catch and debug more errors

This commit is contained in:
Frank Morgner
2013-10-21 18:26:04 +02:00
parent f6879f42de
commit a11be64015
3 changed files with 32 additions and 5 deletions

View File

@@ -21,6 +21,7 @@
#endif
#include "cmdline.h"
#include "sslutil.h"
#include <eac/pace.h>
#include <libopensc/log.h>
#include <libopensc/opensc.h>
@@ -556,8 +557,11 @@ main (int argc, char **argv)
}
for (i = 0; i < cmdline.cv_certificate_given; i++) {
if (!fread_to_eof(cmdline.cv_certificate_arg[i],
(unsigned char **) &certs[i], &certs_lens[i]))
(unsigned char **) &certs[i], &certs_lens[i])) {
fprintf(stderr, "Could not read certificate.\n");
r = SC_ERROR_INVALID_DATA;
goto err;
}
}
if (!pace_input.chat_length) {
@@ -566,27 +570,35 @@ main (int argc, char **argv)
|| !cvc_cert || !cvc_cert->body
|| !cvc_cert->body->certificate_authority_reference
|| !cvc_cert->body->chat) {
fprintf(stderr, "Could not parse certificate.\n");
ssl_error(ctx);
r = SC_ERROR_INVALID_DATA;
goto err;
}
pace_input.chat_length = i2d_CVC_CHAT(cvc_cert->body->chat, &certs_chat);
if (0 >= (int) pace_input.chat_length) {
fprintf(stderr, "Could not parse CHAT.\n");
r = SC_ERROR_INVALID_DATA;
ssl_error(ctx);
goto err;
}
pace_input.chat = certs_chat;
}
if (!fread_to_eof(cmdline.private_key_arg,
&privkey, &privkey_len))
&privkey, &privkey_len)) {
fprintf(stderr, "Could not parse private key.\n");
r = SC_ERROR_INVALID_DATA;
goto err;
}
if (cmdline.auxiliary_data_given) {
auxiliary_data_len = sizeof auxiliary_data;
if (sc_hex_to_bin(cmdline.auxiliary_data_arg, auxiliary_data,
&auxiliary_data_len) < 0) {
fprintf(stderr, "Could not parse auxiliary data.\n");
exit(2);
r = SC_ERROR_INVALID_DATA;
goto err;
}
} else {
if (cmdline.older_than_given) {
@@ -625,7 +637,8 @@ main (int argc, char **argv)
if (0 > (int) auxiliary_data_len
|| auxiliary_data_len > sizeof auxiliary_data) {
free(p);
r = SC_ERROR_INTERNAL;
fprintf(stderr, "Auxiliary data too big.\n");
r = SC_ERROR_OUT_OF_MEMORY;
goto err;
}
memcpy(auxiliary_data, p, auxiliary_data_len);
@@ -768,6 +781,7 @@ main (int argc, char **argv)
input = fopen(cmdline.translate_arg, "r");
if (!input) {
perror("Opening file with APDUs");
r = SC_ERROR_INVALID_DATA;
goto err;
}
}

View File

@@ -407,6 +407,8 @@ static int format_mse_cdata(struct sc_context *ctx, int protocol,
data = NPA_MSE_C_new();
if (!data) {
ssl_error(ctx);
r = SC_ERROR_INTERNAL;
goto err;
}
@@ -455,6 +457,7 @@ static int format_mse_cdata(struct sc_context *ctx, int protocol,
if (auxiliary_data && auxiliary_data_len) {
if (!d2i_ASN1_AUXILIARY_DATA(&data->auxiliary_data, &auxiliary_data, auxiliary_data_len)) {
sc_debug(ctx, SC_LOG_DEBUG_VERBOSE, "Error setting authenticated auxiliary data of MSE:Set AT data");
ssl_error(ctx);
r = SC_ERROR_INTERNAL;
goto err;
}
@@ -468,6 +471,7 @@ static int format_mse_cdata(struct sc_context *ctx, int protocol,
if (length < 0
|| (0x80 & ASN1_get_object(&data_no_sequence, &length, &tag, &class, length))) {
sc_debug(ctx, SC_LOG_DEBUG_VERBOSE, "Error encoding MSE:Set AT APDU data");
ssl_error(ctx);
r = SC_ERROR_INTERNAL;
goto err;
}

View File

@@ -227,6 +227,9 @@ class nPA_SE(Security_Environment):
ef_card_security.data = ef_card_security_data
nonce = pace.PACE_STEP1_enc_nonce(self.eac_ctx, self.sec)
if not nonce:
pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"])
resp = nPA_SE.__pack_general_authenticate([[0x80, len(nonce), nonce]])
@@ -238,6 +241,9 @@ class nPA_SE(Security_Environment):
tlv_data = nPA_SE.__unpack_general_authenticate(data)
pubkey = pace.PACE_STEP3A_generate_mapping_data(self.eac_ctx)
if not pubkey:
pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"])
for tag, length, value in tlv_data:
if tag == 0x81:
@@ -280,7 +286,7 @@ class nPA_SE(Security_Environment):
else:
raise SwError(SW["ERR_INCORRECTPARAMETERS"])
if 1 != pace.PACE_STEP3D_verify_authentication_token(self.eac_ctx, token):
if not my_token or 1 != pace.PACE_STEP3D_verify_authentication_token(self.eac_ctx, token):
pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"])
@@ -332,6 +338,9 @@ class nPA_SE(Security_Environment):
raise SwError(SW["ERR_NOINFO69"])
nonce, token = pace.CA_STEP5_derive_keys(self.eac_ctx, pubkey)
if not nonce or not token:
pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"])
self.eac_step += 1