.
[gnupg.git] / tools / gpgsm-gencert.sh
index ec5025b..ea96bb2 100755 (executable)
@@ -1,7 +1,7 @@
 #!/bin/sh
 #                                                              -*- sh -*-
 # gpgsm-gencert.c - Generate X.509 certificates through GPGSM.  
-#      Copyright (C) 2004 Free Software Foundation, Inc.
+#      Copyright (C) 2004, 2005 Free Software Foundation, Inc.
 #
 # This file is part of GnuPG.
 #
@@ -84,34 +84,118 @@ query_user_menu()
     echo "You selected: $ANSWER" >&2
 }
 
-query_user_menu "Key type" "RSA"
-KEY_TYPE=$ANSWER
 
-query_user_menu "Key length" "1024" "2048"
-KEY_LENGTH=$ANSWER
+
+KEY_TYPE=""
+while [ -z "$KEY_TYPE" ]; do
+  query_user_menu "Key type" "RSA" "Existing key" "Direct from card"
+  case "$ANSWER" in
+    RSA)
+      KEY_TYPE=$ANSWER
+      query_user_menu "Key length" "1024" "2048"
+      KEY_LENGTH=$ANSWER
+      KEY_GRIP=
+      ;;
+    Existing*)
+      # User requested to use an existing key; need to set some dummy defaults
+      query_user "Keygrip "
+      if [ -n "$ANSWER" ]; then
+        KEY_TYPE=RSA 
+        KEY_LENGTH=1024
+        KEY_GRIP=$ANSWER
+      fi
+      ;;
+    Direct*)
+      tmp=$(echo 'SCD SERIALNO' | gpg-connect-agent | \
+            awk '$2 == "SERIALNO" {print $3}') 
+      if [ -z "$tmp" ]; then
+          echo "No card found" >&2
+      else
+        echo "Card with S/N $tmp found" >&2
+        tmp=$(echo 'SCD LEARN --force' | gpg-connect-agent | \
+              awk '$2 == "KEYPAIRINFO" {printf " %s", $4}')
+        sshid=$(echo 'SCD GETATTR $AUTHKEYID' | gpg-connect-agent | \
+                awk '$2 == "$AUTHKEYID" {print $3}') 
+        [ -n "$sshid" ] && echo "gpg-agent uses $sshid as ssh key" >&2
+        query_user_menu "Select key " $tmp "back"
+        if [ "$ANSWER" != "back" ]; then
+          KEY_TYPE="card:$ANSWER"
+          KEY_LENGTH=
+          KEY_GRIP=
+        fi
+      fi
+      ;;
+    *)
+      exit 1
+      ;;   
+  esac
+done
 
 query_user_menu "Key usage" "sign, encrypt" "sign" "encrypt"
 KEY_USAGE=$ANSWER
 
-query_user "Name"
+query_user "Name (DN)"
 NAME=$ANSWER
 
-query_user "E-Mail address"
-EMAIL_ADDRESS=$ANSWER
+EMAIL_ADDRESSES=
+LF=
+while : ; do
+  query_user "E-Mail addresses (end with an empty line)"
+  [ -z "$ANSWER" ] && break
+  EMAIL_ADDRESSES="${EMAIL_ADDRESSES}${LF}Name-Email: $ANSWER"
+  LF='
+'
+done
+
+DNS_ADDRESSES=
+LF=
+while : ; do
+  query_user "DNS Names (optional; end with an empty line)"
+  [ -z "$ANSWER" ] && break
+  DNS_ADDRESSES="${DNS_ADDRESSES}${LF}Name-DNS: $ANSWER"
+  LF='
+'
+done
+
+URI_ADDRESSES=
+LF=
+while : ; do
+  query_user "URIs (optional; end with an empty line)"
+  [ -z "$ANSWER" ] && break
+  URI_ADDRESSES="${URI_ADDRESSES}${LF}Name-URI: $ANSWER"
+  LF='
+'
+done
 
 file_parameter=$(mktemp "/tmp/gpgsm.XXXXXX")
 outfile=$(mktemp "/tmp/gpgsm.XXXXXX")
 
-cat > "$file_parameter" <<EOF
+
+(
+cat <<EOF
 Key-Type: $KEY_TYPE
 Key-Length: $KEY_LENGTH
 Key-Usage: $KEY_USAGE
 Name-DN: $NAME
-Name-Email: $EMAIL_ADDRESS
 EOF
+[ -n "$KEY_GRIP" ] && echo "Key-Grip: $KEY_GRIP"
+[ -n "$EMAIL_ADDRESSES" ] && echo "$EMAIL_ADDRESSES"
+[ -n "$DNS_ADDRESSES" ] && echo "$DNS_ADDRESSES"
+[ -n "$URI_ADDRESSES" ] && echo "$URI_ADDRESSES"
+) > "$file_parameter"
+
+
+echo 'Parameters for certificate request to create:' >&2
+cat -n "$file_parameter" >&2
+echo  >&2
+
+query_user_menu "Really create such a CSR?" "yes" "no"
+[ "$ANSWER" != "yes" ] && exit 1
+    
 
 echo -e "$ASSUAN_COMMANDS" | \
-   gpgsm --server 4< "$file_parameter" 5>"$outfile" >/dev/null
+     gpgsm --no-log-file --debug-level none --debug-none \
+           --server 4< "$file_parameter" 5>"$outfile" >/dev/null
 
 cat "$outfile"