Module Name: src
Committed By: agc
Date: Sat Mar 13 23:30:41 UTC 2010
Modified Files:
src/crypto/external/bsd/netpgp/dist: TODO configure configure.ac tst
src/crypto/external/bsd/netpgp/dist/include: netpgp.h
src/crypto/external/bsd/netpgp/dist/src/lib: create.c keyring.c
keyring.h netpgp.c packet-print.c packet.h reader.c ssh2pgp.c
version.h
src/crypto/external/bsd/netpgp/dist/src/netpgp: Makefile
src/crypto/external/bsd/netpgp/dist/src/netpgpkeys: netpgpkeys.1
netpgpkeys.c
src/crypto/external/bsd/netpgp/dist/src/netpgpverify: Makefile verify.c
src/crypto/external/bsd/netpgp/lib: config.h shlib_version
Log Message:
Changes to 2.99.1/20100313
+ add functionality to parse basic signature subkeys
+ in doing so, add expiration of keys
+ at the same time, add revocation of keys
+ recognise the primary user id, and use it when displaying user ids
+ recognise self signed keys and subkeys
+ rework the indentation of output
+ add the --list-sigs [userid] option to netpgpkeys(1)
+ use memcmp(3) rather than strcmp(3) when checking binary user ids to
be exported
+ add expiration display to subkey signature output
+ update libnetpgp library version major number to 3
To generate a diff of this commit:
cvs rdiff -u -r1.34 -r1.35 src/crypto/external/bsd/netpgp/dist/TODO
cvs rdiff -u -r1.26 -r1.27 src/crypto/external/bsd/netpgp/dist/configure
cvs rdiff -u -r1.27 -r1.28 src/crypto/external/bsd/netpgp/dist/configure.ac
cvs rdiff -u -r1.20 -r1.21 src/crypto/external/bsd/netpgp/dist/tst
cvs rdiff -u -r1.16 -r1.17 \
src/crypto/external/bsd/netpgp/dist/include/netpgp.h
cvs rdiff -u -r1.23 -r1.24 \
src/crypto/external/bsd/netpgp/dist/src/lib/create.c
cvs rdiff -u -r1.32 -r1.33 \
src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c
cvs rdiff -u -r1.22 -r1.23 \
src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h
cvs rdiff -u -r1.42 -r1.43 \
src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c
cvs rdiff -u -r1.28 -r1.29 \
src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c
cvs rdiff -u -r1.19 -r1.20 \
src/crypto/external/bsd/netpgp/dist/src/lib/packet.h
cvs rdiff -u -r1.31 -r1.32 \
src/crypto/external/bsd/netpgp/dist/src/lib/reader.c
cvs rdiff -u -r1.8 -r1.9 \
src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c
cvs rdiff -u -r1.29 -r1.30 \
src/crypto/external/bsd/netpgp/dist/src/lib/version.h
cvs rdiff -u -r1.11 -r1.12 \
src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile
cvs rdiff -u -r1.5 -r1.6 \
src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1
cvs rdiff -u -r1.8 -r1.9 \
src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c
cvs rdiff -u -r1.10 -r1.11 \
src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile
cvs rdiff -u -r1.6 -r1.7 \
src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c
cvs rdiff -u -r1.3 -r1.4 src/crypto/external/bsd/netpgp/lib/config.h \
src/crypto/external/bsd/netpgp/lib/shlib_version
Please note that diffs are not public domain; they are subject to the
copyright notices on the relevant files.
Modified files:
Index: src/crypto/external/bsd/netpgp/dist/TODO
diff -u src/crypto/external/bsd/netpgp/dist/TODO:1.34 src/crypto/external/bsd/netpgp/dist/TODO:1.35
--- src/crypto/external/bsd/netpgp/dist/TODO:1.34 Mon Mar 8 07:37:23 2010
+++ src/crypto/external/bsd/netpgp/dist/TODO Sat Mar 13 23:30:40 2010
@@ -1,13 +1,10 @@
To Do
=====
-add revocation information to public key display
agent
agentctl
-trust subpackets
make netpgpkeys work - add, import, commit, update, sign, passphrase
convert to and from ascii armored sigs
gpgme compat lib
---list-sigs - these come out in __ops_check_subkey_sig()
return userids from successful verify, and then print id out if required
is get_passphrase_cb needed?
error logging
@@ -93,3 +90,6 @@
hkpclient
netbsd/pkgsrc pr 42922
add expiry information to public key display
+trust subpackets
+add revocation information to public key display
+--list-sigs - these come out in __ops_check_subkey_sig()
Index: src/crypto/external/bsd/netpgp/dist/configure
diff -u src/crypto/external/bsd/netpgp/dist/configure:1.26 src/crypto/external/bsd/netpgp/dist/configure:1.27
--- src/crypto/external/bsd/netpgp/dist/configure:1.26 Mon Mar 8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/configure Sat Mar 13 23:30:40 2010
@@ -1,7 +1,7 @@
#! /bin/sh
-# From configure.ac Revision: 1.26 .
+# From configure.ac Revision: 1.27 .
# Guess values for system-dependent variables and create Makefiles.
-# Generated by GNU Autoconf 2.63 for netpgp 20100307.
+# Generated by GNU Autoconf 2.63 for netpgp 20100313.
#
# Report bugs to <Alistair Crooks <[email protected]> c0596823>.
#
@@ -751,8 +751,8 @@
# Identity of this package.
PACKAGE_NAME='netpgp'
PACKAGE_TARNAME='netpgp'
-PACKAGE_VERSION='20100307'
-PACKAGE_STRING='netpgp 20100307'
+PACKAGE_VERSION='20100313'
+PACKAGE_STRING='netpgp 20100313'
PACKAGE_BUGREPORT='Alistair Crooks <[email protected]> c0596823'
ac_unique_file="src/netpgp/netpgp.c"
@@ -1483,7 +1483,7 @@
# Omit some internal or obsolete options to make the list less imposing.
# This message is too long to be a string in the A/UX 3.1 sh.
cat <<_ACEOF
-\`configure' configures netpgp 20100307 to adapt to many kinds of systems.
+\`configure' configures netpgp 20100313 to adapt to many kinds of systems.
Usage: $0 [OPTION]... [VAR=VALUE]...
@@ -1553,7 +1553,7 @@
if test -n "$ac_init_help"; then
case $ac_init_help in
- short | recursive ) echo "Configuration of netpgp 20100307:";;
+ short | recursive ) echo "Configuration of netpgp 20100313:";;
esac
cat <<\_ACEOF
@@ -1660,7 +1660,7 @@
test -n "$ac_init_help" && exit $ac_status
if $ac_init_version; then
cat <<\_ACEOF
-netpgp configure 20100307
+netpgp configure 20100313
generated by GNU Autoconf 2.63
Copyright (C) 1992, 1993, 1994, 1995, 1996, 1998, 1999, 2000, 2001,
@@ -1674,7 +1674,7 @@
This file contains any messages produced by compilers while
running configure, to aid debugging if configure makes a mistake.
-It was created by netpgp $as_me 20100307, which was
+It was created by netpgp $as_me 20100313, which was
generated by GNU Autoconf 2.63. Invocation command line was
$ $0 $@
@@ -2561,7 +2561,7 @@
# Define the identity of the package.
PACKAGE='netpgp'
- VERSION='20100307'
+ VERSION='20100313'
cat >>confdefs.h <<_ACEOF
@@ -22306,7 +22306,7 @@
# report actual input values of CONFIG_FILES etc. instead of their
# values after options handling.
ac_log="
-This file was extended by netpgp $as_me 20100307, which was
+This file was extended by netpgp $as_me 20100313, which was
generated by GNU Autoconf 2.63. Invocation command line was
CONFIG_FILES = $CONFIG_FILES
@@ -22369,7 +22369,7 @@
_ACEOF
cat >>$CONFIG_STATUS <<_ACEOF || ac_write_fail=1
ac_cs_version="\\
-netpgp config.status 20100307
+netpgp config.status 20100313
configured by $0, generated by GNU Autoconf 2.63,
with options \\"`$as_echo "$ac_configure_args" | sed 's/^ //; s/[\\""\`\$]/\\\\&/g'`\\"
Index: src/crypto/external/bsd/netpgp/dist/configure.ac
diff -u src/crypto/external/bsd/netpgp/dist/configure.ac:1.27 src/crypto/external/bsd/netpgp/dist/configure.ac:1.28
--- src/crypto/external/bsd/netpgp/dist/configure.ac:1.27 Mon Mar 8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/configure.ac Sat Mar 13 23:30:40 2010
@@ -1,10 +1,10 @@
-# $NetBSD: configure.ac,v 1.27 2010/03/08 07:37:24 agc Exp $
+# $NetBSD: configure.ac,v 1.28 2010/03/13 23:30:40 agc Exp $
#
# Process this file with autoconf to produce a configure script.
-AC_INIT([netpgp],[20100307],[Alistair Crooks <[email protected]> c0596823])
+AC_INIT([netpgp],[20100313],[Alistair Crooks <[email protected]> c0596823])
AC_PREREQ(2.63)
-AC_REVISION([$Revision: 1.27 $])
+AC_REVISION([$Revision: 1.28 $])
AS_SHELL_SANITIZE
Index: src/crypto/external/bsd/netpgp/dist/tst
diff -u src/crypto/external/bsd/netpgp/dist/tst:1.20 src/crypto/external/bsd/netpgp/dist/tst:1.21
--- src/crypto/external/bsd/netpgp/dist/tst:1.20 Fri Mar 5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/tst Sat Mar 13 23:30:40 2010
@@ -31,7 +31,7 @@
su root -c "make install"'
passed=0
-total=26
+total=27
echo "======> sign/verify 180938 file"
cp configure a
/usr/bin/netpgp --sign a
@@ -121,5 +121,7 @@
/usr/bin/netpgp --sign --duration 2 --detached h
sleep 3
/usr/bin/netpgp --verify h.sig || passed=$(expr $passed + 1)
+echo "======> list signatures and subkey signatures"
+/usr/bin/netpgpkeys --list-sigs && passed=$(expr $passed + 1)
rm -f a a.gpg b b.gpg c c.gpg d d.gpg e f f.sig g g.asc g2 a2 a3 a4 a5 h h.sig
echo "Passed ${passed}/${total} tests"
Index: src/crypto/external/bsd/netpgp/dist/include/netpgp.h
diff -u src/crypto/external/bsd/netpgp/dist/include/netpgp.h:1.16 src/crypto/external/bsd/netpgp/dist/include/netpgp.h:1.17
--- src/crypto/external/bsd/netpgp/dist/include/netpgp.h:1.16 Fri Mar 5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/include/netpgp.h Sat Mar 13 23:30:40 2010
@@ -72,7 +72,7 @@
int netpgp_set_homedir(netpgp_t *, char *, const char *, const int);
/* key management */
-int netpgp_list_keys(netpgp_t *);
+int netpgp_list_keys(netpgp_t *, const int);
int netpgp_find_key(netpgp_t *, char *);
char *netpgp_get_key(netpgp_t *, const char *, const char *);
char *netpgp_export_key(netpgp_t *, char *);
@@ -92,7 +92,7 @@
int netpgp_decrypt_memory(netpgp_t *, const void *, const size_t, char *, size_t, const int);
/* match and hkp-related functions */
-int netpgp_match_keys(netpgp_t *, char *, const char *, void *);
+int netpgp_match_keys(netpgp_t *, char *, const char *, void *, const int);
int netpgp_match_pubkeys(netpgp_t *, char *, void *);
int netpgp_validate_sigs(netpgp_t *);
Index: src/crypto/external/bsd/netpgp/dist/src/lib/create.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/create.c:1.23 src/crypto/external/bsd/netpgp/dist/src/lib/create.c:1.24
--- src/crypto/external/bsd/netpgp/dist/src/lib/create.c:1.23 Fri Mar 5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/create.c Sat Mar 13 23:30:41 2010
@@ -57,7 +57,7 @@
#if defined(__NetBSD__)
__COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: create.c,v 1.23 2010/03/05 16:01:09 agc Exp $");
+__RCSID("$NetBSD: create.c,v 1.24 2010/03/13 23:30:41 agc Exp $");
#endif
#include <sys/types.h>
@@ -518,7 +518,7 @@
unsigned
__ops_write_xfer_pubkey(__ops_output_t *output,
- const __ops_key_t *keydata,
+ const __ops_key_t *key,
const unsigned armoured)
{
unsigned i, j;
@@ -527,30 +527,20 @@
__ops_writer_push_armoured(output, OPS_PGP_PUBLIC_KEY_BLOCK);
}
/* public key */
- if (!write_struct_pubkey(output, &keydata->key.seckey.pubkey)) {
+ if (!write_struct_pubkey(output, &key->key.seckey.pubkey)) {
return 0;
}
/* TODO: revocation signatures go here */
/* user ids and corresponding signatures */
- for (i = 0; i < keydata->uidc; i++) {
- __ops_userid_t *uid = &keydata->uids[i];
-
- if (!__ops_write_struct_userid(output, uid)) {
+ for (i = 0; i < key->uidc; i++) {
+ if (!__ops_write_struct_userid(output, &key->uids[i])) {
return 0;
}
-
- /* find signature for this packet if it exists */
- for (j = 0; j < keydata->sigc; j++) {
- sigpacket_t *sig = &keydata->sigs[i];
-
- if (strcmp((char *) sig->userid->userid,
- (char *) uid->userid) == 0) {
- if (!__ops_write(output, sig->packet->raw,
- sig->packet->length)) {
- return 0;
- }
+ for (j = 0; j < key->packetc; j++) {
+ if (!__ops_write(output, key->packets[j].raw, key->packets[j].length)) {
+ return 0;
}
}
}
@@ -584,7 +574,7 @@
unsigned
__ops_write_xfer_seckey(__ops_output_t *output,
- const __ops_key_t *keydata,
+ const __ops_key_t *key,
const uint8_t *passphrase,
const size_t pplen,
unsigned armoured)
@@ -595,7 +585,7 @@
__ops_writer_push_armoured(output, OPS_PGP_PRIVATE_KEY_BLOCK);
}
/* public key */
- if (!__ops_write_struct_seckey(&keydata->key.seckey, passphrase,
+ if (!__ops_write_struct_seckey(&key->key.seckey, passphrase,
pplen, output)) {
return 0;
}
@@ -603,23 +593,13 @@
/* TODO: revocation signatures go here */
/* user ids and corresponding signatures */
- for (i = 0; i < keydata->uidc; i++) {
- __ops_userid_t *uid = &keydata->uids[i];
-
- if (!__ops_write_struct_userid(output, uid)) {
+ for (i = 0; i < key->uidc; i++) {
+ if (!__ops_write_struct_userid(output, &key->uids[i])) {
return 0;
}
-
- /* find signature for this packet if it exists */
- for (j = 0; j < keydata->sigc; j++) {
- sigpacket_t *sig = &keydata->sigs[i];
-
- if (strcmp((char *) sig->userid->userid,
- (char *) uid->userid) == 0) {
- if (!__ops_write(output, sig->packet->raw,
- sig->packet->length)) {
- return 0;
- }
+ for (j = 0; j < key->packetc; j++) {
+ if (!__ops_write(output, key->packets[j].raw, key->packets[j].length)) {
+ return 0;
}
}
}
Index: src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c:1.32 src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c:1.33
--- src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c:1.32 Fri Mar 12 01:22:01 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/keyring.c Sat Mar 13 23:30:41 2010
@@ -57,7 +57,7 @@
#if defined(__NetBSD__)
__COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: keyring.c,v 1.32 2010/03/12 01:22:01 agc Exp $");
+__RCSID("$NetBSD: keyring.c,v 1.33 2010/03/13 23:30:41 agc Exp $");
#endif
#ifdef HAVE_FCNTL_H
@@ -480,36 +480,6 @@
/**
\ingroup Core_Keys
-\brief Add signed User ID to key
-\param keydata Key to which to add signed User ID
-\param userid User ID to add
-\param sigpacket Packet to add
-*/
-void
-__ops_add_signed_userid(__ops_key_t *keydata,
- const __ops_userid_t *userid,
- const __ops_subpacket_t *sigpacket)
-{
- __ops_subpacket_t *pkt;
- __ops_userid_t *uid;
-
- uid = __ops_add_userid(keydata, userid);
- pkt = __ops_add_subpacket(keydata, sigpacket);
-
- /*
- * add entry in sigs array to link the userid and sigpacket
- * and add ptr to it from the sigs array */
- EXPAND_ARRAY(keydata, sig);
-
- /**setup new entry in array */
- keydata->sigs[keydata->sigc].userid = uid;
- keydata->sigs[keydata->sigc].packet = pkt;
-
- keydata->sigc++;
-}
-
-/**
-\ingroup Core_Keys
\brief Add selfsigned User ID to key
\param keydata Key to which to add user ID
\param userid Self-signed User ID to add
@@ -551,7 +521,8 @@
sigpacket.raw = __ops_mem_data(mem_sig);
/* add userid to keydata */
- __ops_add_signed_userid(keydata, userid, &sigpacket);
+ (void) __ops_add_userid(keydata, userid);
+ (void) __ops_add_subpacket(keydata, &sigpacket);
/* cleanup */
__ops_create_sig_delete(sig);
@@ -583,7 +554,6 @@
}
}
-
/* used to point to data during keyring read */
typedef struct keyringcb_t {
__ops_keyring_t *keyring; /* the keyring we're reading */
@@ -594,6 +564,8 @@
cb_keyring_read(const __ops_packet_t *pkt, __ops_cbdata_t *cbinfo)
{
__ops_keyring_t *keyring;
+ __ops_revoke_t *revocation;
+ __ops_key_t *key;
keyringcb_t *cb;
cb = __ops_callback_arg(cbinfo);
@@ -602,11 +574,27 @@
case OPS_PARSER_PTAG:
case OPS_PTAG_CT_ENCRYPTED_SECRET_KEY:
/* we get these because we didn't prompt */
+ break;
case OPS_PTAG_CT_SIGNATURE_HEADER:
- case OPS_PTAG_CT_SIGNATURE_FOOTER:
+ key = &keyring->keys[keyring->keyc - 1];
+ EXPAND_ARRAY(key, subsig);
+ key->subsigs[key->subsigc].uid = key->uidc - 1;
+ (void) memcpy(&key->subsigs[key->subsigc].sig, &pkt->u.sig,
+ sizeof(pkt->u.sig));
+ key->subsigc += 1;
+ break;
case OPS_PTAG_CT_SIGNATURE:
+ key = &keyring->keys[keyring->keyc - 1];
+ EXPAND_ARRAY(key, subsig);
+ key->subsigs[key->subsigc].uid = key->uidc - 1;
+ (void) memcpy(&key->subsigs[key->subsigc].sig, &pkt->u.sig,
+ sizeof(pkt->u.sig));
+ key->subsigc += 1;
+ break;
case OPS_PTAG_CT_TRUST:
- case OPS_PARSER_ERRCODE:
+ key = &keyring->keys[keyring->keyc - 1];
+ key->subsigs[key->subsigc - 1].trustlevel = pkt->u.ss_trust.level;
+ key->subsigs[key->subsigc - 1].trustamount = pkt->u.ss_trust.amount;
break;
case OPS_PTAG_SS_KEY_EXPIRY:
EXPAND_ARRAY(keyring, key);
@@ -614,6 +602,47 @@
keyring->keys[keyring->keyc - 1].key.pubkey.duration = pkt->u.ss_time.time;
}
break;
+ case OPS_PTAG_SS_ISSUER_KEY_ID:
+ key = &keyring->keys[keyring->keyc - 1];
+ (void) memcpy(&key->subsigs[key->subsigc - 1].sig.info.signer_id,
+ pkt->u.ss_issuer.key_id,
+ sizeof(pkt->u.ss_issuer.key_id));
+ key->subsigs[key->subsigc - 1].sig.info.signer_id_set = 1;
+ break;
+ case OPS_PTAG_SS_CREATION_TIME:
+ key = &keyring->keys[keyring->keyc - 1];
+ key->subsigs[key->subsigc - 1].sig.info.birthtime = pkt->u.ss_time.time;
+ key->subsigs[key->subsigc - 1].sig.info.birthtime_set = 1;
+ break;
+ case OPS_PTAG_SS_EXPIRATION_TIME:
+ key = &keyring->keys[keyring->keyc - 1];
+ key->subsigs[key->subsigc - 1].sig.info.duration = pkt->u.ss_time.time;
+ key->subsigs[key->subsigc - 1].sig.info.duration_set = 1;
+ break;
+ case OPS_PTAG_SS_PRIMARY_USER_ID:
+ key = &keyring->keys[keyring->keyc - 1];
+ key->uid0 = key->uidc - 1;
+ break;
+ case OPS_PTAG_SS_REVOCATION_REASON:
+ key = &keyring->keys[keyring->keyc - 1];
+ if (key->uidc == 0) {
+ /* revoke whole key */
+ key->revoked = 1;
+ revocation = &key->revocation;
+ } else {
+ /* revoke the user id */
+ EXPAND_ARRAY(key, revoke);
+ revocation = &key->revokes[key->revokec];
+ key->revokes[key->revokec].uid = key->uidc - 1;
+ key->revokec += 1;
+ }
+ revocation->code = pkt->u.ss_revocation.code;
+ revocation->reason = netpgp_strdup(__ops_show_ss_rr_code(pkt->u.ss_revocation.code));
+ break;
+ case OPS_PTAG_CT_SIGNATURE_FOOTER:
+ case OPS_PARSER_ERRCODE:
+ break;
+
default:
break;
}
@@ -968,7 +997,7 @@
\return none
*/
int
-__ops_keyring_list(__ops_io_t *io, const __ops_keyring_t *keyring)
+__ops_keyring_list(__ops_io_t *io, const __ops_keyring_t *keyring, const int psigs)
{
__ops_key_t *key;
unsigned n;
@@ -977,16 +1006,17 @@
(keyring->keyc == 1) ? "" : "s");
for (n = 0, key = keyring->keys; n < keyring->keyc; ++n, ++key) {
if (__ops_is_key_secret(key)) {
- __ops_print_keydata(io, key, "sec",
- &key->key.seckey.pubkey);
+ __ops_print_keydata(io, keyring, key, "sec",
+ &key->key.seckey.pubkey, 0);
} else {
- __ops_print_keydata(io, key, "pub", &key->key.pubkey);
+ __ops_print_keydata(io, keyring, key, "pub", &key->key.pubkey, psigs);
}
(void) fputc('\n', io->res);
}
return 1;
}
+
/* this interface isn't right - hook into callback for getting passphrase */
char *
__ops_export_key(__ops_io_t *io, const __ops_key_t *keydata, uint8_t *passphrase)
Index: src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h:1.22 src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h:1.23
--- src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h:1.22 Fri Mar 5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/keyring.h Sat Mar 13 23:30:41 2010
@@ -93,7 +93,7 @@
unsigned __ops_keyring_fileread(__ops_keyring_t *, const unsigned,
const char *);
-int __ops_keyring_list(__ops_io_t *, const __ops_keyring_t *);
+int __ops_keyring_list(__ops_io_t *, const __ops_keyring_t *, const int);
void __ops_set_seckey(__ops_contents_t *, const __ops_key_t *);
void __ops_forget(void *, unsigned);
@@ -106,9 +106,6 @@
__ops_userid_t *__ops_add_userid(__ops_key_t *, const __ops_userid_t *);
__ops_subpacket_t *__ops_add_subpacket(__ops_key_t *,
const __ops_subpacket_t *);
-void __ops_add_signed_userid(__ops_key_t *,
- const __ops_userid_t *,
- const __ops_subpacket_t *);
unsigned __ops_add_selfsigned_userid(__ops_key_t *, __ops_userid_t *);
@@ -119,12 +116,15 @@
void __ops_pkeyid(FILE *, const uint8_t *, size_t);
-int __ops_sprint_keydata(const __ops_key_t *, char **, const char *,
- const __ops_pubkey_t *);
+int __ops_sprint_keydata(__ops_io_t *, const __ops_keyring_t *,
+ const __ops_key_t *, char **, const char *,
+ const __ops_pubkey_t *, const int);
int __ops_hkp_sprint_keydata(const __ops_key_t *, char **,
const __ops_pubkey_t *);
-void __ops_print_keydata(__ops_io_t *, const __ops_key_t *,
- const char *, const __ops_pubkey_t *);
+void __ops_print_keydata(__ops_io_t *, const __ops_keyring_t *, const __ops_key_t *,
+ const char *, const __ops_pubkey_t *, const int);
+void __ops_print_sig(__ops_io_t *, const __ops_key_t *, const char *,
+ const __ops_pubkey_t *);
void __ops_print_pubkey(const __ops_pubkey_t *);
int __ops_sprint_pubkey(const __ops_key_t *, char *, size_t);
Index: src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c:1.42 src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c:1.43
--- src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c:1.42 Fri Mar 5 16:30:05 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/netpgp.c Sat Mar 13 23:30:41 2010
@@ -34,7 +34,7 @@
#if defined(__NetBSD__)
__COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: netpgp.c,v 1.42 2010/03/05 16:30:05 agc Exp $");
+__RCSID("$NetBSD: netpgp.c,v 1.43 2010/03/13 23:30:41 agc Exp $");
#endif
#include <sys/types.h>
@@ -163,7 +163,7 @@
pubkey = __ops_getkeybyid(io, ring,
(const uint8_t *) res->valid_sigs[i].signer_id,
&from);
- __ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+ __ops_print_keydata(io, ring, pubkey, "pub", &pubkey->key.pubkey, 0);
}
}
@@ -534,9 +534,9 @@
/* list the keys in a keyring */
int
-netpgp_list_keys(netpgp_t *netpgp)
+netpgp_list_keys(netpgp_t *netpgp, const int psigs)
{
- return __ops_keyring_list(netpgp->io, netpgp->pubring);
+ return __ops_keyring_list(netpgp->io, netpgp->pubring, psigs);
}
DEFINE_ARRAY(strings_t, char *);
@@ -547,7 +547,7 @@
/* find and list some keys in a keyring */
int
-netpgp_match_keys(netpgp_t *netpgp, char *name, const char *fmt, void *vp)
+netpgp_match_keys(netpgp_t *netpgp, char *name, const char *fmt, void *vp, const int psigs)
{
const __ops_key_t *key;
unsigned k;
@@ -570,10 +570,10 @@
key, &pubs.v[pubs.c],
&key->key.pubkey);
} else {
- __ops_sprint_keydata(
+ __ops_sprint_keydata(netpgp->io, netpgp->pubring,
key, &pubs.v[pubs.c],
"pub",
- &key->key.pubkey);
+ &key->key.pubkey, psigs);
}
pubs.c += 1;
k += 1;
@@ -662,8 +662,9 @@
return (__ops_hkp_sprint_keydata(key, &newkey,
&key->key.pubkey) > 0) ? newkey : NULL;
}
- return (__ops_sprint_keydata(key, &newkey, "pub",
- &key->key.pubkey) > 0) ? newkey : NULL;
+ return (__ops_sprint_keydata(netpgp->io, netpgp->pubring,
+ key, &newkey, "pub",
+ &key->key.pubkey, 0) > 0) ? newkey : NULL;
}
/* export a given key */
@@ -706,7 +707,7 @@
f);
return 0;
}
- return __ops_keyring_list(io, netpgp->pubring);
+ return __ops_keyring_list(io, netpgp->pubring, 0);
}
/* generate a new key */
@@ -876,10 +877,10 @@
if (pubkey == NULL) {
(void) fprintf(io->errs,
"netpgp: warning - using pubkey from secring\n");
- __ops_print_keydata(io, keypair, "pub",
- &keypair->key.seckey.pubkey);
+ __ops_print_keydata(io, netpgp->pubring, keypair, "pub",
+ &keypair->key.seckey.pubkey, 0);
} else {
- __ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+ __ops_print_keydata(io, netpgp->pubring, pubkey, "pub", &pubkey->key.pubkey, 0);
}
}
if (netpgp_getvar(netpgp, "ssh keys") == NULL) {
@@ -989,10 +990,10 @@
if (pubkey == NULL) {
(void) fprintf(io->errs,
"netpgp: warning - using pubkey from secring\n");
- __ops_print_keydata(io, keypair, "pub",
- &keypair->key.seckey.pubkey);
+ __ops_print_keydata(io, netpgp->pubring, keypair, "pub",
+ &keypair->key.seckey.pubkey, 0);
} else {
- __ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+ __ops_print_keydata(io, netpgp->pubring, pubkey, "pub", &pubkey->key.pubkey, 0);
}
}
/* now decrypt key */
Index: src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c:1.28 src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c:1.29
--- src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c:1.28 Mon Mar 8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/packet-print.c Sat Mar 13 23:30:41 2010
@@ -58,7 +58,7 @@
#if defined(__NetBSD__)
__COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: packet-print.c,v 1.28 2010/03/08 07:37:24 agc Exp $");
+__RCSID("$NetBSD: packet-print.c,v 1.29 2010/03/13 23:30:41 agc Exp $");
#endif
#include <string.h>
@@ -382,28 +382,60 @@
return dest;
}
+/* print the sub key binding signature info */
+static int
+psubkeybinding(char *buf, size_t size, __ops_subsig_t *subsig, const __ops_pubkey_t *pubkey, char *expired)
+{
+ char keyid[512];
+ char t[32];
+
+ return snprintf(buf, size, "sub %d/%s %s %s %s\n",
+ numkeybits(pubkey),
+ __ops_show_pka(subsig->sig.info.key_alg),
+ strhexdump(keyid, subsig->sig.info.signer_id, OPS_KEY_ID_SIZE, ""),
+ ptimestr(t, sizeof(t), subsig->sig.info.birthtime),
+ expired);
+}
+
+static int
+isrevoked(const __ops_key_t *key, unsigned uid)
+{
+ unsigned r;
+
+ for (r = 0 ; r < key->revokec ; r++) {
+ if (key->revokes[r].uid == uid) {
+ return r;
+ }
+ }
+ return -1;
+}
+
#ifndef KB
#define KB(x) ((x) * 1024)
#endif
/* print into a string (malloc'ed) the pubkeydata */
int
-__ops_sprint_keydata(const __ops_key_t *key, char **buf, const char *header,
- const __ops_pubkey_t *pubkey)
-{
- unsigned i;
- time_t now;
- char uidbuf[KB(128)];
- char keyid[OPS_KEY_ID_SIZE * 3];
- char fp[(OPS_FINGERPRINT_SIZE * 3) + 1];
- char expired[128];
- char t[32];
- int cc;
- int n;
+__ops_sprint_keydata(__ops_io_t *io, const __ops_keyring_t *keyring,
+ const __ops_key_t *key, char **buf, const char *header,
+ const __ops_pubkey_t *pubkey, const int psigs)
+{
+ const __ops_key_t *trustkey;
+ unsigned from;
+ unsigned i;
+ unsigned j;
+ time_t now;
+ char uidbuf[KB(128)];
+ char keyid[OPS_KEY_ID_SIZE * 3];
+ char fp[(OPS_FINGERPRINT_SIZE * 3) + 1];
+ char expired[128];
+ char t[32];
+ int cc;
+ int n;
+ int r;
- for (i = 0, n = 0; i < key->uidc; i++) {
- n += snprintf(&uidbuf[n], sizeof(uidbuf) - n,
- "uid %s\n", key->uids[i].userid);
+ if (key->revoked) {
+ return -1;
}
now = time(NULL);
if (pubkey->duration > 0) {
@@ -417,6 +449,41 @@
} else {
expired[0] = 0x0;
}
+ for (i = 0, n = 0; i < key->uidc; i++) {
+ if ((r = isrevoked(key, i)) >= 0 &&
+ key->revokes[r].code == OPS_REVOCATION_COMPROMISED) {
+ continue;
+ }
+ n += snprintf(&uidbuf[n], sizeof(uidbuf) - n, "uid%s%s%s\n",
+ (psigs) ? " " : " ",
+ key->uids[i].userid,
+ (isrevoked(key, i) >= 0) ? " [REVOKED]" : "");
+ for (j = 0 ; j < key->subsigc ; j++) {
+ if (psigs) {
+ if (key->subsigs[j].uid != i) {
+ continue;
+ }
+ } else {
+ if (!(key->subsigs[j].sig.info.version == 4 &&
+ key->subsigs[j].sig.info.type == OPS_SIG_SUBKEY &&
+ i == key->uidc - 1)) {
+ continue;
+ }
+ }
+ from = 0;
+ trustkey = __ops_getkeybyid(io, keyring, key->subsigs[j].sig.info.signer_id, &from);
+ if (key->subsigs[j].sig.info.version == 4 &&
+ key->subsigs[j].sig.info.type == OPS_SIG_SUBKEY) {
+ psubkeybinding(&uidbuf[n], sizeof(uidbuf) - n, &key->subsigs[j], pubkey, expired);
+ } else {
+ n += snprintf(&uidbuf[n], sizeof(uidbuf) - n,
+ "sig %s %s %s\n",
+ strhexdump(keyid, key->subsigs[j].sig.info.signer_id, OPS_KEY_ID_SIZE, ""),
+ ptimestr(t, sizeof(t), key->subsigs[j].sig.info.birthtime),
+ (trustkey) ? (char *)trustkey->uids[trustkey->uid0].userid : "[unknown]");
+ }
+ }
+ }
return __ops_asprintf(buf, "%s %d/%s %s %s %s\nKey fingerprint: %s\n%s",
header,
numkeybits(pubkey),
@@ -455,12 +522,13 @@
/* print the key data for a pub or sec key */
void
-__ops_print_keydata(__ops_io_t *io, const __ops_key_t *key, const char *header,
- const __ops_pubkey_t *pubkey)
+__ops_print_keydata(__ops_io_t *io, const __ops_keyring_t *keyring,
+ const __ops_key_t *key, const char *header,
+ const __ops_pubkey_t *pubkey, const int psigs)
{
char *cp;
- if (__ops_sprint_keydata(key, &cp, header, pubkey)) {
+ if (__ops_sprint_keydata(io, keyring, key, &cp, header, pubkey, psigs) >= 0) {
(void) fprintf(io->res, "%s", cp);
free(cp);
}
Index: src/crypto/external/bsd/netpgp/dist/src/lib/packet.h
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/packet.h:1.19 src/crypto/external/bsd/netpgp/dist/src/lib/packet.h:1.20
--- src/crypto/external/bsd/netpgp/dist/src/lib/packet.h:1.19 Fri Mar 5 16:01:09 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/packet.h Sat Mar 13 23:30:41 2010
@@ -296,6 +296,14 @@
* with errcode returned */
} __ops_content_tag_t;
+enum {
+ OPS_REVOCATION_NO_REASON = 0,
+ OPS_REVOCATION_SUPERSEDED = 1,
+ OPS_REVOCATION_COMPROMISED = 2,
+ OPS_REVOCATION_RETIRED = 3,
+ OPS_REVOCATION_NO_LONGER_VALID = 0x20
+};
+
typedef __ops_content_tag_t __ops_packet_tag_t;
typedef __ops_content_tag_t __ops_ss_type_t;
@@ -757,7 +765,6 @@
} __ops_ss_embedded_sig_t;
/** __ops_subpacket_t */
-
typedef struct __ops_subpacket_t {
size_t length;
uint8_t *raw;
@@ -1077,12 +1084,18 @@
#define EXPAND_ARRAY(str, arr) do { \
if (str->arr##c == str->arr##vsize) { \
void *__newarr; \
- str->arr##vsize = (str->arr##vsize * 2) + 10; \
- if ((__newarr = realloc(str->arr##s, \
- str->arr##vsize * sizeof(*str->arr##s))) == NULL) { \
+ char *__newarrc; \
+ unsigned __newsize; \
+ __newsize = (str->arr##vsize * 2) + 10; \
+ if ((__newarrc = __newarr = realloc(str->arr##s, \
+ __newsize * sizeof(*str->arr##s))) == NULL) { \
(void) fprintf(stderr, "EXPAND_ARRAY - bad realloc\n"); \
+ } else { \
+ (void) memset(&__newarrc[str->arr##vsize * sizeof(*str->arr##s)], \
+ 0x0, (__newsize - str->arr##vsize) * sizeof(*str->arr##s)); \
+ str->arr##s = __newarr; \
+ str->arr##vsize = __newsize; \
} \
- str->arr##s = __newarr; \
} \
} while(/*CONSTCOND*/0)
@@ -1094,24 +1107,40 @@
} __ops_keydata_key_t;
-/** sigpacket_t */
+/* sigpacket_t */
typedef struct {
__ops_userid_t *userid;
__ops_subpacket_t *packet;
} sigpacket_t;
-/* XXX: gonna have to expand this to hold onto subkeys, too... */
-/** \struct __ops_keydata
- * \todo expand to hold onto subkeys
- */
+/* user revocation info */
+typedef struct __ops_revoke_t {
+ uint32_t uid; /* index in uid array */
+ uint8_t code; /* revocation code */
+ char *reason; /* c'mon, spill the beans */
+} __ops_revoke_t;
+
+/** signature subpackets */
+typedef struct __ops_subsig_t {
+ uint32_t uid; /* index in userid array in key */
+ __ops_sig_t sig; /* trust signature */
+ uint8_t trustlevel; /* level of trust */
+ uint8_t trustamount; /* amount of trust */
+} __ops_subsig_t;
+
+/* describes a user's key */
struct __ops_key_t {
- DYNARRAY(__ops_userid_t, uid);
- DYNARRAY(__ops_subpacket_t, packet);
- DYNARRAY(sigpacket_t, sig);
+ DYNARRAY(__ops_userid_t, uid); /* array of user ids */
+ DYNARRAY(__ops_subpacket_t, packet); /* array of raw subpackets */
+ DYNARRAY(__ops_subsig_t, subsig); /* array of signature subkeys */
+ DYNARRAY(__ops_revoke_t, revoke); /* array of signature revocations */
uint8_t key_id[OPS_KEY_ID_SIZE];
- __ops_fingerprint_t fingerprint;
- __ops_content_tag_t type;
- __ops_keydata_key_t key;
+ __ops_fingerprint_t fingerprint; /* pgp fingerprint */
+ __ops_content_tag_t type; /* type of key */
+ __ops_keydata_key_t key; /* pubkey/seckey data */
+ uint32_t uid0; /* primary uid index in uids array */
+ uint8_t revoked;
+ __ops_revoke_t revocation;
};
#define MDC_PKT_TAG 0xd3
Index: src/crypto/external/bsd/netpgp/dist/src/lib/reader.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/reader.c:1.31 src/crypto/external/bsd/netpgp/dist/src/lib/reader.c:1.32
--- src/crypto/external/bsd/netpgp/dist/src/lib/reader.c:1.31 Fri Mar 5 16:01:10 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/reader.c Sat Mar 13 23:30:41 2010
@@ -54,7 +54,7 @@
#if defined(__NetBSD__)
__COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: reader.c,v 1.31 2010/03/05 16:01:10 agc Exp $");
+__RCSID("$NetBSD: reader.c,v 1.32 2010/03/13 23:30:41 agc Exp $");
#endif
#include <sys/types.h>
@@ -2243,7 +2243,7 @@
keypair = cbinfo->cryptinfo.keydata;
do {
/* print out the user id */
- __ops_print_keydata(io, pubkey, "pub", &pubkey->key.pubkey);
+ __ops_print_keydata(io, cbinfo->cryptinfo.pubring,pubkey, "pub", &pubkey->key.pubkey, 0);
/* now decrypt key */
secret = __ops_decrypt_seckey(keypair, cbinfo->passfp);
if (secret == NULL) {
@@ -2279,8 +2279,8 @@
if (cbinfo->cryptinfo.keydata == NULL) {
(void) fprintf(io->errs, "get_passphrase_cb: NULL keydata\n");
} else {
- __ops_print_keydata(io, cbinfo->cryptinfo.keydata, "pub",
- &cbinfo->cryptinfo.keydata->key.pubkey);
+ __ops_print_keydata(io, cbinfo->cryptinfo.pubring, cbinfo->cryptinfo.keydata, "pub",
+ &cbinfo->cryptinfo.keydata->key.pubkey, 0);
}
switch (pkt->tag) {
case OPS_GET_PASSPHRASE:
Index: src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c:1.8 src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c:1.9
--- src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c:1.8 Fri Mar 5 16:01:10 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/ssh2pgp.c Sat Mar 13 23:30:41 2010
@@ -333,7 +333,8 @@
__ops_fingerprint(&key->fingerprint, pubkey);
free(userid.userid);
if (__ops_get_debug_level(__FILE__)) {
- __ops_print_keydata(io, key, "pub", pubkey);
+ /*__ops_print_keydata(io, keyring, key, "pub", pubkey, 0);*/
+ __OPS_USED(io); /* XXX */
}
}
(void) free(bin);
@@ -358,7 +359,8 @@
return 0;
}
if (__ops_get_debug_level(__FILE__)) {
- __ops_print_keydata(io, key, "sec", &key->key.seckey.pubkey);
+ /*__ops_print_keydata(io, key, "sec", &key->key.seckey.pubkey, 0);*/
+ /* XXX */
}
/* let's add some sane defaults */
(void) memcpy(&key->key.seckey.pubkey, pubkey, sizeof(*pubkey));
Index: src/crypto/external/bsd/netpgp/dist/src/lib/version.h
diff -u src/crypto/external/bsd/netpgp/dist/src/lib/version.h:1.29 src/crypto/external/bsd/netpgp/dist/src/lib/version.h:1.30
--- src/crypto/external/bsd/netpgp/dist/src/lib/version.h:1.29 Mon Mar 8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/lib/version.h Sat Mar 13 23:30:41 2010
@@ -58,7 +58,7 @@
#endif
/* development versions have .99 suffix */
-#define NETPGP_BASE_VERSION "1.99.22"
+#define NETPGP_BASE_VERSION "2.99.1"
#define NETPGP_VERSION_CAT(a, b) "NetPGP portable " a "/[" b "]"
#define NETPGP_VERSION_STRING \
Index: src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile:1.11 src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile:1.12
--- src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile:1.11 Mon Mar 8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgp/Makefile Sat Mar 13 23:30:41 2010
@@ -117,16 +117,16 @@
PACKAGE = netpgp
PACKAGE_BUGREPORT = Alistair Crooks <[email protected]> c0596823
PACKAGE_NAME = netpgp
-PACKAGE_STRING = netpgp 20100307
+PACKAGE_STRING = netpgp 20100313
PACKAGE_TARNAME = netpgp
-PACKAGE_VERSION = 20100307
+PACKAGE_VERSION = 20100313
PATH_SEPARATOR = :
RANLIB = ranlib
SED = /usr/bin/sed
SET_MAKE =
SHELL = /bin/ksh
STRIP = strip
-VERSION = 20100307
+VERSION = 20100313
WARNCFLAGS = -Werror -Wall -Wpointer-arith
abs_builddir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgp
abs_srcdir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgp
Index: src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1:1.5 src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1:1.6
--- src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1:1.5 Sat Feb 6 02:24:34 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.1 Sat Mar 13 23:30:41 2010
@@ -1,6 +1,6 @@
-.\" $NetBSD: netpgpkeys.1,v 1.5 2010/02/06 02:24:34 agc Exp $
+.\" $NetBSD: netpgpkeys.1,v 1.6 2010/03/13 23:30:41 agc Exp $
.\"
-.\" Copyright (c) 2009 The NetBSD Foundation, Inc.
+.\" Copyright (c) 2009, 2010 The NetBSD Foundation, Inc.
.\" All rights reserved.
.\"
.\" This manual page is derived from software contributed to
@@ -27,7 +27,7 @@
.\" ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
.\" POSSIBILITY OF SUCH DAMAGE.
.\"
-.Dd December 4, 2009
+.Dd March 13, 2010
.Dt NETPGPKEYS 1
.Os
.Sh NAME
@@ -55,6 +55,10 @@
.Op options
.Ar file ...
.Nm
+.Fl Fl list-sigs
+.Op options
+.Ar file ...
+.Nm
.Fl Fl version
.Pp
where the options for all commands are:
@@ -165,6 +169,10 @@
.It Fl Fl list-keys
List all the public keys in the current keyring.
If no keyring is provided, the user's public keyring is used.
+.It Fl Fl list-sigs
+List all the public keys in the current keyring, along with
+the sub-key signatures which provide the key with trust.
+If no keyring is provided, the user's public keyring is used.
.It Fl Fl version
Print the version information from the
.Xr libnetpgp 3
Index: src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c:1.8 src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c:1.9
--- src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c:1.8 Fri Mar 5 16:01:10 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpkeys/netpgpkeys.c Sat Mar 13 23:30:41 2010
@@ -53,6 +53,7 @@
"\t--generate-key [options] OR\n"
"\t--import-key [options] OR\n"
"\t--list-keys [options] OR\n"
+ "\t--list-sigs [options] OR\n"
"\t--get-key keyid [options] OR\n"
"\t--version\n"
"where options are:\n"
@@ -65,6 +66,7 @@
enum optdefs {
/* commands */
LIST_KEYS = 1,
+ LIST_SIGS,
FIND_KEY,
EXPORT_KEY,
IMPORT_KEY,
@@ -95,6 +97,7 @@
static struct option options[] = {
/* key-management commands */
{"list-keys", no_argument, NULL, LIST_KEYS},
+ {"list-sigs", no_argument, NULL, LIST_SIGS},
{"find-key", no_argument, NULL, FIND_KEY},
{"export-key", no_argument, NULL, EXPORT_KEY},
{"import-key", no_argument, NULL, IMPORT_KEY},
@@ -148,7 +151,9 @@
switch (p->cmd) {
case LIST_KEYS:
- return (f == NULL) ? netpgp_list_keys(netpgp) : netpgp_match_keys(netpgp, f, "human", stdout);
+ return (f == NULL) ? netpgp_list_keys(netpgp, 0) : netpgp_match_keys(netpgp, f, "human", stdout, 0);
+ case LIST_SIGS:
+ return (f == NULL) ? netpgp_list_keys(netpgp, 1) : netpgp_match_keys(netpgp, f, "human", stdout, 1);
case FIND_KEY:
return netpgp_find_key(netpgp, netpgp_getvar(netpgp, "userid"));
case EXPORT_KEY:
@@ -205,9 +210,6 @@
optindex = 0;
while ((ch = getopt_long(argc, argv, "", options, &optindex)) != -1) {
switch (options[optindex].val) {
- case LIST_KEYS:
- p.cmd = options[optindex].val;
- break;
case COREDUMPS:
netpgp_setvar(&netpgp, "coredumps", "allowed");
p.cmd = options[optindex].val;
@@ -216,6 +218,8 @@
netpgp_setvar(&netpgp, "userid checks", "skip");
p.cmd = options[optindex].val;
break;
+ case LIST_KEYS:
+ case LIST_SIGS:
case FIND_KEY:
case EXPORT_KEY:
case IMPORT_KEY:
Index: src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile:1.10 src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile:1.11
--- src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile:1.10 Mon Mar 8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpverify/Makefile Sat Mar 13 23:30:41 2010
@@ -117,16 +117,16 @@
PACKAGE = netpgp
PACKAGE_BUGREPORT = Alistair Crooks <[email protected]> c0596823
PACKAGE_NAME = netpgp
-PACKAGE_STRING = netpgp 20100307
+PACKAGE_STRING = netpgp 20100313
PACKAGE_TARNAME = netpgp
-PACKAGE_VERSION = 20100307
+PACKAGE_VERSION = 20100313
PATH_SEPARATOR = :
RANLIB = ranlib
SED = /usr/bin/sed
SET_MAKE =
SHELL = /bin/ksh
STRIP = strip
-VERSION = 20100307
+VERSION = 20100313
WARNCFLAGS = -Werror -Wall -Wpointer-arith
abs_builddir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgpverify
abs_srcdir = /usr/src/crypto/external/bsd/netpgp/dist/src/netpgpverify
Index: src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c
diff -u src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c:1.6 src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c:1.7
--- src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c:1.6 Mon Mar 8 07:37:24 2010
+++ src/crypto/external/bsd/netpgp/dist/src/netpgpverify/verify.c Sat Mar 13 23:30:41 2010
@@ -55,7 +55,7 @@
#if defined(__NetBSD__)
__COPYRIGHT("@(#) Copyright (c) 2009 The NetBSD Foundation, Inc. All rights reserved.");
-__RCSID("$NetBSD: verify.c,v 1.6 2010/03/08 07:37:24 agc Exp $");
+__RCSID("$NetBSD: verify.c,v 1.7 2010/03/13 23:30:41 agc Exp $");
#endif
#include <sys/types.h>
@@ -161,7 +161,7 @@
#undef USE_SHA384
/* development versions have .99 suffix */
-#define NETPGP_BASE_VERSION "1.99.22"
+#define NETPGP_BASE_VERSION "2.99.1"
#define NETPGP_VERSION_CAT(a, b) "NetPGP portable " a "/[" b "]"
#define NETPGP_VERSION_STRING \
Index: src/crypto/external/bsd/netpgp/lib/config.h
diff -u src/crypto/external/bsd/netpgp/lib/config.h:1.3 src/crypto/external/bsd/netpgp/lib/config.h:1.4
--- src/crypto/external/bsd/netpgp/lib/config.h:1.3 Tue Dec 22 06:03:25 2009
+++ src/crypto/external/bsd/netpgp/lib/config.h Sat Mar 13 23:30:41 2010
@@ -125,19 +125,19 @@
#define PACKAGE_NAME "netpgp"
/* Define to the full name and version of this package. */
-#define PACKAGE_STRING "netpgp 20091221"
+#define PACKAGE_STRING "netpgp 20100313"
/* Define to the one symbol short name of this package. */
#define PACKAGE_TARNAME "netpgp"
/* Define to the version of this package. */
-#define PACKAGE_VERSION "20091221"
+#define PACKAGE_VERSION "20100313"
/* Define to 1 if you have the ANSI C header files. */
#define STDC_HEADERS 1
/* Version number of package */
-#define VERSION "20091221"
+#define VERSION "20100313"
/* Define for Solaris 2.5.1 so the uint32_t typedef from <sys/synch.h>,
<pthread.h>, or <semaphore.h> is not used. If the typedef were allowed, the
Index: src/crypto/external/bsd/netpgp/lib/shlib_version
diff -u src/crypto/external/bsd/netpgp/lib/shlib_version:1.3 src/crypto/external/bsd/netpgp/lib/shlib_version:1.4
--- src/crypto/external/bsd/netpgp/lib/shlib_version:1.3 Mon Jul 20 17:30:52 2009
+++ src/crypto/external/bsd/netpgp/lib/shlib_version Sat Mar 13 23:30:41 2010
@@ -1,2 +1,2 @@
-major=2
+major=3
minor=0