56a6866
#!/usr/bin/perl -w
56a6866
56a6866
use diagnostics;
56a6866
use Fcntl;
d01a981
d01a981
# Copyright (C) 2007, 2008 Red Hat, Inc.
d01a981
#
d01a981
# This program is free software; you can redistribute it and/or modify
d01a981
# it under the terms of the GNU General Public License as published by
d01a981
# the Free Software Foundation; either version 2 of the License, or
d01a981
# (at your option) any later version.
d01a981
#
d01a981
# This program is distributed in the hope that it will be useful,
d01a981
# but WITHOUT ANY WARRANTY; without even the implied warranty of
d01a981
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
d01a981
# GNU General Public License for more details.
d01a981
d01a981
# generate-cacerts.pl generates a JKS keystore named 'cacerts' from
d01a981
# OpenSSL's certificate bundle using OpenJDK's keytool.
d01a981
d01a981
# First extract each of OpenSSL's bundled certificates into its own
d01a981
# aliased filename.
d01a981
$file = $ARGV[1];
d01a981
open(CERTS, $file);
d01a981
@certs = <CERTS>;
d01a981
close(CERTS);
d01a981
Thomas Fitzsimmons 180c47e
$pem_file_count = 0;
Thomas Fitzsimmons 180c47e
$in_cert_block = 0;
Thomas Fitzsimmons 180c47e
$write_current_cert = 1;
d01a981
foreach $cert (@certs)
d01a981
{
708646c
    if ($cert =~ "Certificate:\n")
708646c
    {
708646c
        print "New certificate...\n";
708646c
    }        
708646c
    elsif ($cert =~ /Subject: /)
Thomas Fitzsimmons 180c47e
    {
Thomas Fitzsimmons 180c47e
        $_ = $cert;
Thomas Fitzsimmons 180c47e
        if ($cert =~ /personal-freemail/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "thawtepersonalfreemailca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /personal-basic/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "thawtepersonalbasicca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /personal-premium/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "thawtepersonalpremiumca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /server-certs/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "thawteserverca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /premium-server/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "thawtepremiumserverca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Class 1 Public Primary Certification Authority$/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass1ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Class 1 Public Primary Certification Authority - G2/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass1g2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~
Thomas Fitzsimmons 180c47e
               /VeriSign Class 1 Public Primary Certification Authority - G3/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass1g3ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Class 2 Public Primary Certification Authority$/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Class 2 Public Primary Certification Authority - G2/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass2g2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~
Thomas Fitzsimmons 180c47e
               /VeriSign Class 2 Public Primary Certification Authority - G3/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass2g3ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Class 3 Public Primary Certification Authority$/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass3ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        # Version 1 of Class 3 Public Primary Certification Authority
Thomas Fitzsimmons 180c47e
        # - G2 is added.  Version 3 is excluded.  See below.
56a6866
        elsif ($cert =~ /Class 3 Public Primary Certification Authority - G2.*1998/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass3g2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~
Thomas Fitzsimmons 180c47e
               /VeriSign Class 3 Public Primary Certification Authority - G3/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "verisignclass3g3ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~
Thomas Fitzsimmons 180c47e
               /RSA Data Security.*Secure Server Certification Authority/)
Thomas Fitzsimmons 180c47e
        {
56a6866
            $cert_alias = "rsaserverca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /GTE CyberTrust Global Root/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "gtecybertrustglobalca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Baltimore CyberTrust Root/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "baltimorecybertrustca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /www.entrust.net\/Client_CA_Info\/CPS/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "entrustclientca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /www.entrust.net\/GCCA_CPS/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "entrustglobalclientca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /www.entrust.net\/CPS_2048/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "entrust2048ca";
Thomas Fitzsimmons 180c47e
        }
56a6866
        elsif ($cert =~ /www.entrust.net\/CPS incorp /)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "entrustsslca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /www.entrust.net\/SSL_CPS/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "entrustgsslca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /The Go Daddy Group/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "godaddyclass2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Starfield Class 2 Certification Authority/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "starfieldclass2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /ValiCert Class 2 Policy Validation Authority/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "valicertclass2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /GeoTrust Global CA$/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "geotrustglobalca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Equifax Secure Certificate Authority/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "equifaxsecureca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Equifax Secure eBusiness CA-1/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "equifaxsecureebusinessca1";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Equifax Secure eBusiness CA-2/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "equifaxsecureebusinessca2";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Equifax Secure Global eBusiness CA-1/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "equifaxsecureglobalebusinessca1";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Sonera Class1 CA/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "soneraclass1ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Sonera Class2 CA/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "soneraclass2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /AAA Certificate Services/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "comodoaaaca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /AddTrust Class 1 CA Root/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "addtrustclass1ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /AddTrust External CA Root/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "addtrustexternalca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /AddTrust Qualified CA Root/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "addtrustqualifiedca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /UTN-USERFirst-Hardware/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "utnuserfirsthardwareca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /UTN-USERFirst-Client Authentication and Email/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "utnuserfirstclientauthemailca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /UTN - DATACorp SGC/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "utndatacorpsgcca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /UTN-USERFirst-Object/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "utnuserfirstobjectca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /America Online Root Certification Authority 1/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "aolrootca1";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /DigiCert Assured ID Root CA/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "digicertassuredidrootca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /DigiCert Global Root CA/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "digicertglobalrootca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /DigiCert High Assurance EV Root CA/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "digicerthighassuranceevrootca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /GlobalSign Root CA$/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "globalsignca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /GlobalSign Root CA - R2/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "globalsignr2ca";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        elsif ($cert =~ /Elektronik.*Kas.*2005/)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $cert_alias = "extra-elektronikkas2005";
Thomas Fitzsimmons 180c47e
        }
0d2dd80
        elsif ($cert =~ /Muntaner 244 Barcelona.*Firmaprofesional/)
0d2dd80
        {
0d2dd80
            $cert_alias = "extra-oldfirmaprofesional";
0d2dd80
        }
Thomas Fitzsimmons 180c47e
        # Mozilla does not provide these certificates:
Thomas Fitzsimmons 180c47e
        #   baltimorecodesigningca
Thomas Fitzsimmons 180c47e
        #   gtecybertrust5ca
Thomas Fitzsimmons 180c47e
        #   trustcenterclass2caii
Thomas Fitzsimmons 180c47e
        #   trustcenterclass4caii
Thomas Fitzsimmons 180c47e
        #   trustcenteruniversalcai
Thomas Fitzsimmons 180c47e
        else
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            # Generate an alias using the OU and CN attributes of the
56a6866
            # Subject field if both are present, otherwise use only the
56a6866
            # CN attribute.  The Subject field must have either the OU
Thomas Fitzsimmons 180c47e
            # or the CN attribute.
Thomas Fitzsimmons 180c47e
            $_ = $cert;
Thomas Fitzsimmons 180c47e
            if ($cert =~ /OU=/)
Thomas Fitzsimmons 180c47e
            {
56a6866
                s/Subject:.*?OU=//;
Thomas Fitzsimmons 180c47e
                # Remove other occurrences of OU=.
Thomas Fitzsimmons 180c47e
                s/OU=.*CN=//;
Thomas Fitzsimmons 180c47e
                # Remove CN= if there were not other occurrences of OU=.
Thomas Fitzsimmons 180c47e
                s/CN=//;
Thomas Fitzsimmons 180c47e
                s/\/emailAddress.*//;
Thomas Fitzsimmons 180c47e
                s/Certificate Authority/ca/g;
Thomas Fitzsimmons 180c47e
                s/Certification Authority/ca/g;
Thomas Fitzsimmons 180c47e
            }
Thomas Fitzsimmons 180c47e
            elsif ($cert =~ /CN=/)
Thomas Fitzsimmons 180c47e
            {
56a6866
                s/Subject:.*CN=//;
Thomas Fitzsimmons 180c47e
                s/\/emailAddress.*//;
Thomas Fitzsimmons 180c47e
                s/Certificate Authority/ca/g;
Thomas Fitzsimmons 180c47e
                s/Certification Authority/ca/g;
Thomas Fitzsimmons 180c47e
            }
Thomas Fitzsimmons 180c47e
            s/\W//g;
Thomas Fitzsimmons 180c47e
            tr/A-Z/a-z/;
Thomas Fitzsimmons 180c47e
            $cert_alias = "extra-$_";
Thomas Fitzsimmons 180c47e
        }
56a6866
        print "$cert => alias $cert_alias\n";
Thomas Fitzsimmons 180c47e
    }
708646c
    elsif ($cert =~ "Signature Algorithm: ecdsa")
Thomas Fitzsimmons 180c47e
    {
708646c
        # Ignore ECC certs since keytool rejects them
Thomas Fitzsimmons 180c47e
        $write_current_cert = 0;
708646c
        print " => ignoring ECC certificate\n";
Thomas Fitzsimmons 180c47e
    }
Thomas Fitzsimmons 180c47e
    elsif ($cert eq "-----BEGIN CERTIFICATE-----\n")
Thomas Fitzsimmons 180c47e
    {
Thomas Fitzsimmons 180c47e
        if ($in_cert_block != 0)
Thomas Fitzsimmons 180c47e
        {
0d2dd80
            die "FAIL: $file is malformed.";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        $in_cert_block = 1;
Thomas Fitzsimmons 180c47e
        if ($write_current_cert == 1)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            $pem_file_count++;
Joe Orton 5968244
            if (!sysopen(PEM, "$cert_alias.pem", O_WRONLY|O_CREAT|O_EXCL)) {
Joe Orton 5968244
                $cert_alias = "$cert_alias.1";
Joe Orton 5968244
                sysopen(PEM, "$cert_alias.1.pem", O_WRONLY|O_CREAT|O_EXCL)
Joe Orton 5968244
                    || die("FAIL: could not open file for $cert_alias.pem: $!");
Joe Orton 5968244
            }
Thomas Fitzsimmons 180c47e
            print PEM $cert;
0d2dd80
            print " => writing $cert_alias.pem...\n";
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
    }
Thomas Fitzsimmons 180c47e
    elsif ($cert eq "-----END CERTIFICATE-----\n")
Thomas Fitzsimmons 180c47e
    {
Thomas Fitzsimmons 180c47e
        $in_cert_block = 0;
Thomas Fitzsimmons 180c47e
        if ($write_current_cert == 1)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            print PEM $cert;
Thomas Fitzsimmons 180c47e
            close(PEM);
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
        $write_current_cert = 1
Thomas Fitzsimmons 180c47e
    }
Thomas Fitzsimmons 180c47e
    else
Thomas Fitzsimmons 180c47e
    {
Thomas Fitzsimmons 180c47e
        if ($in_cert_block == 1 && $write_current_cert == 1)
Thomas Fitzsimmons 180c47e
        {
Thomas Fitzsimmons 180c47e
            print PEM $cert;
Thomas Fitzsimmons 180c47e
        }
Thomas Fitzsimmons 180c47e
    }
d01a981
}
d01a981
d01a981
# Check that the correct number of .pem files were produced.
d01a981
@pem_files = <*.pem>;
Thomas Fitzsimmons 180c47e
if (@pem_files != $pem_file_count)
d01a981
{
56a6866
    print "$pem_file_count != ".@pem_files."\n";
0d2dd80
    die "FAIL: Number of .pem files produced does not match".
Thomas Fitzsimmons 180c47e
        " number of certs read from $file.";
d01a981
}
d01a981
d01a981
# Now store each cert in the 'cacerts' file using keytool.
d01a981
$certs_written_count = 0;
d01a981
foreach $pem_file (@pem_files)
d01a981
{
708646c
    print "+ Adding $pem_file...\n";
708646c
    if (system("$ARGV[0] -import".
708646c
               " -alias `basename $pem_file .pem`".
708646c
               " -keystore cacerts -noprompt -storepass 'changeit' -file $pem_file") == 0) {
708646c
        $certs_written_count++;
708646c
    } else {
708646c
        print "FAILED\n";
708646c
    }
d01a981
}
d01a981
d01a981
# Check that the correct number of certs were added to the keystore.
Thomas Fitzsimmons 180c47e
if ($certs_written_count != $pem_file_count)
d01a981
{
0d2dd80
    die "FAIL: Number of certs added to keystore does not match".
Thomas Fitzsimmons 180c47e
        " number of certs read from $file.";
d01a981
}