diff --git a/src/usr/local/www/system_camanager.php b/src/usr/local/www/system_camanager.php
index 70cb0ff947..3dfa3dcdf7 100644
--- a/src/usr/local/www/system_camanager.php
+++ b/src/usr/local/www/system_camanager.php
@@ -45,10 +45,7 @@ global $cert_strict_values;
$max_lifetime = cert_get_max_lifetime();
$default_lifetime = min(3650, $max_lifetime);
$openssl_ecnames = openssl_get_curve_names();
-
-if (isset($_REQUEST['id']) && is_numericint($_REQUEST['id'])) {
- $id = $_REQUEST['id'];
-}
+$class = "success";
init_config_arr(array('ca'));
$a_ca = &$config['ca'];
@@ -59,15 +56,20 @@ $a_cert = &$config['cert'];
init_config_arr(array('crl'));
$a_crl = &$config['crl'];
-if ($_REQUEST['act']) {
- $act = $_REQUEST['act'];
+$act = $_REQUEST['act'];
+
+if (isset($_REQUEST['id']) && ctype_alnum($_REQUEST['id'])) {
+ $id = $_REQUEST['id'];
+}
+if (!empty($id)) {
+ $thisca =& lookup_ca($id);
}
/* Actions other than 'new' require an ID.
* 'del' action must be submitted via POST. */
if ((!empty($act) &&
($act != 'new') &&
- !$a_ca[$id]) ||
+ !$thisca) ||
(($act == 'del') && empty($_POST))) {
pfSenseHeader("system_camanager.php");
exit;
@@ -75,39 +77,46 @@ if ((!empty($act) &&
switch ($act) {
case 'del':
- /* Only remove CA reference when deleting. It can be reconnected if a new matching CA is imported */
- $index = count($a_cert) - 1;
- for (;$index >= 0; $index--) {
- if ($a_cert[$index]['caref'] == $a_ca[$id]['refid']) {
- unset($a_cert[$index]['caref']);
+ $name = htmlspecialchars($thisca['descr']);
+ if (cert_in_use($id)) {
+ $savemsg = sprintf(gettext("Certificate %s is in use and cannot be deleted"), $name);
+ $class = "danger";
+ } else {
+ /* Only remove CA reference when deleting. It can be reconnected if a new matching CA is imported */
+ foreach ($a_cert as $cid => $acrt) {
+ if ($acrt['caref'] == $thisca['refid']) {
+ unset($a_cert[$cid]['caref']);
+ }
}
- }
- /* Remove any CRLs for this CA, there is no way to recover the connection once the CA has been removed. */
- $index = count($a_crl) - 1;
- for (;$index >= 0; $index--) {
- if ($a_crl[$index]['caref'] == $a_ca[$id]['refid']) {
- unset($a_crl[$index]);
+ /* Remove any CRLs for this CA, there is no way to recover the connection once the CA has been removed. */
+ foreach ($a_crl as $cid => $acrl) {
+ if ($acrl['caref'] == $thisca['refid']) {
+ unset($a_crl[$cid]);
+ }
}
+ /* Delete the CA */
+ foreach ($a_ca as $cid => $aca) {
+ if ($aca['refid'] == $thisca['refid']) {
+ unset($a_ca[$cid]);
+ }
+ }
+ $savemsg = sprintf(gettext("Deleted Certificate Authority %s and associated CRLs"), htmlspecialchars($name));
+ write_config($savemsg);
+ ca_setup_trust_store();
}
- $name = $a_ca[$id]['descr'];
- unset($a_ca[$id]);
- write_config();
- ca_setup_trust_store();
- $savemsg = sprintf(gettext("Certificate Authority %s and its CRLs (if any) successfully deleted."), htmlspecialchars($name));
- pfSenseHeader("system_camanager.php");
- exit;
+ unset($act);
break;
case 'edit':
/* Editing an existing CA, so populate values. */
$pconfig['method'] = 'existing';
- $pconfig['descr'] = $a_ca[$id]['descr'];
- $pconfig['refid'] = $a_ca[$id]['refid'];
- $pconfig['cert'] = base64_decode($a_ca[$id]['crt']);
- $pconfig['serial'] = $a_ca[$id]['serial'];
- $pconfig['trust'] = ($a_ca[$id]['trust'] == 'enabled');
- $pconfig['randomserial'] = ($a_ca[$id]['randomserial'] == 'enabled');
- if (!empty($a_ca[$id]['prv'])) {
- $pconfig['key'] = base64_decode($a_ca[$id]['prv']);
+ $pconfig['descr'] = $thisca['descr'];
+ $pconfig['refid'] = $thisca['refid'];
+ $pconfig['cert'] = base64_decode($thisca['crt']);
+ $pconfig['serial'] = $thisca['serial'];
+ $pconfig['trust'] = ($thisca['trust'] == 'enabled');
+ $pconfig['randomserial'] = ($thisca['randomserial'] == 'enabled');
+ if (!empty($thisca['prv'])) {
+ $pconfig['key'] = base64_decode($thisca['prv']);
}
break;
case 'new':
@@ -122,11 +131,11 @@ switch ($act) {
break;
case 'exp':
/* Exporting a ca */
- send_user_download('data', base64_decode($a_ca[$id]['crt']), "{$a_ca[$id]['descr']}.crt");
+ send_user_download('data', base64_decode($thisca['crt']), "{$thisca['descr']}.crt");
break;
case 'expkey':
/* Exporting a private key */
- send_user_download('data', base64_decode($a_ca[$id]['prv']), "{$a_ca[$id]['descr']}.key");
+ send_user_download('data', base64_decode($thisca['prv']), "{$thisca['descr']}.key");
break;
default:
break;
@@ -226,8 +235,8 @@ if ($_POST['save']) {
$ca['refid'] = $pconfig['refid'];
}
- if (isset($id) && $a_ca[$id]) {
- $ca = $a_ca[$id];
+ if (isset($id) && $thisca) {
+ $ca = $thisca;
}
$ca['descr'] = $pconfig['descr'];
@@ -242,10 +251,12 @@ if ($_POST['save']) {
if (!empty($pconfig['key'])) {
$ca['prv'] = base64_encode($pconfig['key']);
}
+ $savemsg = sprintf(gettext("Updated Certificate Authority %s"), $ca['descr']);
} else {
$old_err_level = error_reporting(0); /* otherwise openssl_ functions throw warnings directly to a page screwing menu tab */
if ($pconfig['method'] == "existing") {
ca_import($ca, $pconfig['cert'], $pconfig['key'], $pconfig['serial']);
+ $savemsg = sprintf(gettext("Imported Certificate Authority %s"), $ca['descr']);
} else if ($pconfig['method'] == "internal") {
$dn = array('commonName' => cert_escape_x509_chars($pconfig['dn_commonname']));
if (!empty($pconfig['dn_country'])) {
@@ -271,6 +282,7 @@ if ($_POST['save']) {
}
}
}
+ $savemsg = sprintf(gettext("Created internal Certificate Authority %s"), $ca['descr']);
} else if ($pconfig['method'] == "intermediate") {
$dn = array('commonName' => cert_escape_x509_chars($pconfig['dn_commonname']));
if (!empty($pconfig['dn_country'])) {
@@ -296,18 +308,19 @@ if ($_POST['save']) {
}
}
}
+ $savemsg = sprintf(gettext("Created internal intermediate Certificate Authority %s"), $ca['descr']);
}
error_reporting($old_err_level);
}
- if (isset($id) && $a_ca[$id]) {
- $a_ca[$id] = $ca;
+ if (isset($id) && $thisca) {
+ $thisca = $ca;
} else {
$a_ca[] = $ca;
}
if (!$input_errors) {
- write_config();
+ write_config($savemsg);
ca_setup_trust_store();
pfSenseHeader("system_camanager.php");
}
@@ -328,7 +341,7 @@ if ($input_errors) {
}
if ($savemsg) {
- print_info_box($savemsg, 'success');
+ print_info_box($savemsg, $class);
}
$tab_array = array();
@@ -397,7 +410,7 @@ $pluginparams['type'] = 'certificates';
$pluginparams['event'] = 'used_ca';
$certificates_used_by_packages = pkg_call_plugins('plugin_certificates', $pluginparams);
-foreach ($a_ca as $i => $ca):
+foreach ($a_ca as $ca):
$name = htmlspecialchars($ca['descr']);
$subj = cert_get_subject($ca['crt']);
$issuer = cert_get_issuer($ca['crt']);
@@ -453,16 +466,16 @@ foreach ($a_ca as $i => $ca):
- " href="system_camanager.php?act=edit&id==$i?>">
- " href="system_camanager.php?act=exp&id==$i?>">
+ " href="system_camanager.php?act=edit&id==$ca['refid']?>">
+ " href="system_camanager.php?act=exp&id==$ca['refid']?>">
- " href="system_camanager.php?act=expkey&id==$i?>">
+ " href="system_camanager.php?act=expkey&id==$ca['refid']?>">
">
- " href="system_camanager.php?act=del&id==$i?>" usepost >
+ " href="system_camanager.php?act=del&id==$ca['refid']?>" usepost >
|
@@ -540,7 +553,7 @@ events.push(function() {
$form = new Form;
//$form->setAction('system_camanager.php?act=edit');
-if (isset($id) && $a_ca[$id]) {
+if (isset($id) && $thisca) {
$form->addGlobal(new Form_Input(
'id',
null,
diff --git a/src/usr/local/www/system_certmanager.php b/src/usr/local/www/system_certmanager.php
index 11e27ae52f..b0edceddc9 100644
--- a/src/usr/local/www/system_certmanager.php
+++ b/src/usr/local/www/system_certmanager.php
@@ -52,6 +52,7 @@ global $cert_strict_values;
$max_lifetime = cert_get_max_lifetime();
$default_lifetime = min(3650, $max_lifetime);
$openssl_ecnames = openssl_get_curve_names();
+$class = "success";
if (isset($_REQUEST['userid']) && is_numericint($_REQUEST['userid'])) {
$userid = $_REQUEST['userid'];
@@ -63,10 +64,6 @@ if (isset($userid)) {
$a_user =& $config['system']['user'];
}
-if (isset($_REQUEST['id']) && is_numericint($_REQUEST['id'])) {
- $id = $_REQUEST['id'];
-}
-
init_config_arr(array('ca'));
$a_ca = &$config['ca'];
@@ -82,11 +79,18 @@ foreach ($a_ca as $ca) {
$act = $_REQUEST['act'];
+if (isset($_REQUEST['id']) && ctype_alnum($_REQUEST['id'])) {
+ $id = $_REQUEST['id'];
+}
+if (!empty($id)) {
+ $thiscert =& lookup_cert($id);
+}
+
/* Actions other than 'new' require an ID.
* 'del' action must be submitted via POST. */
if ((!empty($act) &&
($act != 'new') &&
- !$a_cert[$id]) ||
+ !$thiscert) ||
(($act == 'del') && empty($_POST))) {
pfSenseHeader("system_certmanager.php");
exit;
@@ -94,11 +98,21 @@ if ((!empty($act) &&
switch ($act) {
case 'del':
- unset($a_cert[$id]);
- write_config();
- $savemsg = sprintf(gettext("Certificate %s successfully deleted."), htmlspecialchars($a_cert[$id]['descr']));
- pfSenseHeader("system_certmanager.php");
- exit;
+ $name = htmlspecialchars($thiscert['descr']);
+ if (cert_in_use($id)) {
+ $savemsg = sprintf(gettext("Certificate %s is in use and cannot be deleted"), $name);
+ $class = "danger";
+ } else {
+ foreach ($a_cert as $cid => $acrt) {
+ if ($acrt['refid'] == $thiscert['refid']) {
+ unset($a_cert[$cid]);
+ }
+ }
+ $savemsg = sprintf(gettext("Deleted certificate %s"), $name);
+ write_config($savemsg);
+ }
+ unset($act);
+ break;
case 'new':
/* New certificate, so set default values */
$pconfig['method'] = $_POST['method'];
@@ -116,35 +130,35 @@ switch ($act) {
break;
case 'csr':
/* Editing a CSR, so populate values */
- $pconfig['descr'] = $a_cert[$id]['descr'];
- $pconfig['csr'] = base64_decode($a_cert[$id]['csr']);
+ $pconfig['descr'] = $thiscert['descr'];
+ $pconfig['csr'] = base64_decode($thiscert['csr']);
break;
case 'exp':
/* Exporting a certificate */
- send_user_download('data', base64_decode($a_cert[$id]['crt']), "{$a_cert[$id]['descr']}.crt");
+ send_user_download('data', base64_decode($thiscert['crt']), "{$thiscert['descr']}.crt");
break;
case 'req':
/* Exporting a certificate signing request */
- send_user_download('data', base64_decode($a_cert[$id]['csr']), "{$a_cert[$id]['descr']}.req");
+ send_user_download('data', base64_decode($thiscert['csr']), "{$thiscert['descr']}.req");
break;
case 'key':
/* Exporting a private key */
- send_user_download('data', base64_decode($a_cert[$id]['prv']), "{$a_cert[$id]['descr']}.key");
+ send_user_download('data', base64_decode($thiscert['prv']), "{$thiscert['descr']}.key");
break;
case 'p12':
/* Exporting a PKCS#12 file containing the certificate, key, and (if present) CA */
$args = array();
- $args['friendly_name'] = $a_cert[$id]['descr'];
- $ca = lookup_ca($a_cert[$id]['caref']);
+ $args['friendly_name'] = $thiscert['descr'];
+ $ca = lookup_ca($thiscert['caref']);
if ($ca) {
/* If the CA can be found, then add the CA to the container */
$args['extracerts'] = openssl_x509_read(base64_decode($ca['crt']));
}
- $res_crt = openssl_x509_read(base64_decode($a_cert[$id]['crt']));
- $res_key = openssl_pkey_get_private(base64_decode($a_cert[$id]['prv']));
+ $res_crt = openssl_x509_read(base64_decode($thiscert['crt']));
+ $res_key = openssl_pkey_get_private(base64_decode($thiscert['prv']));
$exp_data = "";
openssl_pkcs12_export($res_crt, $exp_data, $res_key, null, $args);
- send_user_download('data', $exp_data, "{$a_cert[$id]['descr']}.p12");
+ send_user_download('data', $exp_data, "{$thiscert['descr']}.p12");
break;
default:
break;
@@ -342,6 +356,7 @@ if ($_POST['save'] == gettext("Save")) {
$cert = lookup_cert($pconfig['certref']);
if ($cert && $a_user) {
$a_user[$userid]['cert'][] = $cert['refid'];
+ $savemsg = sprintf(gettext("Added certificate %s to user %s"), $cert['descr'], $a_user[$userid]['name']);
}
} elseif ($pconfig['method'] == "sign") { // Sign a CSR
$csrid = lookup_cert($pconfig['csrtosign']);
@@ -379,13 +394,14 @@ if ($_POST['save'] == gettext("Save")) {
// Add it to the config file
$config['cert'][] = $newcert;
+ $savemsg = sprintf(gettext("Signed certificate %s"), $newcert['descr']);
}
} else {
$cert = array();
$cert['refid'] = uniqid();
- if (isset($id) && $a_cert[$id]) {
- $cert = $a_cert[$id];
+ if (isset($id) && $thiscert) {
+ $cert = $thiscert;
}
$cert['descr'] = $pconfig['descr'];
@@ -394,6 +410,7 @@ if ($_POST['save'] == gettext("Save")) {
if ($pconfig['method'] == "import") {
cert_import($cert, $pconfig['cert'], $pconfig['key']);
+ $savemsg = sprintf(gettext("Imported certificate %s"), $cert['descr']);
}
if ($pconfig['method'] == "internal") {
@@ -439,6 +456,7 @@ if ($_POST['save'] == gettext("Save")) {
}
}
}
+ $savemsg = sprintf(gettext("Created internal certificate %s"), $cert['descr']);
}
if ($pconfig['method'] == "external") {
@@ -484,12 +502,13 @@ if ($_POST['save'] == gettext("Save")) {
}
}
}
+ $savemsg = sprintf(gettext("Created certificate signing request %s"), $cert['descr']);
}
error_reporting($old_err_level);
- if (isset($id) && $a_cert[$id]) {
- $a_cert[$id] = $cert;
+ if (isset($id) && $thiscert) {
+ $thiscert = $cert;
} else {
$a_cert[] = $cert;
}
@@ -500,7 +519,7 @@ if ($_POST['save'] == gettext("Save")) {
}
if (!$input_errors) {
- write_config();
+ write_config($savemsg);
}
if ((isset($userid) && is_numeric($userid)) && !$input_errors) {
@@ -536,11 +555,12 @@ if ($_POST['save'] == gettext("Save")) {
/* save modifications */
if (!$input_errors) {
- $cert = $a_cert[$id];
+ $cert = $thiscert;
$cert['descr'] = $pconfig['descr'];
csr_complete($cert, $pconfig['cert']);
- $a_cert[$id] = $cert;
- write_config();
+ $thiscert = $cert;
+ $savemsg = sprintf(gettext("Updated certificate signing request %s"), $pconfig['descr']);
+ write_config($savemsg);
pfSenseHeader("system_certmanager.php");
}
}
@@ -560,7 +580,7 @@ if ($input_errors) {
}
if ($savemsg) {
- print_info_box($savemsg, 'success');
+ print_info_box($savemsg, $class);
}
$tab_array = array();
@@ -571,7 +591,7 @@ display_top_tabs($tab_array);
if ($act == "new" || (($_POST['save'] == gettext("Save")) && $input_errors)) {
$form = new Form();
- $form->setAction('system_certmanager.php?act=edit');
+ $form->setAction('system_certmanager.php');
if (isset($userid) && $a_user) {
$form->addGlobal(new Form_Input(
@@ -582,7 +602,7 @@ if ($act == "new" || (($_POST['save'] == gettext("Save")) && $input_errors)) {
));
}
- if (isset($id) && $a_cert[$id]) {
+ if (isset($id) && $thiscert) {
$form->addGlobal(new Form_Input(
'id',
null,
@@ -607,7 +627,7 @@ if ($act == "new" || (($_POST['save'] == gettext("Save")) && $input_errors)) {
'*Descriptive name',
'text',
($a_user && empty($pconfig['descr'])) ? $a_user[$userid]['name'] : $pconfig['descr']
- ))->addClass('toggle-internal toggle-import toggle-external toggle-sign collapse');
+ ))->addClass('toggle-internal toggle-import toggle-external toggle-sign toggle-existing collapse');
$form->add($section);
@@ -1080,7 +1100,7 @@ if ($act == "new" || (($_POST['save'] == gettext("Save")) && $input_errors)) {
))->setWidth(7)
->setHelp('Paste the certificate received from the certificate authority here.');
- if (isset($id) && $a_cert[$id]) {
+ if (isset($id) && $thiscert) {
$form->addGlobal(new Form_Input(
'id',
null,
@@ -1164,8 +1184,7 @@ $pluginparams = array();
$pluginparams['type'] = 'certificates';
$pluginparams['event'] = 'used_certificates';
$certificates_used_by_packages = pkg_call_plugins('plugin_certificates', $pluginparams);
-$i = 0;
-foreach ($a_cert as $i => $cert):
+foreach ($a_cert as $cert):
if (!is_array($cert) || empty($cert)) {
continue;
}
@@ -1244,26 +1263,25 @@ foreach ($a_cert as $i => $cert):
- ">
+ ">
- ">
+ ">
">
- ">
+ ">
- ">
- ">
- ">
+ ">
+ ">
+ ">
- " usepost>
+ " usepost>
|
diff --git a/src/usr/local/www/system_crlmanager.php b/src/usr/local/www/system_crlmanager.php
index 4445c6972c..1da88aa04a 100644
--- a/src/usr/local/www/system_crlmanager.php
+++ b/src/usr/local/www/system_crlmanager.php
@@ -56,6 +56,7 @@ $a_cert = &$config['cert'];
init_config_arr(array('crl'));
$a_crl = &$config['crl'];
+/* Clean up blank entries missing a reference ID */
foreach ($a_crl as $cid => $acrl) {
if (!isset($acrl['refid'])) {
unset ($a_crl[$cid]);