2016-02-01 07:43:26 -05:00
|
|
|
# frozen_string_literal: true
|
2007-11-10 02:48:56 -05:00
|
|
|
require 'rubygems/command'
|
|
|
|
require 'rubygems/security'
|
2013-09-14 04:59:02 -04:00
|
|
|
begin
|
|
|
|
require 'openssl'
|
|
|
|
rescue LoadError => e
|
|
|
|
raise unless (e.respond_to?(:path) && e.path == 'openssl') ||
|
|
|
|
e.message =~ / -- openssl$/
|
|
|
|
end
|
2007-11-10 02:48:56 -05:00
|
|
|
|
|
|
|
class Gem::Commands::CertCommand < Gem::Command
|
|
|
|
|
|
|
|
def initialize
|
2012-11-29 01:52:18 -05:00
|
|
|
super 'cert', 'Manage RubyGems certificates and signing settings',
|
|
|
|
:add => [], :remove => [], :list => [], :build => [], :sign => []
|
|
|
|
|
|
|
|
OptionParser.accept OpenSSL::X509::Certificate do |certificate|
|
|
|
|
begin
|
|
|
|
OpenSSL::X509::Certificate.new File.read certificate
|
|
|
|
rescue Errno::ENOENT
|
|
|
|
raise OptionParser::InvalidArgument, "#{certificate}: does not exist"
|
|
|
|
rescue OpenSSL::X509::CertificateError
|
|
|
|
raise OptionParser::InvalidArgument,
|
|
|
|
"#{certificate}: invalid X509 certificate"
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-11-29 01:52:18 -05:00
|
|
|
OptionParser.accept OpenSSL::PKey::RSA do |key_file|
|
|
|
|
begin
|
2013-09-14 04:59:02 -04:00
|
|
|
passphrase = ENV['GEM_PRIVATE_KEY_PASSPHRASE']
|
|
|
|
key = OpenSSL::PKey::RSA.new File.read(key_file), passphrase
|
2012-11-29 01:52:18 -05:00
|
|
|
rescue Errno::ENOENT
|
|
|
|
raise OptionParser::InvalidArgument, "#{key_file}: does not exist"
|
|
|
|
rescue OpenSSL::PKey::RSAError
|
|
|
|
raise OptionParser::InvalidArgument, "#{key_file}: invalid RSA key"
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
2012-11-29 01:52:18 -05:00
|
|
|
|
|
|
|
raise OptionParser::InvalidArgument,
|
|
|
|
"#{key_file}: private key not found" unless key.private?
|
|
|
|
|
|
|
|
key
|
|
|
|
end
|
|
|
|
|
|
|
|
add_option('-a', '--add CERT', OpenSSL::X509::Certificate,
|
|
|
|
'Add a trusted certificate.') do |cert, options|
|
|
|
|
options[:add] << cert
|
|
|
|
end
|
|
|
|
|
|
|
|
add_option('-l', '--list [FILTER]',
|
|
|
|
'List trusted certificates where the',
|
|
|
|
'subject contains FILTER') do |filter, options|
|
|
|
|
filter ||= ''
|
|
|
|
|
|
|
|
options[:list] << filter
|
|
|
|
end
|
|
|
|
|
|
|
|
add_option('-r', '--remove FILTER',
|
|
|
|
'Remove trusted certificates where the',
|
|
|
|
'subject contains FILTER') do |filter, options|
|
|
|
|
options[:remove] << filter
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
add_option('-b', '--build EMAIL_ADDR',
|
|
|
|
'Build private key and self-signed',
|
2012-11-29 01:52:18 -05:00
|
|
|
'certificate for EMAIL_ADDR') do |email_address, options|
|
|
|
|
options[:build] << email_address
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
|
|
|
|
2012-11-29 01:52:18 -05:00
|
|
|
add_option('-C', '--certificate CERT', OpenSSL::X509::Certificate,
|
|
|
|
'Signing certificate for --sign') do |cert, options|
|
2011-01-18 19:08:49 -05:00
|
|
|
options[:issuer_cert] = cert
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
|
|
|
|
2012-11-29 01:52:18 -05:00
|
|
|
add_option('-K', '--private-key KEY', OpenSSL::PKey::RSA,
|
|
|
|
'Key for --sign or --build') do |key, options|
|
|
|
|
options[:key] = key
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
|
|
|
|
2012-11-29 01:52:18 -05:00
|
|
|
add_option('-s', '--sign CERT',
|
|
|
|
'Signs CERT with the key from -K',
|
|
|
|
'and the certificate from -C') do |cert_file, options|
|
|
|
|
raise OptionParser::InvalidArgument, "#{cert_file}: does not exist" unless
|
|
|
|
File.file? cert_file
|
|
|
|
|
|
|
|
options[:sign] << cert_file
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2013-09-14 04:59:02 -04:00
|
|
|
def add_certificate certificate # :nodoc:
|
|
|
|
Gem::Security.trust_dir.trust_cert certificate
|
|
|
|
|
|
|
|
say "Added '#{certificate.subject}'"
|
|
|
|
end
|
|
|
|
|
2007-11-10 02:48:56 -05:00
|
|
|
def execute
|
2012-11-29 01:52:18 -05:00
|
|
|
options[:add].each do |certificate|
|
2013-09-14 04:59:02 -04:00
|
|
|
add_certificate certificate
|
2012-11-29 01:52:18 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
options[:remove].each do |filter|
|
2013-09-14 04:59:02 -04:00
|
|
|
remove_certificates_matching filter
|
2012-11-29 01:52:18 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
options[:list].each do |filter|
|
2013-09-14 04:59:02 -04:00
|
|
|
list_certificates_matching filter
|
2012-11-29 01:52:18 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
options[:build].each do |name|
|
|
|
|
build name
|
|
|
|
end
|
|
|
|
|
2013-09-14 04:59:02 -04:00
|
|
|
sign_certificates unless options[:sign].empty?
|
2013-07-22 18:46:50 -04:00
|
|
|
end
|
|
|
|
|
2013-09-13 15:58:57 -04:00
|
|
|
def build name
|
2013-09-14 04:59:02 -04:00
|
|
|
key, key_path = build_key
|
|
|
|
cert_path = build_cert name, key
|
2012-11-29 01:52:18 -05:00
|
|
|
|
2013-09-14 04:59:02 -04:00
|
|
|
say "Certificate: #{cert_path}"
|
|
|
|
|
|
|
|
if key_path
|
|
|
|
say "Private Key: #{key_path}"
|
|
|
|
say "Don't forget to move the key file to somewhere private!"
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def build_cert name, key # :nodoc:
|
2013-09-13 15:58:57 -04:00
|
|
|
cert = Gem::Security.create_cert_email name, key
|
2013-09-14 04:59:02 -04:00
|
|
|
Gem::Security.write cert, "gem-public_cert.pem"
|
|
|
|
end
|
2013-07-09 19:21:36 -04:00
|
|
|
|
2013-09-14 04:59:02 -04:00
|
|
|
def build_key # :nodoc:
|
2014-09-13 23:30:02 -04:00
|
|
|
return options[:key] if options[:key]
|
2012-11-29 01:52:18 -05:00
|
|
|
|
2014-09-13 23:30:02 -04:00
|
|
|
passphrase = ask_for_password 'Passphrase for your Private Key:'
|
|
|
|
say "\n"
|
2013-09-14 04:59:02 -04:00
|
|
|
|
2014-09-13 23:30:02 -04:00
|
|
|
passphrase_confirmation = ask_for_password 'Please repeat the passphrase for your Private Key:'
|
|
|
|
say "\n"
|
2013-09-14 04:59:02 -04:00
|
|
|
|
2014-09-13 23:30:02 -04:00
|
|
|
raise Gem::CommandLineError,
|
|
|
|
"Passphrase and passphrase confirmation don't match" unless passphrase == passphrase_confirmation
|
2013-09-14 04:59:02 -04:00
|
|
|
|
2014-09-13 23:30:02 -04:00
|
|
|
key = Gem::Security.create_key
|
|
|
|
key_path = Gem::Security.write key, "gem-private_key.pem", 0600, passphrase
|
|
|
|
|
|
|
|
return key, key_path
|
2012-11-29 01:52:18 -05:00
|
|
|
end
|
|
|
|
|
|
|
|
def certificates_matching filter
|
|
|
|
return enum_for __method__, filter unless block_given?
|
|
|
|
|
|
|
|
Gem::Security.trusted_certificates.select do |certificate, _|
|
|
|
|
subject = certificate.subject.to_s
|
|
|
|
subject.downcase.index filter
|
|
|
|
end.sort_by do |certificate, _|
|
|
|
|
certificate.subject.to_a.map { |name, data,| [name, data] }
|
|
|
|
end.each do |certificate, path|
|
|
|
|
yield certificate, path
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
def description # :nodoc:
|
|
|
|
<<-EOF
|
|
|
|
The cert command manages signing keys and certificates for creating signed
|
|
|
|
gems. Your signing certificate and private key are typically stored in
|
|
|
|
~/.gem/gem-public_cert.pem and ~/.gem/gem-private_key.pem respectively.
|
|
|
|
|
|
|
|
To build a certificate for signing gems:
|
|
|
|
|
|
|
|
gem cert --build you@example
|
|
|
|
|
|
|
|
If you already have an RSA key, or are creating a new certificate for an
|
|
|
|
existing key:
|
|
|
|
|
|
|
|
gem cert --build you@example --private-key /path/to/key.pem
|
|
|
|
|
|
|
|
If you wish to trust a certificate you can add it to the trust list with:
|
|
|
|
|
|
|
|
gem cert --add /path/to/cert.pem
|
|
|
|
|
|
|
|
You can list trusted certificates with:
|
|
|
|
|
|
|
|
gem cert --list
|
|
|
|
|
|
|
|
or:
|
|
|
|
|
|
|
|
gem cert --list cert_subject_substring
|
|
|
|
|
|
|
|
If you wish to remove a previously trusted certificate:
|
|
|
|
|
|
|
|
gem cert --remove cert_subject_substring
|
|
|
|
|
|
|
|
To sign another gem author's certificate:
|
|
|
|
|
|
|
|
gem cert --sign /path/to/other_cert.pem
|
|
|
|
|
|
|
|
For further reading on signing gems see `ri Gem::Security`.
|
|
|
|
EOF
|
|
|
|
end
|
|
|
|
|
2013-09-14 04:59:02 -04:00
|
|
|
def list_certificates_matching filter # :nodoc:
|
|
|
|
certificates_matching filter do |certificate, _|
|
|
|
|
# this could probably be formatted more gracefully
|
|
|
|
say certificate.subject.to_s
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-11-29 01:52:18 -05:00
|
|
|
def load_default_cert
|
2013-06-04 17:54:58 -04:00
|
|
|
cert_file = File.join Gem.default_cert_path
|
2012-11-29 01:52:18 -05:00
|
|
|
cert = File.read cert_file
|
|
|
|
options[:issuer_cert] = OpenSSL::X509::Certificate.new cert
|
|
|
|
rescue Errno::ENOENT
|
|
|
|
alert_error \
|
|
|
|
"--certificate not specified and ~/.gem/gem-public_cert.pem does not exist"
|
|
|
|
|
|
|
|
terminate_interaction 1
|
|
|
|
rescue OpenSSL::X509::CertificateError
|
|
|
|
alert_error \
|
|
|
|
"--certificate not specified and ~/.gem/gem-public_cert.pem is not valid"
|
|
|
|
|
|
|
|
terminate_interaction 1
|
|
|
|
end
|
|
|
|
|
|
|
|
def load_default_key
|
2013-06-04 17:54:58 -04:00
|
|
|
key_file = File.join Gem.default_key_path
|
2012-11-29 01:52:18 -05:00
|
|
|
key = File.read key_file
|
2013-09-14 04:59:02 -04:00
|
|
|
passphrase = ENV['GEM_PRIVATE_KEY_PASSPHRASE']
|
|
|
|
options[:key] = OpenSSL::PKey::RSA.new key, passphrase
|
2012-11-29 01:52:18 -05:00
|
|
|
rescue Errno::ENOENT
|
|
|
|
alert_error \
|
|
|
|
"--private-key not specified and ~/.gem/gem-private_key.pem does not exist"
|
|
|
|
|
|
|
|
terminate_interaction 1
|
|
|
|
rescue OpenSSL::PKey::RSAError
|
|
|
|
alert_error \
|
|
|
|
"--private-key not specified and ~/.gem/gem-private_key.pem is not valid"
|
|
|
|
|
|
|
|
terminate_interaction 1
|
|
|
|
end
|
|
|
|
|
2013-09-14 04:59:02 -04:00
|
|
|
def load_defaults # :nodoc:
|
|
|
|
load_default_cert unless options[:issuer_cert]
|
|
|
|
load_default_key unless options[:key]
|
|
|
|
end
|
|
|
|
|
|
|
|
def remove_certificates_matching filter # :nodoc:
|
|
|
|
certificates_matching filter do |certificate, path|
|
|
|
|
FileUtils.rm path
|
|
|
|
say "Removed '#{certificate.subject}'"
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
2012-11-29 01:52:18 -05:00
|
|
|
def sign cert_file
|
|
|
|
cert = File.read cert_file
|
|
|
|
cert = OpenSSL::X509::Certificate.new cert
|
|
|
|
|
|
|
|
permissions = File.stat(cert_file).mode & 0777
|
|
|
|
|
|
|
|
issuer_cert = options[:issuer_cert]
|
|
|
|
issuer_key = options[:key]
|
|
|
|
|
|
|
|
cert = Gem::Security.sign cert, issuer_key, issuer_cert
|
|
|
|
|
|
|
|
Gem::Security.write cert, cert_file, permissions
|
2007-11-10 02:48:56 -05:00
|
|
|
end
|
|
|
|
|
2013-09-14 04:59:02 -04:00
|
|
|
def sign_certificates # :nodoc:
|
|
|
|
load_defaults unless options[:sign].empty?
|
|
|
|
|
|
|
|
options[:sign].each do |cert_file|
|
|
|
|
sign cert_file
|
|
|
|
end
|
|
|
|
end
|
|
|
|
|
|
|
|
end if defined?(OpenSSL::SSL)
|
2007-11-10 02:48:56 -05:00
|
|
|
|