2015-10-06 21:16:39 +02:00
|
|
|
package main
|
|
|
|
|
|
|
|
import (
|
|
|
|
"encoding/hex"
|
2015-10-07 22:58:22 +02:00
|
|
|
"os"
|
|
|
|
"strings"
|
2016-02-06 19:20:54 +01:00
|
|
|
|
2021-08-23 15:05:15 +02:00
|
|
|
"github.com/rfjakob/gocryptfs/v2/internal/cryptocore"
|
|
|
|
"github.com/rfjakob/gocryptfs/v2/internal/exitcodes"
|
|
|
|
"github.com/rfjakob/gocryptfs/v2/internal/readpassword"
|
|
|
|
"github.com/rfjakob/gocryptfs/v2/internal/tlog"
|
2015-10-06 21:16:39 +02:00
|
|
|
)
|
|
|
|
|
2020-05-09 16:10:22 +02:00
|
|
|
// unhexMasterKey - Convert a hex-encoded master key to binary.
|
|
|
|
// Calls os.Exit on failure.
|
|
|
|
func unhexMasterKey(masterkey string, fromStdin bool) []byte {
|
2015-10-06 21:16:39 +02:00
|
|
|
masterkey = strings.Replace(masterkey, "-", "", -1)
|
|
|
|
key, err := hex.DecodeString(masterkey)
|
|
|
|
if err != nil {
|
2016-10-16 16:19:12 +02:00
|
|
|
tlog.Fatal.Printf("Could not parse master key: %v", err)
|
2017-05-07 22:15:01 +02:00
|
|
|
os.Exit(exitcodes.MasterKey)
|
2015-10-06 21:16:39 +02:00
|
|
|
}
|
2016-02-06 19:20:54 +01:00
|
|
|
if len(key) != cryptocore.KeyLen {
|
2016-10-16 16:19:12 +02:00
|
|
|
tlog.Fatal.Printf("Master key has length %d but we require length %d", len(key), cryptocore.KeyLen)
|
2017-05-07 22:15:01 +02:00
|
|
|
os.Exit(exitcodes.MasterKey)
|
2015-10-06 21:16:39 +02:00
|
|
|
}
|
2016-10-16 16:19:12 +02:00
|
|
|
tlog.Info.Printf("Using explicit master key.")
|
2018-03-22 00:02:10 +01:00
|
|
|
if !fromStdin {
|
|
|
|
tlog.Info.Printf(tlog.ColorYellow +
|
|
|
|
"THE MASTER KEY IS VISIBLE VIA \"ps ax\" AND MAY BE STORED IN YOUR SHELL HISTORY!\n" +
|
|
|
|
"ONLY USE THIS MODE FOR EMERGENCIES" + tlog.ColorReset)
|
|
|
|
}
|
2015-10-06 21:16:39 +02:00
|
|
|
return key
|
|
|
|
}
|
2018-04-01 14:51:53 +02:00
|
|
|
|
2020-05-09 16:32:11 +02:00
|
|
|
// handleArgsMasterkey looks at `args.masterkey` and `args.zerokey`, gets the
|
|
|
|
// masterkey from the source the user wanted (string on the command line, stdin, all-zero),
|
|
|
|
// and returns it in binary. Returns nil if no masterkey source was specified.
|
|
|
|
func handleArgsMasterkey(args *argContainer) (masterkey []byte) {
|
2018-04-01 14:51:53 +02:00
|
|
|
// "-masterkey=stdin"
|
|
|
|
if args.masterkey == "stdin" {
|
2022-01-03 15:18:59 +01:00
|
|
|
in, err := readpassword.Once(nil, nil, "Masterkey")
|
|
|
|
if err != nil {
|
|
|
|
tlog.Fatal.Println(err)
|
|
|
|
os.Exit(exitcodes.ReadPassword)
|
|
|
|
}
|
|
|
|
return unhexMasterKey(string(in), true)
|
2018-04-01 14:51:53 +02:00
|
|
|
}
|
|
|
|
// "-masterkey=941a6029-3adc6a1c-..."
|
|
|
|
if args.masterkey != "" {
|
2020-05-09 16:32:11 +02:00
|
|
|
return unhexMasterKey(args.masterkey, false)
|
2018-04-01 14:51:53 +02:00
|
|
|
}
|
|
|
|
// "-zerokey"
|
|
|
|
if args.zerokey {
|
|
|
|
tlog.Info.Printf("Using all-zero dummy master key.")
|
|
|
|
tlog.Info.Printf(tlog.ColorYellow +
|
|
|
|
"ZEROKEY MODE PROVIDES NO SECURITY AT ALL AND SHOULD ONLY BE USED FOR TESTING." +
|
|
|
|
tlog.ColorReset)
|
2020-05-09 16:32:11 +02:00
|
|
|
return make([]byte, cryptocore.KeyLen)
|
2018-04-01 14:51:53 +02:00
|
|
|
}
|
2020-05-09 16:32:11 +02:00
|
|
|
// No master key source specified on the command line. Caller must parse
|
|
|
|
// the config file.
|
|
|
|
return nil
|
2018-04-01 14:51:53 +02:00
|
|
|
}
|