1*d9f75844SAndroid Build Coastguard Worker#!/usr/bin/env vpython3 2*d9f75844SAndroid Build Coastguard Worker 3*d9f75844SAndroid Build Coastguard Worker# -*- coding:utf-8 -*- 4*d9f75844SAndroid Build Coastguard Worker# Copyright (c) 2015 The WebRTC project authors. All Rights Reserved. 5*d9f75844SAndroid Build Coastguard Worker# 6*d9f75844SAndroid Build Coastguard Worker# Use of this source code is governed by a BSD-style license 7*d9f75844SAndroid Build Coastguard Worker# that can be found in the LICENSE file in the root of the source 8*d9f75844SAndroid Build Coastguard Worker# tree. An additional intellectual property rights grant can be found 9*d9f75844SAndroid Build Coastguard Worker# in the file PATENTS. All contributing project authors may 10*d9f75844SAndroid Build Coastguard Worker# be found in the AUTHORS file in the root of the source tree. 11*d9f75844SAndroid Build Coastguard Worker"""This is a tool to transform a crt file into a C/C++ header. 12*d9f75844SAndroid Build Coastguard Worker 13*d9f75844SAndroid Build Coastguard WorkerUsage: 14*d9f75844SAndroid Build Coastguard Workerpython3 generate_sslroots.py certfile.pem [--verbose | -v] [--full_cert | -f] 15*d9f75844SAndroid Build Coastguard Worker 16*d9f75844SAndroid Build Coastguard WorkerArguments: 17*d9f75844SAndroid Build Coastguard Worker -v Print output while running. 18*d9f75844SAndroid Build Coastguard Worker -f Add public key and certificate name. Default is to skip and reduce 19*d9f75844SAndroid Build Coastguard Worker generated file size. 20*d9f75844SAndroid Build Coastguard Worker 21*d9f75844SAndroid Build Coastguard WorkerThe supported cert files are: 22*d9f75844SAndroid Build Coastguard Worker - Google: https://pki.goog/roots.pem 23*d9f75844SAndroid Build Coastguard Worker - Mozilla: https://curl.se/docs/caextract.html 24*d9f75844SAndroid Build Coastguard Worker""" 25*d9f75844SAndroid Build Coastguard Worker 26*d9f75844SAndroid Build Coastguard Workerimport subprocess 27*d9f75844SAndroid Build Coastguard Workerfrom optparse import OptionParser 28*d9f75844SAndroid Build Coastguard Workerimport os 29*d9f75844SAndroid Build Coastguard Workerimport re 30*d9f75844SAndroid Build Coastguard Worker 31*d9f75844SAndroid Build Coastguard Worker_GENERATED_FILE = 'ssl_roots.h' 32*d9f75844SAndroid Build Coastguard Worker_PREFIX = '__generated__' 33*d9f75844SAndroid Build Coastguard Worker_EXTENSION = '.crt' 34*d9f75844SAndroid Build Coastguard Worker_SUBJECT_NAME_ARRAY = 'subject_name' 35*d9f75844SAndroid Build Coastguard Worker_SUBJECT_NAME_VARIABLE = 'SubjectName' 36*d9f75844SAndroid Build Coastguard Worker_PUBLIC_KEY_ARRAY = 'public_key' 37*d9f75844SAndroid Build Coastguard Worker_PUBLIC_KEY_VARIABLE = 'PublicKey' 38*d9f75844SAndroid Build Coastguard Worker_CERTIFICATE_ARRAY = 'certificate' 39*d9f75844SAndroid Build Coastguard Worker_CERTIFICATE_VARIABLE = 'Certificate' 40*d9f75844SAndroid Build Coastguard Worker_CERTIFICATE_SIZE_VARIABLE = 'CertificateSize' 41*d9f75844SAndroid Build Coastguard Worker_INT_TYPE = 'size_t' 42*d9f75844SAndroid Build Coastguard Worker_CHAR_TYPE = 'unsigned char* const' 43*d9f75844SAndroid Build Coastguard Worker_VERBOSE = 'verbose' 44*d9f75844SAndroid Build Coastguard Worker_MOZILLA_BUNDLE_CHECK = '## Certificate data from Mozilla as of:' 45*d9f75844SAndroid Build Coastguard Worker 46*d9f75844SAndroid Build Coastguard Worker 47*d9f75844SAndroid Build Coastguard Workerdef main(): 48*d9f75844SAndroid Build Coastguard Worker """The main entrypoint.""" 49*d9f75844SAndroid Build Coastguard Worker parser = OptionParser('usage %prog FILE') 50*d9f75844SAndroid Build Coastguard Worker parser.add_option('-v', '--verbose', dest='verbose', action='store_true') 51*d9f75844SAndroid Build Coastguard Worker parser.add_option('-f', '--full_cert', dest='full_cert', action='store_true') 52*d9f75844SAndroid Build Coastguard Worker options, args = parser.parse_args() 53*d9f75844SAndroid Build Coastguard Worker if len(args) < 1: 54*d9f75844SAndroid Build Coastguard Worker parser.error('No crt file specified.') 55*d9f75844SAndroid Build Coastguard Worker return 56*d9f75844SAndroid Build Coastguard Worker root_dir, bundle_type = _SplitCrt(args[0], options) 57*d9f75844SAndroid Build Coastguard Worker _GenCFiles(root_dir, options, bundle_type) 58*d9f75844SAndroid Build Coastguard Worker _Cleanup(root_dir) 59*d9f75844SAndroid Build Coastguard Worker 60*d9f75844SAndroid Build Coastguard Worker 61*d9f75844SAndroid Build Coastguard Workerdef _SplitCrt(source_file, options): 62*d9f75844SAndroid Build Coastguard Worker sub_file_blocks = [] 63*d9f75844SAndroid Build Coastguard Worker label_name = '' 64*d9f75844SAndroid Build Coastguard Worker prev_line = None 65*d9f75844SAndroid Build Coastguard Worker root_dir = os.path.dirname(os.path.abspath(source_file)) + '/' 66*d9f75844SAndroid Build Coastguard Worker _PrintOutput(root_dir, options) 67*d9f75844SAndroid Build Coastguard Worker lines = None 68*d9f75844SAndroid Build Coastguard Worker with open(source_file) as f: 69*d9f75844SAndroid Build Coastguard Worker lines = f.readlines() 70*d9f75844SAndroid Build Coastguard Worker mozilla_bundle = any(l.startswith(_MOZILLA_BUNDLE_CHECK) for l in lines) 71*d9f75844SAndroid Build Coastguard Worker for line in lines: 72*d9f75844SAndroid Build Coastguard Worker if line.startswith('#'): 73*d9f75844SAndroid Build Coastguard Worker if mozilla_bundle: 74*d9f75844SAndroid Build Coastguard Worker continue 75*d9f75844SAndroid Build Coastguard Worker if line.startswith('# Label: '): 76*d9f75844SAndroid Build Coastguard Worker sub_file_blocks.append(line) 77*d9f75844SAndroid Build Coastguard Worker label = re.search(r'\".*\"', line) 78*d9f75844SAndroid Build Coastguard Worker temp_label = label.group(0) 79*d9f75844SAndroid Build Coastguard Worker end = len(temp_label) - 1 80*d9f75844SAndroid Build Coastguard Worker label_name = _SafeName(temp_label[1:end]) 81*d9f75844SAndroid Build Coastguard Worker if mozilla_bundle and line.startswith('==='): 82*d9f75844SAndroid Build Coastguard Worker sub_file_blocks.append(line) 83*d9f75844SAndroid Build Coastguard Worker label_name = _SafeName(prev_line) 84*d9f75844SAndroid Build Coastguard Worker elif line.startswith('-----END CERTIFICATE-----'): 85*d9f75844SAndroid Build Coastguard Worker sub_file_blocks.append(line) 86*d9f75844SAndroid Build Coastguard Worker new_file_name = root_dir + _PREFIX + label_name + _EXTENSION 87*d9f75844SAndroid Build Coastguard Worker _PrintOutput('Generating: ' + new_file_name, options) 88*d9f75844SAndroid Build Coastguard Worker new_file = open(new_file_name, 'w') 89*d9f75844SAndroid Build Coastguard Worker for out_line in sub_file_blocks: 90*d9f75844SAndroid Build Coastguard Worker new_file.write(out_line) 91*d9f75844SAndroid Build Coastguard Worker new_file.close() 92*d9f75844SAndroid Build Coastguard Worker sub_file_blocks = [] 93*d9f75844SAndroid Build Coastguard Worker else: 94*d9f75844SAndroid Build Coastguard Worker sub_file_blocks.append(line) 95*d9f75844SAndroid Build Coastguard Worker prev_line = line 96*d9f75844SAndroid Build Coastguard Worker return root_dir, 'Mozilla' if mozilla_bundle else 'Google' 97*d9f75844SAndroid Build Coastguard Worker 98*d9f75844SAndroid Build Coastguard Worker 99*d9f75844SAndroid Build Coastguard Workerdef _GenCFiles(root_dir, options, bundle_type): 100*d9f75844SAndroid Build Coastguard Worker output_header_file = open(root_dir + _GENERATED_FILE, 'w') 101*d9f75844SAndroid Build Coastguard Worker output_header_file.write(_CreateOutputHeader(bundle_type)) 102*d9f75844SAndroid Build Coastguard Worker if options.full_cert: 103*d9f75844SAndroid Build Coastguard Worker subject_name_list = _CreateArraySectionHeader(_SUBJECT_NAME_VARIABLE, 104*d9f75844SAndroid Build Coastguard Worker _CHAR_TYPE, options) 105*d9f75844SAndroid Build Coastguard Worker public_key_list = _CreateArraySectionHeader(_PUBLIC_KEY_VARIABLE, 106*d9f75844SAndroid Build Coastguard Worker _CHAR_TYPE, options) 107*d9f75844SAndroid Build Coastguard Worker certificate_list = _CreateArraySectionHeader(_CERTIFICATE_VARIABLE, 108*d9f75844SAndroid Build Coastguard Worker _CHAR_TYPE, options) 109*d9f75844SAndroid Build Coastguard Worker certificate_size_list = _CreateArraySectionHeader(_CERTIFICATE_SIZE_VARIABLE, 110*d9f75844SAndroid Build Coastguard Worker _INT_TYPE, options) 111*d9f75844SAndroid Build Coastguard Worker 112*d9f75844SAndroid Build Coastguard Worker for _, _, files in os.walk(root_dir): 113*d9f75844SAndroid Build Coastguard Worker for current_file in files: 114*d9f75844SAndroid Build Coastguard Worker if current_file.startswith(_PREFIX): 115*d9f75844SAndroid Build Coastguard Worker prefix_length = len(_PREFIX) 116*d9f75844SAndroid Build Coastguard Worker length = len(current_file) - len(_EXTENSION) 117*d9f75844SAndroid Build Coastguard Worker label = current_file[prefix_length:length] 118*d9f75844SAndroid Build Coastguard Worker filtered_output, cert_size = _CreateCertSection(root_dir, current_file, 119*d9f75844SAndroid Build Coastguard Worker label, options) 120*d9f75844SAndroid Build Coastguard Worker output_header_file.write(filtered_output + '\n\n\n') 121*d9f75844SAndroid Build Coastguard Worker if options.full_cert: 122*d9f75844SAndroid Build Coastguard Worker subject_name_list += _AddLabelToArray(label, _SUBJECT_NAME_ARRAY) 123*d9f75844SAndroid Build Coastguard Worker public_key_list += _AddLabelToArray(label, _PUBLIC_KEY_ARRAY) 124*d9f75844SAndroid Build Coastguard Worker certificate_list += _AddLabelToArray(label, _CERTIFICATE_ARRAY) 125*d9f75844SAndroid Build Coastguard Worker certificate_size_list += (' %s,\n') % (cert_size) 126*d9f75844SAndroid Build Coastguard Worker 127*d9f75844SAndroid Build Coastguard Worker if options.full_cert: 128*d9f75844SAndroid Build Coastguard Worker subject_name_list += _CreateArraySectionFooter() 129*d9f75844SAndroid Build Coastguard Worker output_header_file.write(subject_name_list) 130*d9f75844SAndroid Build Coastguard Worker public_key_list += _CreateArraySectionFooter() 131*d9f75844SAndroid Build Coastguard Worker output_header_file.write(public_key_list) 132*d9f75844SAndroid Build Coastguard Worker certificate_list += _CreateArraySectionFooter() 133*d9f75844SAndroid Build Coastguard Worker output_header_file.write(certificate_list) 134*d9f75844SAndroid Build Coastguard Worker certificate_size_list += _CreateArraySectionFooter() 135*d9f75844SAndroid Build Coastguard Worker output_header_file.write(certificate_size_list) 136*d9f75844SAndroid Build Coastguard Worker output_header_file.write(_CreateOutputFooter()) 137*d9f75844SAndroid Build Coastguard Worker output_header_file.close() 138*d9f75844SAndroid Build Coastguard Worker 139*d9f75844SAndroid Build Coastguard Worker 140*d9f75844SAndroid Build Coastguard Workerdef _Cleanup(root_dir): 141*d9f75844SAndroid Build Coastguard Worker for f in os.listdir(root_dir): 142*d9f75844SAndroid Build Coastguard Worker if f.startswith(_PREFIX): 143*d9f75844SAndroid Build Coastguard Worker os.remove(root_dir + f) 144*d9f75844SAndroid Build Coastguard Worker 145*d9f75844SAndroid Build Coastguard Worker 146*d9f75844SAndroid Build Coastguard Workerdef _CreateCertSection(root_dir, source_file, label, options): 147*d9f75844SAndroid Build Coastguard Worker command = 'openssl x509 -in %s%s -noout -C' % (root_dir, source_file) 148*d9f75844SAndroid Build Coastguard Worker _PrintOutput(command, options) 149*d9f75844SAndroid Build Coastguard Worker output = subprocess.getstatusoutput(command)[1] 150*d9f75844SAndroid Build Coastguard Worker decl_block = 'unsigned char .*_(%s|%s|%s)' %\ 151*d9f75844SAndroid Build Coastguard Worker (_SUBJECT_NAME_ARRAY, _PUBLIC_KEY_ARRAY, _CERTIFICATE_ARRAY) 152*d9f75844SAndroid Build Coastguard Worker prog = re.compile(decl_block, re.IGNORECASE) 153*d9f75844SAndroid Build Coastguard Worker renamed_output = prog.sub('const unsigned char ' + label + r'_\1', output) 154*d9f75844SAndroid Build Coastguard Worker 155*d9f75844SAndroid Build Coastguard Worker filtered_output = '' 156*d9f75844SAndroid Build Coastguard Worker cert_block = '^const unsigned char.*?};$' 157*d9f75844SAndroid Build Coastguard Worker prog2 = re.compile(cert_block, re.IGNORECASE | re.MULTILINE | re.DOTALL) 158*d9f75844SAndroid Build Coastguard Worker if not options.full_cert: 159*d9f75844SAndroid Build Coastguard Worker filtered_output = prog2.sub('', renamed_output, count=2) 160*d9f75844SAndroid Build Coastguard Worker else: 161*d9f75844SAndroid Build Coastguard Worker filtered_output = renamed_output 162*d9f75844SAndroid Build Coastguard Worker 163*d9f75844SAndroid Build Coastguard Worker cert_size_block = r'\d\d\d+' 164*d9f75844SAndroid Build Coastguard Worker prog3 = re.compile(cert_size_block, re.MULTILINE | re.VERBOSE) 165*d9f75844SAndroid Build Coastguard Worker result = prog3.findall(renamed_output) 166*d9f75844SAndroid Build Coastguard Worker cert_size = result[len(result) - 1] 167*d9f75844SAndroid Build Coastguard Worker 168*d9f75844SAndroid Build Coastguard Worker return filtered_output, cert_size 169*d9f75844SAndroid Build Coastguard Worker 170*d9f75844SAndroid Build Coastguard Worker 171*d9f75844SAndroid Build Coastguard Workerdef _CreateOutputHeader(bundle_type): 172*d9f75844SAndroid Build Coastguard Worker output = ('/*\n' 173*d9f75844SAndroid Build Coastguard Worker ' * Copyright 2004 The WebRTC Project Authors. All rights ' 174*d9f75844SAndroid Build Coastguard Worker 'reserved.\n' 175*d9f75844SAndroid Build Coastguard Worker ' *\n' 176*d9f75844SAndroid Build Coastguard Worker ' * Use of this source code is governed by a BSD-style license\n' 177*d9f75844SAndroid Build Coastguard Worker ' * that can be found in the LICENSE file in the root of the ' 178*d9f75844SAndroid Build Coastguard Worker 'source\n' 179*d9f75844SAndroid Build Coastguard Worker ' * tree. An additional intellectual property rights grant can be ' 180*d9f75844SAndroid Build Coastguard Worker 'found\n' 181*d9f75844SAndroid Build Coastguard Worker ' * in the file PATENTS. All contributing project authors may\n' 182*d9f75844SAndroid Build Coastguard Worker ' * be found in the AUTHORS file in the root of the source tree.\n' 183*d9f75844SAndroid Build Coastguard Worker ' */\n\n' 184*d9f75844SAndroid Build Coastguard Worker '#ifndef RTC_BASE_SSL_ROOTS_H_\n' 185*d9f75844SAndroid Build Coastguard Worker '#define RTC_BASE_SSL_ROOTS_H_\n\n' 186*d9f75844SAndroid Build Coastguard Worker '// This file is the root certificates in C form.\n\n' 187*d9f75844SAndroid Build Coastguard Worker '// It was generated with the following script:\n' 188*d9f75844SAndroid Build Coastguard Worker '// tools_webrtc/sslroots/generate_sslroots.py' 189*d9f75844SAndroid Build Coastguard Worker ' %s_CA_bundle.pem\n\n' 190*d9f75844SAndroid Build Coastguard Worker '// clang-format off\n' 191*d9f75844SAndroid Build Coastguard Worker '// Don\'t bother formatting generated code,\n' 192*d9f75844SAndroid Build Coastguard Worker '// also it would breaks subject/issuer lines.\n\n' % bundle_type) 193*d9f75844SAndroid Build Coastguard Worker return output 194*d9f75844SAndroid Build Coastguard Worker 195*d9f75844SAndroid Build Coastguard Worker 196*d9f75844SAndroid Build Coastguard Workerdef _CreateOutputFooter(): 197*d9f75844SAndroid Build Coastguard Worker return '// clang-format on\n\n#endif // RTC_BASE_SSL_ROOTS_H_\n' 198*d9f75844SAndroid Build Coastguard Worker 199*d9f75844SAndroid Build Coastguard Worker 200*d9f75844SAndroid Build Coastguard Workerdef _CreateArraySectionHeader(type_name, type_type, options): 201*d9f75844SAndroid Build Coastguard Worker output = ('const %s kSSLCert%sList[] = {\n') % (type_type, type_name) 202*d9f75844SAndroid Build Coastguard Worker _PrintOutput(output, options) 203*d9f75844SAndroid Build Coastguard Worker return output 204*d9f75844SAndroid Build Coastguard Worker 205*d9f75844SAndroid Build Coastguard Worker 206*d9f75844SAndroid Build Coastguard Workerdef _AddLabelToArray(label, type_name): 207*d9f75844SAndroid Build Coastguard Worker return ' %s_%s,\n' % (label, type_name) 208*d9f75844SAndroid Build Coastguard Worker 209*d9f75844SAndroid Build Coastguard Worker 210*d9f75844SAndroid Build Coastguard Workerdef _CreateArraySectionFooter(): 211*d9f75844SAndroid Build Coastguard Worker return '};\n\n' 212*d9f75844SAndroid Build Coastguard Worker 213*d9f75844SAndroid Build Coastguard Worker 214*d9f75844SAndroid Build Coastguard Workerdef _SafeName(original_file_name): 215*d9f75844SAndroid Build Coastguard Worker bad_chars = ' -./\\()áéíőú\r\n' 216*d9f75844SAndroid Build Coastguard Worker replacement_chars = '' 217*d9f75844SAndroid Build Coastguard Worker for _ in bad_chars: 218*d9f75844SAndroid Build Coastguard Worker replacement_chars += '_' 219*d9f75844SAndroid Build Coastguard Worker translation_table = str.maketrans(bad_chars, replacement_chars) 220*d9f75844SAndroid Build Coastguard Worker return original_file_name.translate(translation_table) 221*d9f75844SAndroid Build Coastguard Worker 222*d9f75844SAndroid Build Coastguard Worker 223*d9f75844SAndroid Build Coastguard Workerdef _PrintOutput(output, options): 224*d9f75844SAndroid Build Coastguard Worker if options.verbose: 225*d9f75844SAndroid Build Coastguard Worker print(output) 226*d9f75844SAndroid Build Coastguard Worker 227*d9f75844SAndroid Build Coastguard Worker 228*d9f75844SAndroid Build Coastguard Workerif __name__ == '__main__': 229*d9f75844SAndroid Build Coastguard Worker main() 230