catch and debug more errors

This commit is contained in:
Frank Morgner
2013-10-21 18:26:04 +02:00
parent f6879f42de
commit a11be64015
3 changed files with 32 additions and 5 deletions

View File

@@ -21,6 +21,7 @@
#endif #endif
#include "cmdline.h" #include "cmdline.h"
#include "sslutil.h"
#include <eac/pace.h> #include <eac/pace.h>
#include <libopensc/log.h> #include <libopensc/log.h>
#include <libopensc/opensc.h> #include <libopensc/opensc.h>
@@ -556,8 +557,11 @@ main (int argc, char **argv)
} }
for (i = 0; i < cmdline.cv_certificate_given; i++) { for (i = 0; i < cmdline.cv_certificate_given; i++) {
if (!fread_to_eof(cmdline.cv_certificate_arg[i], if (!fread_to_eof(cmdline.cv_certificate_arg[i],
(unsigned char **) &certs[i], &certs_lens[i])) (unsigned char **) &certs[i], &certs_lens[i])) {
fprintf(stderr, "Could not read certificate.\n");
r = SC_ERROR_INVALID_DATA;
goto err; goto err;
}
} }
if (!pace_input.chat_length) { if (!pace_input.chat_length) {
@@ -566,27 +570,35 @@ main (int argc, char **argv)
|| !cvc_cert || !cvc_cert->body || !cvc_cert || !cvc_cert->body
|| !cvc_cert->body->certificate_authority_reference || !cvc_cert->body->certificate_authority_reference
|| !cvc_cert->body->chat) { || !cvc_cert->body->chat) {
fprintf(stderr, "Could not parse certificate.\n");
ssl_error(ctx);
r = SC_ERROR_INVALID_DATA; r = SC_ERROR_INVALID_DATA;
goto err; goto err;
} }
pace_input.chat_length = i2d_CVC_CHAT(cvc_cert->body->chat, &certs_chat); pace_input.chat_length = i2d_CVC_CHAT(cvc_cert->body->chat, &certs_chat);
if (0 >= (int) pace_input.chat_length) { if (0 >= (int) pace_input.chat_length) {
fprintf(stderr, "Could not parse CHAT.\n");
r = SC_ERROR_INVALID_DATA; r = SC_ERROR_INVALID_DATA;
ssl_error(ctx);
goto err; goto err;
} }
pace_input.chat = certs_chat; pace_input.chat = certs_chat;
} }
if (!fread_to_eof(cmdline.private_key_arg, if (!fread_to_eof(cmdline.private_key_arg,
&privkey, &privkey_len)) &privkey, &privkey_len)) {
fprintf(stderr, "Could not parse private key.\n");
r = SC_ERROR_INVALID_DATA;
goto err; goto err;
}
if (cmdline.auxiliary_data_given) { if (cmdline.auxiliary_data_given) {
auxiliary_data_len = sizeof auxiliary_data; auxiliary_data_len = sizeof auxiliary_data;
if (sc_hex_to_bin(cmdline.auxiliary_data_arg, auxiliary_data, if (sc_hex_to_bin(cmdline.auxiliary_data_arg, auxiliary_data,
&auxiliary_data_len) < 0) { &auxiliary_data_len) < 0) {
fprintf(stderr, "Could not parse auxiliary data.\n"); fprintf(stderr, "Could not parse auxiliary data.\n");
exit(2); r = SC_ERROR_INVALID_DATA;
goto err;
} }
} else { } else {
if (cmdline.older_than_given) { if (cmdline.older_than_given) {
@@ -625,7 +637,8 @@ main (int argc, char **argv)
if (0 > (int) auxiliary_data_len if (0 > (int) auxiliary_data_len
|| auxiliary_data_len > sizeof auxiliary_data) { || auxiliary_data_len > sizeof auxiliary_data) {
free(p); free(p);
r = SC_ERROR_INTERNAL; fprintf(stderr, "Auxiliary data too big.\n");
r = SC_ERROR_OUT_OF_MEMORY;
goto err; goto err;
} }
memcpy(auxiliary_data, p, auxiliary_data_len); memcpy(auxiliary_data, p, auxiliary_data_len);
@@ -768,6 +781,7 @@ main (int argc, char **argv)
input = fopen(cmdline.translate_arg, "r"); input = fopen(cmdline.translate_arg, "r");
if (!input) { if (!input) {
perror("Opening file with APDUs"); perror("Opening file with APDUs");
r = SC_ERROR_INVALID_DATA;
goto err; goto err;
} }
} }

View File

@@ -407,6 +407,8 @@ static int format_mse_cdata(struct sc_context *ctx, int protocol,
data = NPA_MSE_C_new(); data = NPA_MSE_C_new();
if (!data) { if (!data) {
ssl_error(ctx);
r = SC_ERROR_INTERNAL;
goto err; goto err;
} }
@@ -455,6 +457,7 @@ static int format_mse_cdata(struct sc_context *ctx, int protocol,
if (auxiliary_data && auxiliary_data_len) { if (auxiliary_data && auxiliary_data_len) {
if (!d2i_ASN1_AUXILIARY_DATA(&data->auxiliary_data, &auxiliary_data, auxiliary_data_len)) { if (!d2i_ASN1_AUXILIARY_DATA(&data->auxiliary_data, &auxiliary_data, auxiliary_data_len)) {
sc_debug(ctx, SC_LOG_DEBUG_VERBOSE, "Error setting authenticated auxiliary data of MSE:Set AT data"); sc_debug(ctx, SC_LOG_DEBUG_VERBOSE, "Error setting authenticated auxiliary data of MSE:Set AT data");
ssl_error(ctx);
r = SC_ERROR_INTERNAL; r = SC_ERROR_INTERNAL;
goto err; goto err;
} }
@@ -468,6 +471,7 @@ static int format_mse_cdata(struct sc_context *ctx, int protocol,
if (length < 0 if (length < 0
|| (0x80 & ASN1_get_object(&data_no_sequence, &length, &tag, &class, length))) { || (0x80 & ASN1_get_object(&data_no_sequence, &length, &tag, &class, length))) {
sc_debug(ctx, SC_LOG_DEBUG_VERBOSE, "Error encoding MSE:Set AT APDU data"); sc_debug(ctx, SC_LOG_DEBUG_VERBOSE, "Error encoding MSE:Set AT APDU data");
ssl_error(ctx);
r = SC_ERROR_INTERNAL; r = SC_ERROR_INTERNAL;
goto err; goto err;
} }

View File

@@ -227,6 +227,9 @@ class nPA_SE(Security_Environment):
ef_card_security.data = ef_card_security_data ef_card_security.data = ef_card_security_data
nonce = pace.PACE_STEP1_enc_nonce(self.eac_ctx, self.sec) nonce = pace.PACE_STEP1_enc_nonce(self.eac_ctx, self.sec)
if not nonce:
pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"])
resp = nPA_SE.__pack_general_authenticate([[0x80, len(nonce), nonce]]) resp = nPA_SE.__pack_general_authenticate([[0x80, len(nonce), nonce]])
@@ -238,6 +241,9 @@ class nPA_SE(Security_Environment):
tlv_data = nPA_SE.__unpack_general_authenticate(data) tlv_data = nPA_SE.__unpack_general_authenticate(data)
pubkey = pace.PACE_STEP3A_generate_mapping_data(self.eac_ctx) pubkey = pace.PACE_STEP3A_generate_mapping_data(self.eac_ctx)
if not pubkey:
pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"])
for tag, length, value in tlv_data: for tag, length, value in tlv_data:
if tag == 0x81: if tag == 0x81:
@@ -280,7 +286,7 @@ class nPA_SE(Security_Environment):
else: else:
raise SwError(SW["ERR_INCORRECTPARAMETERS"]) raise SwError(SW["ERR_INCORRECTPARAMETERS"])
if 1 != pace.PACE_STEP3D_verify_authentication_token(self.eac_ctx, token): if not my_token or 1 != pace.PACE_STEP3D_verify_authentication_token(self.eac_ctx, token):
pace.print_ossl_err() pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"]) raise SwError(SW["WARN_NOINFO63"])
@@ -332,6 +338,9 @@ class nPA_SE(Security_Environment):
raise SwError(SW["ERR_NOINFO69"]) raise SwError(SW["ERR_NOINFO69"])
nonce, token = pace.CA_STEP5_derive_keys(self.eac_ctx, pubkey) nonce, token = pace.CA_STEP5_derive_keys(self.eac_ctx, pubkey)
if not nonce or not token:
pace.print_ossl_err()
raise SwError(SW["WARN_NOINFO63"])
self.eac_step += 1 self.eac_step += 1