2 * Copyright (c) 2000 - 2015 Samsung Electronics Co., Ltd All Rights Reserved
4 * Licensed under the Apache License, Version 2.0 (the "License");
5 * you may not use this file except in compliance with the License.
6 * You may obtain a copy of the License at
8 * http://www.apache.org/licenses/LICENSE-2.0
10 * Unless required by applicable law or agreed to in writing, software
11 * distributed under the License is distributed on an "AS IS" BASIS,
12 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
13 * See the License for the specific language governing permissions and
14 * limitations under the License
17 * @file ckm-service.cpp
18 * @author Bartlomiej Grzelewski (b.grzelewski@samsung.com)
20 * @brief CKM service implementation.
23 #include <protocols.h>
25 #include <dpl/serialization.h>
26 #include <dpl/log/log.h>
28 #include <ckm-service.h>
29 #include <ckm-logic.h>
32 const CKM::InterfaceID SOCKET_ID_CONTROL = 0;
33 const CKM::InterfaceID SOCKET_ID_STORAGE = 1;
34 } // namespace anonymous
38 CKMService::CKMService()
39 : m_logic(new CKMLogic)
42 CKMService::~CKMService() {
46 void CKMService::Start() {
50 void CKMService::Stop() {
54 GenericSocketService::ServiceDescriptionVector CKMService::GetServiceDescription()
56 return ServiceDescriptionVector {
57 {SERVICE_SOCKET_CKM_CONTROL, "http://tizen.org/privilege/keymanager.admin", SOCKET_ID_CONTROL},
58 {SERVICE_SOCKET_CKM_STORAGE, "http://tizen.org/privilege/keymanager", SOCKET_ID_STORAGE}
62 void CKMService::SetCommManager(CommMgr *manager)
64 ThreadService::SetCommManager(manager);
68 // CKMService does not support security check
69 // so 3rd parameter is not used
70 bool CKMService::ProcessOne(
71 const ConnectionID &conn,
75 LogDebug ("process One");
79 if (!info.buffer.Ready())
82 if (info.interfaceID == SOCKET_ID_CONTROL)
83 response = ProcessControl(info.buffer);
85 response = ProcessStorage(info.credentials, info.buffer);
87 m_serviceManager->Write(conn, response);
90 } Catch (MessageBuffer::Exception::Base) {
91 LogError("Broken protocol. Closing socket.");
92 } Catch (Exception::BrokenProtocol) {
93 LogError("Broken protocol. Closing socket.");
94 } catch (const DataType::Exception::Base &e) {
95 LogError("Closing socket. DBDataType::Exception: " << e.DumpToString());
96 } catch (const std::string &e) {
97 LogError("String exception(" << e << "). Closing socket");
98 } catch (const std::exception &e) {
99 LogError("Std exception:: " << e.what());
101 LogError("Unknown exception. Closing socket.");
104 m_serviceManager->Close(conn);
108 RawBuffer CKMService::ProcessControl(MessageBuffer &buffer) {
112 Password newPass, oldPass;
115 buffer.Deserialize(command);
117 LogDebug("Process control. Command: " << command);
119 cc = static_cast<ControlCommand>(command);
122 case ControlCommand::UNLOCK_USER_KEY:
123 buffer.Deserialize(user, newPass);
124 return m_logic->unlockUserKey(user, newPass);
125 case ControlCommand::LOCK_USER_KEY:
126 buffer.Deserialize(user);
127 return m_logic->lockUserKey(user);
128 case ControlCommand::REMOVE_USER_DATA:
129 buffer.Deserialize(user);
130 return m_logic->removeUserData(user);
131 case ControlCommand::CHANGE_USER_PASSWORD:
132 buffer.Deserialize(user, oldPass, newPass);
133 return m_logic->changeUserPassword(user, oldPass, newPass);
134 case ControlCommand::RESET_USER_PASSWORD:
135 buffer.Deserialize(user, newPass);
136 return m_logic->resetUserPassword(user, newPass);
137 case ControlCommand::REMOVE_APP_DATA:
138 buffer.Deserialize(smackLabel);
139 return m_logic->removeApplicationData(smackLabel);
140 case ControlCommand::UPDATE_CC_MODE:
141 return m_logic->updateCCMode();
142 case ControlCommand::SET_PERMISSION:
147 PermissionMask permissionMask = 0;
149 buffer.Deserialize(user, name, label, accessorLabel, permissionMask);
151 Credentials cred(user, label);
152 return m_logic->setPermission(
162 Throw(Exception::BrokenProtocol);
166 RawBuffer CKMService::ProcessStorage(Credentials &cred, MessageBuffer &buffer)
172 Label label, accessorLabel;
175 buffer.Deserialize(command);
176 buffer.Deserialize(msgID);
178 // This is a workaround solution for locktype=None in Tizen 2.2.1
179 // When locktype is None, lockscreen app doesn't interfere with unlocking process.
180 // Therefor lockscreen app cannot notify unlock events to key-manager when locktype is None.
181 // So, to unlock user data when lock type is None, key-manager always try to unlock user data with null password.
182 // Even if the result is fail, it will be ignored.
183 Password nullPassword("");
184 m_logic->unlockUserKey(cred.clientUid, nullPassword);
186 LogDebug("Process storage. Command: " << command);
188 switch(static_cast<LogicCommand>(command)) {
189 case LogicCommand::SAVE:
192 PolicySerializable policy;
193 buffer.Deserialize(tmpDataType, name, label, rawData, policy);
194 return m_logic->saveData(
200 DataType(tmpDataType),
203 case LogicCommand::SAVE_PKCS12:
206 PKCS12Serializable pkcs;
207 PolicySerializable keyPolicy, certPolicy;
208 buffer.Deserialize(name, label, pkcs, keyPolicy, certPolicy);
209 return m_logic->savePKCS12(
218 case LogicCommand::REMOVE:
220 buffer.Deserialize(name, label);
221 return m_logic->removeData(
227 case LogicCommand::GET:
230 buffer.Deserialize(tmpDataType, name, label, password);
231 return m_logic->getData(
234 DataType(tmpDataType),
239 case LogicCommand::GET_PKCS12:
243 buffer.Deserialize(name,
247 return m_logic->getPKCS12(
255 case LogicCommand::GET_LIST:
257 buffer.Deserialize(tmpDataType);
258 return m_logic->getDataList(
261 DataType(tmpDataType));
263 case LogicCommand::CREATE_KEY_AES:
268 PolicySerializable policyKey;
269 buffer.Deserialize(size,
273 return m_logic->createKeyAES(
281 case LogicCommand::CREATE_KEY_PAIR:
283 CryptoAlgorithmSerializable keyGenAlgorithm;
285 Label privateKeyLabel;
287 Label publicKeyLabel;
288 PolicySerializable policyPrivateKey;
289 PolicySerializable policyPublicKey;
290 buffer.Deserialize(keyGenAlgorithm,
297 return m_logic->createKeyPair(
308 case LogicCommand::GET_CHAIN_CERT:
310 RawBuffer certificate;
311 RawBufferVector untrustedVector;
312 RawBufferVector trustedVector;
313 bool systemCerts = false;
314 buffer.Deserialize(certificate, untrustedVector, trustedVector, systemCerts);
315 return m_logic->getCertificateChain(
323 case LogicCommand::GET_CHAIN_ALIAS:
325 RawBuffer certificate;
326 LabelNameVector untrustedVector;
327 LabelNameVector trustedVector;
328 bool systemCerts = false;
329 buffer.Deserialize(certificate, untrustedVector, trustedVector, systemCerts);
330 return m_logic->getCertificateChain(
338 case LogicCommand::CREATE_SIGNATURE:
340 Password password; // password for private_key
342 int padding = 0, hash = 0;
343 buffer.Deserialize(name, label, password, message, hash, padding);
344 return m_logic->createSignature(
349 password, // password for private_key
351 static_cast<HashAlgorithm>(hash),
352 static_cast<RSAPaddingAlgorithm>(padding));
354 case LogicCommand::VERIFY_SIGNATURE:
356 Password password; // password for public_key (optional)
359 //HashAlgorithm hash;
360 //RSAPaddingAlgorithm padding;
361 int padding = 0, hash = 0;
362 buffer.Deserialize(name,
369 return m_logic->verifySignature(
374 password, // password for public_key (optional)
377 static_cast<const HashAlgorithm>(hash),
378 static_cast<const RSAPaddingAlgorithm>(padding));
380 case LogicCommand::SET_PERMISSION:
382 PermissionMask permissionMask = 0;
383 buffer.Deserialize(name, label, accessorLabel, permissionMask);
384 return m_logic->setPermission(
394 Throw(Exception::BrokenProtocol);
398 void CKMService::ProcessMessage(MsgKeyRequest msg)
400 Crypto::GKeyShPtr key;
401 int ret = m_logic->getKeyForService(msg.cred,
406 MsgKeyResponse kResp(msg.id, key, ret);
408 if (!m_commMgr->SendMessage(kResp))
409 LogError("No listener found"); // can't do much more
411 LogError("Uncaught exception in SendMessage. Check listeners.");
415 void CKMService::CustomHandle(const ReadEvent &event) {
416 LogDebug("Read event");
417 auto &info = m_connectionInfoMap[event.connectionID.counter];
418 info.buffer.Push(event.rawBuffer);
419 while(ProcessOne(event.connectionID, info, true));
422 void CKMService::CustomHandle(const SecurityEvent & /*event*/) {
423 LogError("This should not happend! SecurityEvent was called on CKMService!");