]> git.saurik.com Git - apple/security.git/blob - SecurityTool/macOS/keychain_lock.c
Security-59754.60.13.tar.gz
[apple/security.git] / SecurityTool / macOS / keychain_lock.c
1 /*
2 * Copyright (c) 2003-2004,2012,2014 Apple Inc. All Rights Reserved.
3 *
4 * @APPLE_LICENSE_HEADER_START@
5 *
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
11 * file.
12 *
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
20 *
21 * @APPLE_LICENSE_HEADER_END@
22 *
23 * keychain_lock.c
24 */
25
26 #include "keychain_lock.h"
27
28 #include "keychain_utilities.h"
29 #include "readline_cssm.h"
30 #include "security_tool.h"
31
32 #include <stdio.h>
33 #include <stdlib.h>
34 #include <string.h>
35 #include <unistd.h>
36 #include <Security/SecKeychain.h>
37
38 static int
39 do_lock_all(void)
40 {
41 OSStatus result = SecKeychainLockAll();
42 if (result) {
43 sec_perror("SecKeychainLockAll", result);
44 }
45
46 return result;
47 }
48
49 static int
50 do_lock(const char *keychainName)
51 {
52 SecKeychainRef keychain = NULL;
53 OSStatus result;
54
55 if (keychainName)
56 {
57 keychain = keychain_open(keychainName);
58 if (!keychain)
59 {
60 result = 1;
61 goto loser;
62 }
63 }
64
65 result = SecKeychainLock(keychain);
66 if (result)
67 {
68 sec_error("SecKeychainLock %s: %s", keychainName ? keychainName : "<NULL>", sec_errstr(result));
69 }
70
71 loser:
72 if (keychain)
73 CFRelease(keychain);
74
75 return result;
76 }
77
78 int
79 keychain_lock(int argc, char * const *argv)
80 {
81 char *keychainName = NULL;
82 int ch, result = 0;
83 Boolean lockAll = FALSE;
84 while ((ch = getopt(argc, argv, "ah")) != -1)
85 {
86 switch (ch)
87 {
88 case 'a':
89 lockAll = TRUE;
90 break;
91 case '?':
92 default:
93 return SHOW_USAGE_MESSAGE;
94 }
95 }
96 argc -= optind;
97 argv += optind;
98
99 if (argc == 1 && !lockAll)
100 {
101 keychainName = argv[0];
102 if (*keychainName == '\0')
103 {
104 result = 2;
105 goto loser;
106 }
107 }
108 else if (argc != 0)
109 return SHOW_USAGE_MESSAGE;
110
111 if (lockAll)
112 result = do_lock_all();
113 else
114 result = do_lock(keychainName);
115
116 loser:
117
118 return result;
119 }