2 * Copyright (c) 2013-2016 Apple Inc. All Rights Reserved.
4 * @APPLE_LICENSE_HEADER_START@
6 * This file contains Original Code and/or Modifications of Original Code
7 * as defined in and that are subject to the Apple Public Source License
8 * Version 2.0 (the 'License'). You may not use this file except in
9 * compliance with the License. Please obtain a copy of the License at
10 * http://www.opensource.apple.com/apsl/ and read it before using this
13 * The Original Code and all software distributed under the License are
14 * distributed on an 'AS IS' basis, WITHOUT WARRANTY OF ANY KIND, EITHER
15 * EXPRESS OR IMPLIED, AND APPLE HEREBY DISCLAIMS ALL SUCH WARRANTIES,
16 * INCLUDING WITHOUT LIMITATION, ANY WARRANTIES OF MERCHANTABILITY,
17 * FITNESS FOR A PARTICULAR PURPOSE, QUIET ENJOYMENT OR NON-INFRINGEMENT.
18 * Please see the License for the specific language governing rights and
19 * limitations under the License.
21 * @APPLE_LICENSE_HEADER_END@
24 #import <Foundation/Foundation.h>
25 #include "recovery_key.h"
30 #include <utilities/SecCFWrappers.h>
32 #include <Security/SecureObjectSync/SOSCloudCircle.h>
33 #include <Security/SecureObjectSync/SOSCloudCircleInternal.h>
34 #include <Security/SecRecoveryKey.h>
36 #import <CoreCDP/CoreCDP.h>
39 #include "secToolFileIO.h"
42 recovery_key(int argc, char * const *argv)
45 CFErrorRef error = NULL;
46 BOOL hadError = false;
47 SOSLogSetOutputTo(NULL, NULL);
49 static struct option long_options[] =
51 /* These options set a flag. */
52 {"recovery-string", no_argument, NULL, 'R' },
53 {"generate", required_argument, NULL, 'G'},
54 {"set", required_argument, NULL, 's'},
55 {"get", no_argument, NULL, 'g'},
56 {"clear", no_argument, NULL, 'c'},
57 {"follow-up", no_argument, NULL, 'F'},
58 {"verifier", no_argument, NULL, 'V'},
63 while ((ch = getopt_long(argc, argv, "FG:Rs:gcV:", long_options, &option_index)) != -1)
66 NSError *nserror = NULL;
67 NSString *testString = [NSString stringWithUTF8String:optarg];
69 return SHOW_USAGE_MESSAGE;
71 SecRecoveryKey *rk = SecRKCreateRecoveryKeyWithError(testString, &nserror);
73 printmsg(CFSTR("SecRKCreateRecoveryKeyWithError: %@\n"), nserror);
74 return SHOW_USAGE_MESSAGE;
76 NSData *publicKey = SecRKCopyBackupPublicKey(rk);
78 return SHOW_USAGE_MESSAGE;
80 printmsg(CFSTR("example (not registered) public recovery key: %@\n"), publicKey);
84 NSString *testString = SecRKCreateRecoveryKeyString(NULL);
86 return SHOW_USAGE_MESSAGE;
88 printmsg(CFSTR("public recovery string: %@\n"), testString);
94 NSError *nserror = NULL;
95 NSString *testString = [NSString stringWithUTF8String:optarg];
97 return SHOW_USAGE_MESSAGE;
99 SecRecoveryKey *rk = SecRKCreateRecoveryKeyWithError(testString, &nserror);
101 printmsg(CFSTR("SecRKCreateRecoveryKeyWithError: %@\n"), nserror);
102 return SHOW_USAGE_MESSAGE;
105 CFErrorRef cferror = NULL;
106 if(!SecRKRegisterBackupPublicKey(rk, &cferror)) {
107 printmsg(CFSTR("Error from SecRKRegisterBackupPublicKey: %@\n"), cferror);
108 CFReleaseNull(cferror);
109 return SHOW_USAGE_MESSAGE;
115 CFDataRef recovery_key = SOSCCCopyRecoveryPublicKey(&error);
116 hadError = recovery_key == NULL;
118 printmsg(CFSTR("recovery key: %@\n"), recovery_key);
119 CFReleaseNull(recovery_key);
124 hadError = SOSCCRegisterRecoveryPublicKey(NULL, &error) != true;
129 NSError *localError = nil;
131 CDPFollowUpController *cdpd = [[CDPFollowUpController alloc] init];
133 CDPFollowUpContext *context = [CDPFollowUpContext contextForRecoveryKeyRepair];
134 context.force = true;
136 secnotice("followup", "Posting a follow up (for SOS) of type recovery key");
137 [cdpd postFollowUpWithContext:context error:&localError];
139 printmsg(CFSTR("Request to CoreCDP to follow up failed: %@\n"), localError);
141 printmsg(CFSTR("CoreCDP handling follow up\n"));
146 NSError *localError = nil;
147 NSString *testString = [NSString stringWithUTF8String:optarg];
148 NSString *fileName = [NSString stringWithFormat:@"%@.plist", testString];
149 if(testString == nil)
150 return SHOW_USAGE_MESSAGE;
152 NSDictionary *ver = SecRKCopyAccountRecoveryVerifier(testString, &localError);
154 printmsg(CFSTR("Failed to make verifier dictionary: %@\n"), localError);
155 return SHOW_USAGE_MESSAGE;
158 printmsg(CFSTR("Verifier Dictionary: %@\n\n"), ver);
159 printmsg(CFSTR("Writing plist to %@\n"), (__bridge CFStringRef) fileName);
161 [ver writeToFile:fileName atomically:YES];
169 printf("%s [...options]\n", getprogname());
170 for (unsigned n = 0; n < sizeof(long_options)/sizeof(long_options[0]); n++) {
171 printf("\t [-%c|--%s\n", long_options[n].val, long_options[n].name);
173 return SHOW_USAGE_MESSAGE;
177 printerr(CFSTR("Error: %@\n"), error);