From 29fdf375e9edd0dce07e048f2b68aac12d4458de Mon Sep 17 00:00:00 2001 From: frankmorgner Date: Mon, 31 Jan 2011 11:51:31 +0000 Subject: [PATCH] linking against opensc now as shared library git-svn-id: https://vsmartcard.svn.sourceforge.net/svnroot/vsmartcard@394 96b47cad-a561-4643-ad3b-153ac7d7599c --- bitbake/npa.bb | 18 ++++++++++++++++++ ccid/README.dox | 24 +++++------------------- ccid/configure.ac | 24 +++++++++++++++--------- ccid/src/Makefile.am | 22 +++++----------------- npa/Makefile.am | 1 + npa/README.dox | 30 ++++++++++++++++++------------ npa/configure.ac | 16 ++++++++++------ npa/libpace.pc.in | 2 +- npa/src/Makefile.am | 21 ++++----------------- npa/src/pace-tool.c | 20 +++++++++++++------- 10 files changed, 90 insertions(+), 88 deletions(-) create mode 100644 bitbake/npa.bb diff --git a/bitbake/npa.bb b/bitbake/npa.bb new file mode 100644 index 0000000..8bd616a --- /dev/null +++ b/bitbake/npa.bb @@ -0,0 +1,18 @@ +DESCRIPTION = "API and Tools for the new German identity card (neuer Personalausweis, nPA)" +LICENSE = "GPL" + +DEPENDS = "openssl opensc" +RDEPENDS = "libcrypto opensc" + +SRC_URI = "svn://vsmartcard.svn.sourceforge.net/svnroot;module=vsmartcard;proto=https;rev=384" + +S = "${WORKDIR}/vsmartcard/npa" + +inherit autotools pkgconfig + +EXTRA_OECONF = "" + +FILES_${PN} += "\ + ${bindir}/* \ + ${libdir}/* \ +" diff --git a/ccid/README.dox b/ccid/README.dox index 69bc6dc..ae7129c 100644 --- a/ccid/README.dox +++ b/ccid/README.dox @@ -33,26 +33,12 @@ https://docs.openmoko.org/trac/ticket/2240). @subsection o HINTS ON OPENSC -ccid-emulator links against libopensc, which is discouraged and hindered since -opensc>=0.12. We really need to get rid of this dependency. But so far we -manually build it to have libopensc for linking. The good thing is that you -don't need any opensc components to be installed. The bad thing is, that -ccid-emulator configures and builds opensc on its own. So you might need to -pass some extra configure options to opensc. So if you need to pass options to -opensc, use something like the following command: +Without libnpa ccid-emulator links against libopensc, which is discouraged and +hindered since opensc>=0.12. We really need to get rid of this dependency. You +need the opensc components to be installed (especially libopensc.so). But you +might need to adjust the opensc library flags: ./configure \ - OPENSC_CONFIGURE="options" - - -@subsection l HINTS ON LIBPACE - -If you have a local build of libpace and OpenPACE, that you want to link -against use something like the following command: -./configure \ - OPENSSL_CFLAGS="-I/path/to/openssl-1.0.0c_with_openpace-0.4/include" \ - LIBPACE_CFLAGS="-I/path/to/openssl-1.0.0c_with_openpace-0.4/include -I/path/to/libpace-0.1/src" \ - OPENSSL_LIBS="-L/path/to/openssl-1.0.0c_with_openpace-0.4 -lcrypto" \ - LIBPACE_LIBS="-L/path/to/openssl-1.0.0c_with_openpace-0.4 -lcrypto -L/path/to/libpace-0.1/src/.libs -lpace" + OPENSC_LIBS="-L/path/to/opensc/libdir -lopensc" @section u USAGE diff --git a/ccid/configure.ac b/ccid/configure.ac index 58bbd31..84d355d 100644 --- a/ccid/configure.ac +++ b/ccid/configure.ac @@ -67,22 +67,31 @@ LIBS="$saved_LIBS" AC_ARG_ENABLE(pace, AS_HELP_STRING([--enable-pace], [Enable Password Authenticated Connection Establishment (PACE)]), [enable_pace="${enableval}"], [enable_pace=no]) +saved_CPPFLAGS="$CPPFLAGS" +saved_LIBS="$LIBS" if test "x$enable_pace" != xno ; then PKG_CHECK_EXISTS([libpace], [PKG_CHECK_MODULES([LIBPACE], [libpace])], [AC_MSG_WARN([libpace not found by pkg-config])]) - saved_CPPFLAGS="$CPPFLAGS" - saved_LIBS="$LIBS" - CPPFLAGS="$CPPFLAGS $LIBPACE_CFLAGS -I$(pwd)/src/opensc-0.12.0/src" + CPPFLAGS="$CPPFLAGS $LIBPACE_CFLAGS -I$(pwd)/src/opensc/src" LIBS="$LDFLAGS $LIBPACE_LIBS" AC_CHECK_HEADERS(pace/pace.h, [], [ AC_MSG_ERROR([pace/pace.h not found, install libpace or use ./configure LIBPACE_CFLAGS=...]) ]) AC_MSG_CHECKING([for EstablishPACEChannel]) AC_TRY_LINK_FUNC(EstablishPACEChannel, [ AC_MSG_RESULT([yes]) ], [ AC_MSG_ERROR([libpace not found, use ./configure LIBPACE_LIBS=...]) ]) - CPPFLAGS="$saved_CPPFLAGS" - LIBS="$saved_LIBS" enable_pace=yes +else + PKG_CHECK_EXISTS([libopensc], + [PKG_CHECK_MODULES([OPENSC], [libopensc >= 0.12])], + [AC_MSG_WARN([libopensc >= 0.12 not found by pkg-config])]) + test -z "$OPENSC_LIBS" && OPENSC_LIBS="-lopensc" + LIBS="$LDFLAGS $OPENSC_LIBS $OPENSSL_LIBS" + AC_MSG_CHECKING([for sc_ctx_get_reader_count]) + AC_TRY_LINK_FUNC(sc_ctx_get_reader_count, [ AC_MSG_RESULT([yes]) ], + [ AC_MSG_ERROR([libopensc >= 0.12 not found, use ./configure OPENSC_LIBS=...]) ]) fi +CPPFLAGS="$saved_CPPFLAGS" +LIBS="$saved_LIBS" AM_CONDITIONAL(WITH_PACE, test "${enable_pace}" != "no") AM_COND_IF(WITH_PACE, [AC_DEFINE(WITH_PACE, 1, [enable PACE support])]) @@ -134,9 +143,6 @@ fi AM_CONDITIONAL(DOC_ENABLED, [test x"$enable_doc" = xyes]) -AC_SUBST(OPENSC_CONFIGURE) - - # Checks for header files. AC_CHECK_HEADERS([arpa/inet.h fcntl.h memory.h stdint.h stdlib.h string.h sys/ioctl.h unistd.h]) @@ -172,13 +178,13 @@ Linker flags: ${LDFLAGS} Libraries: ${LIBS} PTHREAD_CFLAGS: ${PTHREAD_CFLAGS} PTHREAD_LIBS: ${PTHREAD_LIBS} +OPENSC_LIBS: ${OPENSC_LIBS} OPENSSL_CFLAGS: ${OPENSSL_CFLAGS} OPENSSL_LIBS: ${OPENSSL_LIBS} LIBPACE_CFLAGS: ${LIBPACE_CFLAGS} LIBPACE_LIBS: ${LIBPACE_LIBS} PCSC_CFLAGS: ${PCSC_CFLAGS} PCSC_LIBS: ${PCSC_LIBS} -OPENSC_CONFIGURE: ${OPENSC_CONFIGURE} CCID emulator: ${enable_ccid} PACE support: ${enable_pace} diff --git a/ccid/src/Makefile.am b/ccid/src/Makefile.am index 0c7a797..fe63557 100644 --- a/ccid/src/Makefile.am +++ b/ccid/src/Makefile.am @@ -1,27 +1,15 @@ -OPENSCVERSION = 0.12.0 +EXTRA_DIST = opensc -EXTRA_DIST = opensc-$(OPENSCVERSION) - -AM_CPPFLAGS = -I$(top_srcdir)/src/opensc-$(OPENSCVERSION)/src +AM_CPPFLAGS = -I$(top_srcdir)/src/opensc/src ccid_emulator_SOURCES = ccid.c usbstring.c usb.c binutil.c -ccid_emulator_LDADD = $(OPENSC_LIBS) $(OPENSSL_LIBS) $(PTHREAD_LIBS) -ccid_emulator_CFLAGS = $(OPENSC_CFLAGS) $(OPENSSL_CFLAGS) $(PTHREAD_CFLAGS) +ccid_emulator_LDADD = $(OPENSSL_LIBS) $(PTHREAD_LIBS) +ccid_emulator_CFLAGS = $(OPENSSL_CFLAGS) $(PTHREAD_CFLAGS) cats_test_SOURCES = cats-test.c pcscutil.c cats_test_LDADD = $(PCSC_LIBS) cats_test_CFLAGS = $(PCSC_CFLAGS) -opensc: - cp -r $(top_srcdir)/src/opensc-$(OPENSCVERSION) opensc - cd opensc && ./configure OPENSSL_LIBS="$(OPENSSL_LIBS)" OPENSSL_CFLAGS="$(OPENSSL_CFLAGS)" $(OPENSC_CONFIGURE) - -libopensc.la: opensc - $(MAKE) -C opensc - cp opensc/src/libopensc/.libs/libopensc.* . - -clean-local: - rm -rf opensc libopensc.* bin_PROGRAMS = @@ -47,5 +35,5 @@ ccid_emulator_LDADD += $(LIBPACE_LIBS) ccid_emulator_CFLAGS += $(LIBPACE_CFLAGS) else ccid_emulator_SOURCES += scutil.c -ccid_emulator_LDADD += libopensc.la +ccid_emulator_LDADD += $(OPENSC_LIBS) endif diff --git a/npa/Makefile.am b/npa/Makefile.am index c1943d2..0752e04 100644 --- a/npa/Makefile.am +++ b/npa/Makefile.am @@ -12,6 +12,7 @@ do_subst = sed \ -e 's,[@]libdir[@],$(libdir),g' \ -e 's,[@]includedir[@],$(includedir),g' \ -e 's,[@]VERSION[@],$(VERSION),g' \ + -e 's,[@]OPENSC_LIBS[@],$(OPENSC_LIBS),g' \ -e 's,[@]top_srcdir[@],$(top_srcdir),g' opensc-0.11.13.tar.gz: diff --git a/npa/README.dox b/npa/README.dox index 68e2f87..99a12ba 100644 --- a/npa/README.dox +++ b/npa/README.dox @@ -20,19 +20,11 @@ See file INSTALL. @subsection o HINTS ON OPENSC libnpa links against libopensc, which is discouraged and hindered since -opensc>=0.12. We really need to get rid of this dependency. But so far we -manually build it to have libopensc for linking. The good thing is that you -don't need any opensc components to be installed. The bad thing is, that libnpa -configures and builds opensc on its own. So you might need to pass some extra -configure options to opensc. So if you need to pass options to opensc, use -something like the following command: +opensc>=0.12. We really need to get rid of this dependency. You need the opensc +components to be installed (especially libopensc.so). But you might need to +adjust the opensc library flags: ./configure \ - OPENSC_CONFIGURE="options" - -Worse gets the situation if you need to link against libnpa and some opensc -library at the same time. This will yield conflicts since functionality of -libopensc is linked into both libraries. This is possible (see ccid-emulator), -but not recommended. Only do this if you know what you are doing. + OPENSC_LIBS="-L/path/to/opensc/libdir -lopensc" @subsection o HINTS ON OPENSSL @@ -55,6 +47,20 @@ To pass a secret to pace-tool, the command line parameters or the environment variables PIN/CAN/MRZ/PUK/NEWPIN can be used. If none of these options is used, pace-tool will show a password prompt. +@subsection l LINKING AGAINST LIBNPA + +If you have a local build of libpace and OpenPACE, the preferred way to adjust +libraries and cflags for foreign code is to use pkg-config: +./configure \ + PKG_CONFIG_PATH=/path/to/openssl-1.0.0c_with_openpace-0.4/lib/pkgconfig:/path/to/libpace/lib/pkgconfig" + +Alternatively you can define libs and cflags by hand: +./configure \ + OPENSSL_CFLAGS="-I/path/to/openssl-1.0.0c_with_openpace-0.4/include" \ + LIBPACE_CFLAGS="-I/path/to/openssl-1.0.0c_with_openpace-0.4/include -I/path/to/libpace-0.1/src" \ + OPENSSL_LIBS="-L/path/to/openssl-1.0.0c_with_openpace-0.4 -lcrypto" \ + LIBPACE_LIBS="-L/path/to/openssl-1.0.0c_with_openpace-0.4 -lcrypto -L/path/to/libpace-0.1/src/.libs -lpace" + @section q QUESTIONS For questions, please use http://sourceforge.net/projects/vsmartcard/support diff --git a/npa/configure.ac b/npa/configure.ac index e81397d..a578674 100644 --- a/npa/configure.ac +++ b/npa/configure.ac @@ -19,15 +19,22 @@ AM_PROG_CC_C_O PKG_PROG_PKG_CONFIG # Checks for libraries. +PKG_CHECK_EXISTS([libopensc], + [PKG_CHECK_MODULES([OPENSC], [libopensc >= 0.12 ])], + [AC_MSG_WARN([libopensc >= 0.12 not found by pkg-config])]) +test -z "$OPENSC_LIBS" && OPENSC_LIBS="-lopensc" + PKG_CHECK_EXISTS([libssl], [PKG_CHECK_MODULES([OPENSSL], [libssl])], [AC_MSG_WARN([libssl not found by pkg-config])]) - saved_CPPFLAGS="$CPPFLAGS" saved_LIBS="$LIBS" CPPFLAGS="$CPPFLAGS $OPENSSL_CFLAGS" -LIBS="$LDFLAGS $OPENSSL_LIBS" +LIBS="$LDFLAGS $OPENSC_LIBS $OPENSSL_LIBS" +AC_MSG_CHECKING([for sc_ctx_get_reader_count]) +AC_TRY_LINK_FUNC(sc_ctx_get_reader_count, [ AC_MSG_RESULT([yes]) ], + [ AC_MSG_ERROR([libopensc >= 0.12 not found, use ./configure OPENSC_LIBS=...]) ]) AC_CHECK_HEADERS(openssl/evp.h, [], [ AC_MSG_ERROR([openssl/evp.h not found, install OpenSSL or use ./configure OPENSSL_CFLAGS=...]) ]) AC_MSG_CHECKING([for EVP_read_pw_string_min]) @@ -56,9 +63,6 @@ fi AM_CONDITIONAL(DOC_ENABLED, [test x"$enable_doc" = xyes]) -AC_SUBST(OPENSC_CONFIGURE) - - # Checks for header files. AC_CHECK_HEADERS([arpa/inet.h fcntl.h memory.h stdint.h stdlib.h string.h sys/ioctl.h unistd.h]) @@ -92,9 +96,9 @@ Compiler flags: ${CFLAGS} Preprocessor flags: ${CPPFLAGS} Linker flags: ${LDFLAGS} Libraries: ${LIBS} +OPENSC_LIBS: ${OPENSC_LIBS} OPENSSL_CFLAGS: ${OPENSSL_CFLAGS} OPENSSL_LIBS: ${OPENSSL_LIBS} -OPENSC_CONFIGURE: ${OPENSC_CONFIGURE} Documentation: ${enable_doc} diff --git a/npa/libpace.pc.in b/npa/libpace.pc.in index e124b9d..24b09ad 100644 --- a/npa/libpace.pc.in +++ b/npa/libpace.pc.in @@ -7,5 +7,5 @@ Name: libpace Description: Password Authenticated Connection Establishment (PACE) library Version: @VERSION@ Requires: libssl -Libs: -L${libdir} -lpace +Libs: -L${libdir} -lpace @OPENSC_LIBS@ Cflags: -I${includedir} diff --git a/npa/src/Makefile.am b/npa/src/Makefile.am index effd4cf..a1dcaa6 100644 --- a/npa/src/Makefile.am +++ b/npa/src/Makefile.am @@ -1,28 +1,15 @@ -OPENSCVERSION = 0.12.0 +EXTRA_DIST = opensc -EXTRA_DIST = opensc-$(OPENSCVERSION) - -AM_CPPFLAGS = -I$(top_srcdir)/src/pace -I$(top_srcdir)/src/opensc-$(OPENSCVERSION)/src +AM_CPPFLAGS = -I$(top_srcdir)/src/pace -I$(top_srcdir)/src/opensc/src libpace_la_SOURCES = sm.c scutil.c pace.c pace_lib.c -libpace_la_LIBADD = $(OPENSSL_LIBS) libopensc.la +libpace_la_LIBADD = $(OPENSSL_LIBS) $(OPENSC_LIBS) libpace_la_CFLAGS = $(OPENSSL_CFLAGS) pace_tool_SOURCES = pace-tool.c binutil.c -pace_tool_LDADD = $(OPENSSL_LIBS) libpace.la libopensc.la +pace_tool_LDADD = $(OPENSSL_LIBS) $(OPENSC_LIBS) libpace.la pace_tool_CFLAGS = $(OPENSSL_CFLAGS) -opensc: - cp -r $(top_srcdir)/src/opensc-$(OPENSCVERSION) opensc - cd opensc && ./configure OPENSSL_LIBS="$(OPENSSL_LIBS)" OPENSSL_CFLAGS="$(OPENSSL_CFLAGS)" $(OPENSC_CONFIGURE) - -.PHONY:libopensc.la -libopensc.la: opensc - $(MAKE) -C opensc - cp opensc/src/libopensc/.libs/libopensc.* . - -clean-local: - rm -rf opensc libopensc.* bin_PROGRAMS = pace-tool diff --git a/npa/src/pace-tool.c b/npa/src/pace-tool.c index 43dc96c..9f0f0a6 100644 --- a/npa/src/pace-tool.c +++ b/npa/src/pace-tool.c @@ -185,6 +185,7 @@ main (int argc, char **argv) struct establish_pace_channel_input pace_input; struct establish_pace_channel_output pace_output; time_t t_start, t_end; + struct timeval tv; size_t outlen; memset(&sctx, 0, sizeof sctx); @@ -367,23 +368,28 @@ main (int argc, char **argv) if (strlen(can_ch) > pace_input.pin_length) break; - printf("Trying %s=%s\n", + gettimeofday(&tv, NULL); + printf("%d,%06d: Trying %s=%s\n", + tv.tv_sec, tv.tv_usec, pace_secret_name(pace_input.pin_id), pace_input.pin); i = EstablishPACEChannel(NULL, card, pace_input, &pace_output, &sctx); - can_nb++; - } while (0 > i); + can_nb--; + } while (0 > i && can_nb > 0); t_end = time(NULL); + gettimeofday(&tv, NULL); if (0 > i) { - printf("Tried breaking %s for %.0fs without success.\n", + printf("%d,%06d: Tried breaking %s for %.0fs without success.\n", + tv.tv_sec, tv.tv_usec, pace_secret_name(pace_input.pin_id), difftime(t_end, t_start)); goto err; } else { - printf("Tried breaking %s for %.0fs with success.\n", - pace_secret_name(pace_input.pin_id), difftime(t_end, t_start)); - printf("%s=%s\n", pace_secret_name(pace_input.pin_id), pace_input.pin); + printf("%d,%06d: Tried breaking %s for %.0fs with success (%s=%s).\n", + tv.tv_sec, tv.tv_usec, + pace_secret_name(pace_input.pin_id), difftime(t_end, t_start), + pace_secret_name(pace_input.pin_id), pace_input.pin); } }