&tsigkey);
314 dns_tkeyctx_destroy(&tctx);
316 dns_view_detach(&view);
318 isc_log_destroy(&log);
322 isc_entropy_detach(&ectx);
324 isc_mem_destroy(&mctx);