blob: 67d4096659ed82dae2befe0a2448034cc7b8ea82 [file] [log] [blame]
Pengyu Lv7f6933a2023-04-04 16:05:54 +08001#!/usr/bin/env python3
2#
3# copyright the mbed tls contributors
4# spdx-license-identifier: apache-2.0
5#
6# licensed under the apache license, version 2.0 (the "license"); you may
7# not use this file except in compliance with the license.
8# you may obtain a copy of the license at
9#
10# http://www.apache.org/licenses/LICENSE-2.0
11#
12# Unless required by applicable law or agreed to in writing, software
13# distributed under the License is distributed on an "AS IS" BASIS, WITHOUT
14# WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
15# See the License for the specific language governing permissions and
16# limitations under the License.
17
18"""Audit validity date of X509 crt/crl/csr
19
20This script is used to audit the validity date of crt/crl/csr used for testing.
21The files are in tests/data_files/ while some data are in test suites data in
22tests/suites/*.data files.
23"""
24
25import os
26import sys
27import re
28import typing
29import types
30import argparse
31import datetime
32from enum import Enum
33
34from cryptography import x509
35
36class DataType(Enum):
37 CRT = 1 # Certificate
38 CRL = 2 # Certificate Revocation List
39 CSR = 3 # Certificate Signing Request
40
41class DataFormat(Enum):
42 PEM = 1 # Privacy-Enhanced Mail
43 DER = 2 # Distinguished Encoding Rules
44
45class AuditData:
46 """Store file, type and expiration date for audit."""
47 #pylint: disable=too-few-public-methods
48 def __init__(self, data_type: DataType):
49 self.data_type = data_type
50 self.filename = ""
51 self.not_valid_after: datetime.datetime
52 self.not_valid_before: datetime.datetime
53
54 def fill_validity_duration(self, x509_obj):
55 """Fill expiration_date field from a x509 object"""
56 # Certificate expires after "not_valid_after"
57 # Certificate is invalid before "not_valid_before"
58 if self.data_type == DataType.CRT:
59 self.not_valid_after = x509_obj.not_valid_after
60 self.not_valid_before = x509_obj.not_valid_before
61 # CertificateRevocationList expires after "next_update"
62 # CertificateRevocationList is invalid before "last_update"
63 elif self.data_type == DataType.CRL:
64 self.not_valid_after = x509_obj.next_update
65 self.not_valid_before = x509_obj.last_update
66 # CertificateSigningRequest is always valid.
67 elif self.data_type == DataType.CSR:
68 self.not_valid_after = datetime.datetime.max
69 self.not_valid_before = datetime.datetime.min
70 else:
71 raise ValueError("Unsupported file_type: {}".format(self.data_type))
72
73class X509Parser():
74 """A parser class to parse crt/crl/csr file or data in PEM/DER format."""
75 PEM_REGEX = br'-{5}BEGIN (?P<type>.*?)-{5}\n(?P<data>.*?)-{5}END (?P=type)-{5}\n'
76 PEM_TAG_REGEX = br'-{5}BEGIN (?P<type>.*?)-{5}\n'
77 PEM_TAGS = {
78 DataType.CRT: 'CERTIFICATE',
79 DataType.CRL: 'X509 CRL',
80 DataType.CSR: 'CERTIFICATE REQUEST'
81 }
82
83 def __init__(self, backends: dict):
84 self.backends = backends
85 self.__generate_parsers()
86
87 def __generate_parser(self, data_type: DataType):
88 """Parser generator for a specific DataType"""
89 tag = self.PEM_TAGS[data_type]
90 pem_loader = self.backends[data_type][DataFormat.PEM]
91 der_loader = self.backends[data_type][DataFormat.DER]
92 def wrapper(data: bytes):
93 pem_type = X509Parser.pem_data_type(data)
94 # It is in PEM format with target tag
95 if pem_type == tag:
96 return pem_loader(data)
97 # It is in PEM format without target tag
98 if pem_type:
99 return None
100 # It might be in DER format
101 try:
102 result = der_loader(data)
103 except ValueError:
104 result = None
105 return result
106 wrapper.__name__ = "{}.parser[{}]".format(type(self).__name__, tag)
107 return wrapper
108
109 def __generate_parsers(self):
110 """Generate parsers for all support DataType"""
111 self.parsers = {}
112 for data_type, _ in self.PEM_TAGS.items():
113 self.parsers[data_type] = self.__generate_parser(data_type)
114
115 def __getitem__(self, item):
116 return self.parsers[item]
117
118 @staticmethod
119 def pem_data_type(data: bytes) -> str:
120 """Get the tag from the data in PEM format
121
122 :param data: data to be checked in binary mode.
123 :return: PEM tag or "" when no tag detected.
124 """
125 m = re.search(X509Parser.PEM_TAG_REGEX, data)
126 if m is not None:
127 return m.group('type').decode('UTF-8')
128 else:
129 return ""
130
131class Auditor:
132 """A base class for audit."""
133 def __init__(self, verbose):
134 self.verbose = verbose
135 self.default_files = []
136 self.audit_data = []
137 self.parser = X509Parser({
138 DataType.CRT: {
139 DataFormat.PEM: x509.load_pem_x509_certificate,
140 DataFormat.DER: x509.load_der_x509_certificate
141 },
142 DataType.CRL: {
143 DataFormat.PEM: x509.load_pem_x509_crl,
144 DataFormat.DER: x509.load_der_x509_crl
145 },
146 DataType.CSR: {
147 DataFormat.PEM: x509.load_pem_x509_csr,
148 DataFormat.DER: x509.load_der_x509_csr
149 },
150 })
151
152 def error(self, *args):
153 #pylint: disable=no-self-use
154 print("Error: ", *args, file=sys.stderr)
155
156 def warn(self, *args):
157 if self.verbose:
158 print("Warn: ", *args, file=sys.stderr)
159
160 def parse_file(self, filename: str) -> typing.List[AuditData]:
161 """
162 Parse a list of AuditData from file.
163
164 :param filename: name of the file to parse.
165 :return list of AuditData parsed from the file.
166 """
167 with open(filename, 'rb') as f:
168 data = f.read()
169 result_list = []
170 result = self.parse_bytes(data)
171 if result is not None:
172 result.filename = filename
173 result_list.append(result)
174 return result_list
175
176 def parse_bytes(self, data: bytes):
177 """Parse AuditData from bytes."""
178 for data_type in list(DataType):
179 try:
180 result = self.parser[data_type](data)
181 except ValueError as val_error:
182 result = None
183 self.warn(val_error)
184 if result is not None:
185 audit_data = AuditData(data_type)
186 audit_data.fill_validity_duration(result)
187 return audit_data
188 return None
189
190 def walk_all(self, file_list):
191 """
192 Iterate over all the files in the list and get audit data.
193 """
194 if not file_list:
195 file_list = self.default_files
196 for filename in file_list:
197 data_list = self.parse_file(filename)
198 self.audit_data.extend(data_list)
199
200 def for_each(self, do, *args, **kwargs):
201 """
202 Sort the audit data and iterate over them.
203 """
204 if not isinstance(do, types.FunctionType):
205 return
206 for d in self.audit_data:
207 do(d, *args, **kwargs)
208
209 @staticmethod
210 def find_test_dir():
211 """Get the relative path for the MbedTLS test directory."""
212 if os.path.isdir('tests'):
213 tests_dir = 'tests'
214 elif os.path.isdir('suites'):
215 tests_dir = '.'
216 elif os.path.isdir('../suites'):
217 tests_dir = '..'
218 else:
219 raise Exception("Mbed TLS source tree not found")
220 return tests_dir
221
222class TestDataAuditor(Auditor):
223 """Class for auditing files in tests/data_files/"""
224 def __init__(self, verbose):
225 super().__init__(verbose)
226 self.default_files = self.collect_default_files()
227
228 def collect_default_files(self):
229 """collect all files in tests/data_files/"""
230 test_dir = self.find_test_dir()
231 test_data_folder = os.path.join(test_dir, 'data_files')
232 data_files = []
233 for (dir_path, _, file_names) in os.walk(test_data_folder):
234 data_files.extend(os.path.join(dir_path, file_name)
235 for file_name in file_names)
236 return data_files
237
238
239def list_all(audit_data: AuditData):
240 print("{}\t{}\t{}\t{}".format(
241 audit_data.not_valid_before.isoformat(timespec='seconds'),
242 audit_data.not_valid_after.isoformat(timespec='seconds'),
243 audit_data.data_type.name,
244 audit_data.filename))
245
246def main():
247 """
248 Perform argument parsing.
249 """
250 parser = argparse.ArgumentParser(
251 description='Audit script for X509 crt/crl/csr files.'
252 )
253
254 parser.add_argument('-a', '--all',
255 action='store_true',
256 help='list the information of all files')
257 parser.add_argument('-v', '--verbose',
258 action='store_true', dest='verbose',
259 help='Show warnings')
260 parser.add_argument('-f', '--file', dest='file',
261 help='file to audit (Debug only)',
262 metavar='FILE')
263
264 args = parser.parse_args()
265
266 # start main routine
267 td_auditor = TestDataAuditor(args.verbose)
268
269 if args.file:
270 data_files = [args.file]
271 else:
272 data_files = td_auditor.default_files
273
274 td_auditor.walk_all(data_files)
275
276 if args.all:
277 td_auditor.for_each(list_all)
278
279 print("\nDone!\n")
280
281if __name__ == "__main__":
282 main()