All Downloads are FREE. Search and download functionalities are using the official Maven repository.

org.xipki.ca.server.mgmt.shell.CaRevokeAction Maven / Gradle / Ivy

The newest version!
/*
 *
 * Copyright (c) 2013 - 2018 Lijun Liao
 *
 * Licensed under the Apache License, Version 2.0 (the "License");
 * you may not use this file except in compliance with the License.
 * You may obtain a copy of the License at
 *
 * http://www.apache.org/licenses/LICENSE-2.0
 *
 * Unless required by applicable law or agreed to in writing, software
 * distributed under the License is distributed on an "AS IS" BASIS,
 * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
 * See the License for the specific language governing permissions and
 * limitations under the License.
 */

package org.xipki.ca.server.mgmt.shell;

import java.util.Arrays;
import java.util.Collections;
import java.util.Date;
import java.util.List;

import org.apache.karaf.shell.api.action.Argument;
import org.apache.karaf.shell.api.action.Command;
import org.apache.karaf.shell.api.action.Completion;
import org.apache.karaf.shell.api.action.Option;
import org.apache.karaf.shell.api.action.lifecycle.Service;
import org.xipki.ca.server.mgmt.api.CaMgmtException;
import org.xipki.ca.server.mgmt.shell.completer.CaCrlReasonCompleter;
import org.xipki.ca.server.mgmt.shell.completer.CaNameCompleter;
import org.xipki.security.CertRevocationInfo;
import org.xipki.security.CrlReason;
import org.xipki.shell.CmdFailure;
import org.xipki.shell.IllegalCmdParamException;
import org.xipki.util.DateUtil;

/**
 * TODO.
 * @author Lijun Liao
 * @since 2.0.0
 */

@Command(scope = "ca", name = "ca-revoke", description = "revoke CA")
@Service
public class CaRevokeAction extends CaAction {

  public static final List PERMITTED_REASONS = Collections.unmodifiableList(
      Arrays.asList(new CrlReason[] {
        CrlReason.UNSPECIFIED, CrlReason.KEY_COMPROMISE, CrlReason.CA_COMPROMISE,
        CrlReason.AFFILIATION_CHANGED, CrlReason.SUPERSEDED, CrlReason.CESSATION_OF_OPERATION,
        CrlReason.CERTIFICATE_HOLD, CrlReason.PRIVILEGE_WITHDRAWN}));

  @Argument(index = 0, name = "name", description = "CA name", required = true)
  @Completion(CaNameCompleter.class)
  private String caName;

  @Option(name = "--reason", required = true, description = "CRL reason")
  @Completion(CaCrlReasonCompleter.class)
  private String reason;

  @Option(name = "--rev-date", valueToShowInHelp = "current time",
      description = "revocation date, UTC time of format yyyyMMddHHmmss")
  private String revocationDateS;

  @Option(name = "--inv-date", description = "invalidity date, UTC time of format yyyyMMddHHmmss")
  private String invalidityDateS;

  @Override
  protected Object execute0() throws Exception {
    CrlReason crlReason = CrlReason.forNameOrText(reason);

    if (!PERMITTED_REASONS.contains(crlReason)) {
      throw new IllegalCmdParamException("reason " + reason + " is not permitted");
    }

    if (!caManager.getCaNames().contains(caName)) {
      throw new IllegalCmdParamException("invalid CA name " + caName);
    }

    Date revocationDate = null;
    revocationDate = isNotBlank(revocationDateS)
        ? DateUtil.parseUtcTimeyyyyMMddhhmmss(revocationDateS) : new Date();

    Date invalidityDate = null;
    if (isNotBlank(invalidityDateS)) {
      invalidityDate = DateUtil.parseUtcTimeyyyyMMddhhmmss(invalidityDateS);
    }

    CertRevocationInfo revInfo = new CertRevocationInfo(crlReason, revocationDate, invalidityDate);
    String msg = "CA " + caName;
    try {
      caManager.revokeCa(caName, revInfo);
      println("revoked " + msg);
      return null;
    } catch (CaMgmtException ex) {
      throw new CmdFailure("could not revoke " + msg + ", error: " + ex.getMessage(), ex);
    }
  } // method execute0

}




© 2015 - 2024 Weber Informatics LLC | Privacy Policy