## OpenCA - CA Command
## (c) 1998-2001 by Massimiliano Pala and OpenCA Group
##
##   File Name: genCACert
##       Brief: Generate CA Certificate
##// Description: Generate the CA's Certificate (self-signed) from the
##              request file (careq.pem).
##  Parameters: bits, days, passwd

sub cmdGenCACert {

## This command is executed to generate a new cacert.pem
## in the $opencaDir directory. Use the already generated
## careq.pem

my $baseDoc   = getRequired( 'gencacertsheet');
my $makeCmd   = getRequired( 'MakePath');

## Get the parameters
my $bits	= $query->param('bits');
my $days	= $query->param('days');
my $pwd		= $query->param('passwd');

## Other reserved variables
my $careqFile 	= getRequired ( 'ReqDir' )."/careq.pem";
my $cacertFile 	= getRequired ( 'CACertificate' );
my $cacertDER	= getRequired ( 'CACertificateDER' );
my $cacertCRT	= getRequired ( 'CACertificateCRT' );
my $cacertTXT	= getRequired ( 'CACertificateTXT' );
my $cakeyFile 	= getRequired ( 'CAKey' );
my $chainDir 	= getRequired ( 'ChainDir' );

my ( $page, $crt );

configError(i18nGettext ("Cannot find file __FILE__!", "__FILE__", $careqFile)) unless ( -e "$careqFile" );
configError(i18nGettext ("Cannot find file __FILE__!", "__FILE__", $cakeyFile)) unless ( -e "$cakeyFile" );

## If there is already a cacertfile, than we should move it to .old
if ( -e "$cacertFile" ) {
	$tools->moveFiles( SRC=>"$cacertFile",
			   DEST=>"$cacertFile.${$}_old");
	$msg = i18nGettext ("Old certificate file is (__FILE__).", "__FILE__", "$cacertFile.${$}_old");
}

unlink( "$cacertDER" ) if ( -e "$cacertDER" );

$cryptoShell->genCert(  KEYFILE    => "$cakeyFile",
			USE_ENGINE => 1,
			REQFILE    => "$careqFile",
			OUTFILE    => "$cacertFile",
			DAYS       => $days,
			PASSWD     => $pwd );

configError( "<BR>".gettext ("Error (1) while issuing certificate!")."<BR>" ) if( $? != 0 );

$cryptoShell->dataConvert( DATATYPE=>CERTIFICATE,
			   INFILE=>"$cacertFile",
			   OUTFILE=>"$cacertDER",
			   OUTFORM=>"DER" );

configError( "<BR>".gettext ("Error (2) while convertig certificate!")."<BR>" ) if( $? != 0 );

$cryptoShell->dataConvert( DATATYPE=>CERTIFICATE,
			   INFILE=>"$cacertFile",
			   OUTFILE=>"$cacertTXT",
			   OUTFORM=>"TXT" );

configError( "<BR>".gettext ("Error (3) while convertig certificate!")."<BR>" ) if( $? != 0 );

$crt = new OpenCA::X509( SHELL=>$cryptoShell, INFILE=>"$cacertFile" );
if( not $crt ) {
	configError( "<BR>".i18nGettext ("Error while loading CA certificate (__FILE__).", "__FILE__", $cacertFile));
} else {

	##// Let's link to the chain dir
	$tools->copyFiles ( SRC=>"$cacertFile",
			    DEST=>"$cacertCRT");

	##// Let's make the links for chain verification
	$ret = `cd ${chainDir}; $makeCmd`;

	if ( not $db->storeItem( DATATYPE => "VALID_CA_CERTIFICATE",
				 OBJECT   => $crt,
				 MODE     => "INSERT")) {
		configError (gettext ("Error while storing CA cert to dB!"));
	}
}

## If we cannot load the base Document, then error
configError (i18nGettext ("Cannot load file __FILE__!", "__FILE__", $baseDoc))
			 unless ( $page = $query->getFile("$baseDoc"));

## Substitute the variables
$page = $query->subVar( $page, '$key', $crt->getTXT() );
$page = $query->subVar( $page, '$msg', $msg );

## Send out the page
print "$page";

}

1;

