File: pkcs12_migrator.h

package info (click to toggle)
chromium 138.0.7204.183-1~deb12u1
  • links: PTS, VCS
  • area: main
  • in suites: bookworm-proposed-updates
  • size: 6,080,960 kB
  • sloc: cpp: 34,937,079; ansic: 7,176,967; javascript: 4,110,704; python: 1,419,954; asm: 946,768; xml: 739,971; pascal: 187,324; sh: 89,623; perl: 88,663; objc: 79,944; sql: 50,304; cs: 41,786; fortran: 24,137; makefile: 21,811; php: 13,980; tcl: 13,166; yacc: 8,925; ruby: 7,485; awk: 3,720; lisp: 3,096; lex: 1,327; ada: 727; jsp: 228; sed: 36
file content (90 lines) | stat: -rw-r--r-- 3,232 bytes parent folder | download | duplicates (2)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
// Copyright 2024 The Chromium Authors
// Use of this source code is governed by a BSD-style license that can be
// found in the LICENSE file.

#ifndef CHROME_BROWSER_ASH_KCER_NSSDB_MIGRATION_PKCS12_MIGRATOR_H_
#define CHROME_BROWSER_ASH_KCER_NSSDB_MIGRATION_PKCS12_MIGRATOR_H_

#include <memory>

#include "base/no_destructor.h"
#include "chrome/browser/profiles/profile_keyed_service_factory.h"
#include "chromeos/ash/components/kcer/kcer.h"
#include "components/keyed_service/core/keyed_service.h"
#include "net/cert/scoped_nss_types.h"

namespace content {
class BrowserContext;
}

namespace kcer {

inline constexpr char kKcerPkcs12MigrationUma[] =
    "Ash.KcerPkcs12Migration.Events";

// Used for UMA counters, the entries should not be re-numbered or re-used.
enum class KcerPkcs12MigrationEvent {
  kMigrationStarted = 0,
  kkNothingToMigrate = 1,
  kMigrationFinishedSuccess = 2,
  kMigrationFinishedFailure = 3,
  kCertMigratedSuccess = 4,
  kFailedToReimportCert = 5,
  kExportedPkcs12EmptyError = 6,
  kFailedToGetKcerCerts = 7,
  kFailedToGetNssCerts = 8,
  kMaxValue = kFailedToGetNssCerts,
};

// On Profile creation evaluates whether the migration of client certificates
// from the public slot to the private slot is enabled, and if yes, creates and
// starts a Pkcs12Migrator instance.
class Pkcs12MigratorFactory : public ProfileKeyedServiceFactory {
 public:
  static Pkcs12MigratorFactory* GetInstance();

 private:
  friend class base::NoDestructor<Pkcs12MigratorFactory>;

  Pkcs12MigratorFactory();
  ~Pkcs12MigratorFactory() override = default;

  // Implements BrowserStateKeyedServiceFactory.
  bool ServiceIsCreatedWithBrowserContext() const override;
  std::unique_ptr<KeyedService> BuildServiceInstanceForBrowserContext(
      content::BrowserContext* context) const override;
};

// Copies all client certificates from the NSS public slot of the `context` into
// its private slot (provided by Chaps). It never deletes migrated certificates
// to reduce the risk of breakages and allow a simpler rollback.
class Pkcs12Migrator : public KeyedService {
 public:
  explicit Pkcs12Migrator(content::BrowserContext* context);
  ~Pkcs12Migrator() override;

  // Waits for 30 sec to avoid slowdowns during user session initialization.
  // Finds all NSS public slot client certificates that don't exist on the Chaps
  // token. Copies the NSS public slot client certificates to the Chaps token.
  void Start();

 private:
  void StartAfterDelay();
  void MigrateCerts(bool success, net::ScopedCERTCertificateList certs);
  void MigrateCertsWithKcerCerts(
      net::ScopedCERTCertificateList nss_certs,
      std::vector<scoped_refptr<const Cert>> kcer_certs,
      base::flat_map<Token, Error> kcer_errors);
  void MigrateEachCert(net::ScopedCERTCertificateList certs);
  void ExportedOneCert(net::ScopedCERTCertificateList certs, Pkcs12Blob pkcs12);
  void ImportedOneCert(net::ScopedCERTCertificateList certs,
                       base::expected<void, Error> result);

  bool had_failures_ = false;
  raw_ptr<content::BrowserContext> context_;
  base::WeakPtrFactory<Pkcs12Migrator> weak_factory_{this};
};

}  // namespace kcer

#endif  // CHROME_BROWSER_ASH_KCER_NSSDB_MIGRATION_PKCS12_MIGRATOR_H_