## OpenCA - CA Command
## (c) 1998-2001 by Massimiliano Pala and OpenCA Group
##
##   File Name: bpCreatePIN
##     Version: $Revision: 1.11 $
##       Brief: create PINs for new users
## Description: 
##  Parameters:

sub cmdBpCreatePIN {

	print startLogPage (gettext ("Create PIN Batch Processor"));

	## datadirectory for the batchprocessor
	my $batch_dir  = getRequired ("BP_DIR");

	print addLogSection (gettext ("Running batch processor ..."));

	bpScanDir ($batch_dir, "bpCreatePIN");

	print addPreLogLine ("");
	print addLogLine (gettext ("Batch processor finished"));
	print closeLogSection ();

	print closePage();

}

sub bpCreatePIN {
	my $dir = $_[0];

	## check for ID
	if ( (-f $dir."/ID") and
	     (-f $dir."/acl/newPIN") and
	     (not -f $dir."/private/purePIN") ) {

		## remove perhaps existent .hashedPIN
		unlink ($dir."/public/hashedPIN")
			if (-f $dir."/public/hashedPIN");

		## get new PIN
		my $hashed_pin;
		my $pin;

		## get PIN
		if (getRequired ('SECURE_PIN_LENGTH')) {
			if (getRequired ('SECURE_PIN_RANDOM')) {
				$pin = $cryptoShell->getPIN (
					PIN_LENGTH    => getRequired ('SECURE_PIN_LENGTH'),
					RANDOM_LENGTH => getRequired ('SECURE_PIN_RANDOM')
					);
			} else {
				$pin = $cryptoShell->getPIN (
					PIN_LENGTH    => getRequired ('SECURE_PIN_LENGTH')
					);
			}
		} elsif (getRequired ('SECURE_PIN_RANDOM')) {
			$pin = $cryptoShell->getPIN (
					RANDOM_LENGTH => getRequired ('SECURE_PIN_RANDOM')
					);
		} else {
			configError (gettext ("You must configure SECURE_PIN_LENGTH or SECURE_PIN_RANDOM."));
		}
		if (not $pin) {
			print addPreLogLine (
				    "<FONT COLOR=#FF0000>".
				    i18nGettext (
                      "Cannot create PIN! OpenCA::OpenSSL returns errorcode __ERRNO__.",
                      "__ERRNO__", $OpenCA::OpenSSL::errno).
                    " (".$OpenCA::OpenSSL::errval.")".
				    "</FONT>");
			print addLogLine (
				"<FONT COLOR=#FF0000>".
				gettext ("Aborting for security reasons.").
				"</FONT>");
			print closeLogSection ();
			print closeLogPage ();
			return undef;
		}
		## encrypt the PIN
		my $pinfile = "-----BEGIN PIN-----\n".$pin."\n-----END PIN-----\n";
		if (not $cryptoShell->getSMIME (
                                  ENCRYPT      => 1,
                                  SIGN         => 1,
                                  ENCRYPT_CERT => getRequired ("BP_CERTIFICATE"),
                                  SIGN_CERT    => getRequired ("BP_CERTIFICATE"),
                                  KEY          => getRequired ("BP_KEY"),
                                  USE_ENGINE   => 1,
                                  PASSWD       => $query->param ('passwd'),
                                  DATA         => $pinfile,
                                  OUTFILE      => $dir."/private/purePIN",
                                  TO           => getRequired ("SERVICE_MAIL_ACCOUNT"),
                                  FROM         => getRequired ("SERVICE_MAIL_ACCOUNT"),
                                  SUBJECT      => "Encrypted PIN")) {
			print addPreLogLine ("<FONT COLOR=#FF0000>".
				i18nGettext (
				    "Cannot create PIN because the encryption of the PIN failed - ID __ID__ ignored.",
				    "__ID__", $tools->getFile ($dir."/ID")).
				    "</FONT>");
			return;
		}
		## hash PIN
		$hashed_pin = $cryptoShell->getDigest (
						DATA =>      $pin,
						ALGORITHM => "sha1");
		if (not $hashed_pin) {
			print addPreLogLine (
				    "<FONT COLOR=#FF0000>".
				    i18nGettext (
                         "Cannot hash PIN! OpenCA::OpenSSL returns errorcode __ERRNO__.",
                         "__ERRNO__", $OpenCA::OpenSSL::errno).
				    " (".$OpenCA::OpenSSL::errval.").".
				    "</FONT>");
			print addLogLine (
				    "<FONT COLOR=#FF0000>".
				    gettext ("Aborting for security reasons.").
				    "</FONT>");
			print closeLogSection ();
			print closeLogPage ();
			return undef;
		}
		if (not $tools->saveFile (FILENAME => $dir."/public/hashedPIN", DATA => $hashed_pin)) {
			print addPreLogLine ("<FONT COLOR=#FF0000>".
			                     i18nGettext (
			                         "Cannot write file __FILE__ ID: __ID__ - ignored",
			                         "__FILE__", "$dir/public/hashedPIN",
			                         "__ID__", $tools->getFile ($dir."/ID")).
			                     "</FONT>");
			unlink ($dir."/private/purePIN");
		} else {
			print addPreLogLine (i18nGettext ("ID: __ID__ - PIN successfully created", "__ID__", $tools->getFile ($dir."/ID")));
		}

		## delete permission
		print addPreLogLine ("<FONT COLOR=#FF0000>".
			    i18nGettext (
                  "Cannot remove permission to create a new PIN for ID: __ID__",
			      "__ID__", $tools->getFile ($dir."/ID")).
			   "</FONT>")
			if (not unlink $dir."/acl/newPIN");
	} elsif ( (-f $dir."/ID") and
	     (-f $dir."/acl/newPIN") and
	     (-f $dir."/private/purePIN") ) {
		## delete permission
		print addPreLogLine ("<FONT COLOR=#00FF00>".
			    i18nGettext (
                  "Removed permission to create a new PIN for ID __ID__ because an unencrypted and not hashed PIN is already present",
			      "__ID__", $tools->getFile ($dir."/ID")).
			    "</FONT>")
			if (unlink $dir."/acl/newPIN");
        }
}

1;
