2000-10-19 15:43:08 +00:00
|
|
|
/*
|
2004-04-27 12:31:57 +00:00
|
|
|
* PuTTY key generation front end (Windows).
|
2000-10-19 15:43:08 +00:00
|
|
|
*/
|
|
|
|
|
|
|
|
#include <time.h>
|
|
|
|
#include <stdio.h>
|
2000-10-24 10:47:49 +00:00
|
|
|
#include <stdlib.h>
|
2011-10-02 14:14:21 +00:00
|
|
|
#include <assert.h>
|
2000-10-19 15:43:08 +00:00
|
|
|
|
|
|
|
#define PUTTY_DO_GLOBALS
|
|
|
|
|
|
|
|
#include "putty.h"
|
|
|
|
#include "ssh.h"
|
2015-12-22 12:43:31 +00:00
|
|
|
#include "licence.h"
|
2016-04-02 07:00:07 +00:00
|
|
|
#include "winsecur.h"
|
2003-10-12 13:46:12 +00:00
|
|
|
|
|
|
|
#include <commctrl.h>
|
2000-10-19 15:43:08 +00:00
|
|
|
|
2003-02-07 13:54:34 +00:00
|
|
|
#ifdef MSVC4
|
|
|
|
#define ICON_BIG 1
|
|
|
|
#endif
|
|
|
|
|
2005-08-10 18:31:24 +00:00
|
|
|
#define WM_DONEKEY (WM_APP + 1)
|
2000-10-19 15:43:08 +00:00
|
|
|
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
#define DEFAULT_KEY_BITS 2048
|
|
|
|
#define DEFAULT_CURVE_INDEX 0
|
2000-10-19 15:43:08 +00:00
|
|
|
|
2002-08-06 17:48:14 +00:00
|
|
|
static char *cmdline_keyfile = NULL;
|
|
|
|
|
2002-10-09 18:09:42 +00:00
|
|
|
/*
|
|
|
|
* Print a modal (Really Bad) message box and perform a fatal exit.
|
|
|
|
*/
|
2015-05-15 10:15:42 +00:00
|
|
|
void modalfatalbox(const char *fmt, ...)
|
2002-10-09 18:09:42 +00:00
|
|
|
{
|
|
|
|
va_list ap;
|
2002-11-07 19:49:03 +00:00
|
|
|
char *stuff;
|
2002-10-09 18:09:42 +00:00
|
|
|
|
|
|
|
va_start(ap, fmt);
|
2002-11-07 19:49:03 +00:00
|
|
|
stuff = dupvprintf(fmt, ap);
|
2002-10-09 18:09:42 +00:00
|
|
|
va_end(ap);
|
|
|
|
MessageBox(NULL, stuff, "PuTTYgen Fatal Error",
|
|
|
|
MB_SYSTEMMODAL | MB_ICONERROR | MB_OK);
|
2002-11-07 19:49:03 +00:00
|
|
|
sfree(stuff);
|
2002-10-09 18:09:42 +00:00
|
|
|
exit(1);
|
|
|
|
}
|
|
|
|
|
2013-07-22 07:11:44 +00:00
|
|
|
/*
|
|
|
|
* Print a non-fatal message box and do not exit.
|
|
|
|
*/
|
2015-05-15 10:15:42 +00:00
|
|
|
void nonfatal(const char *fmt, ...)
|
2013-07-22 07:11:44 +00:00
|
|
|
{
|
|
|
|
va_list ap;
|
|
|
|
char *stuff;
|
|
|
|
|
|
|
|
va_start(ap, fmt);
|
|
|
|
stuff = dupvprintf(fmt, ap);
|
|
|
|
va_end(ap);
|
|
|
|
MessageBox(NULL, stuff, "PuTTYgen Error",
|
|
|
|
MB_SYSTEMMODAL | MB_ICONERROR | MB_OK);
|
|
|
|
sfree(stuff);
|
|
|
|
}
|
|
|
|
|
2018-09-22 07:13:41 +00:00
|
|
|
/* Stubs needed to link against misc.c */
|
|
|
|
void queue_idempotent_callback(IdempotentCallback *ic) { assert(0); }
|
2018-09-19 16:37:00 +00:00
|
|
|
|
2000-10-19 15:43:08 +00:00
|
|
|
/* ----------------------------------------------------------------------
|
|
|
|
* Progress report code. This is really horrible :-)
|
|
|
|
*/
|
2001-09-22 20:52:21 +00:00
|
|
|
#define PROGRESSRANGE 65535
|
|
|
|
#define MAXPHASE 5
|
2000-10-19 15:43:08 +00:00
|
|
|
struct progress {
|
2001-09-22 20:52:21 +00:00
|
|
|
int nphases;
|
|
|
|
struct {
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
bool exponential;
|
2001-09-22 20:52:21 +00:00
|
|
|
unsigned startpoint, total;
|
|
|
|
unsigned param, current, n; /* if exponential */
|
|
|
|
unsigned mult; /* if linear */
|
|
|
|
} phases[MAXPHASE];
|
|
|
|
unsigned total, divisor, range;
|
2000-10-19 15:43:08 +00:00
|
|
|
HWND progbar;
|
|
|
|
};
|
|
|
|
|
2001-09-22 20:52:21 +00:00
|
|
|
static void progress_update(void *param, int action, int phase, int iprogress)
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
|
|
|
struct progress *p = (struct progress *) param;
|
2000-10-19 15:43:08 +00:00
|
|
|
unsigned progress = iprogress;
|
|
|
|
int position;
|
|
|
|
|
2001-09-22 20:52:21 +00:00
|
|
|
if (action < PROGFN_READY && p->nphases < phase)
|
|
|
|
p->nphases = phase;
|
|
|
|
switch (action) {
|
2001-11-12 09:19:57 +00:00
|
|
|
case PROGFN_INITIALISE:
|
|
|
|
p->nphases = 0;
|
|
|
|
break;
|
2001-09-22 20:52:21 +00:00
|
|
|
case PROGFN_LIN_PHASE:
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
p->phases[phase-1].exponential = false;
|
2001-09-22 20:52:21 +00:00
|
|
|
p->phases[phase-1].mult = p->phases[phase].total / progress;
|
|
|
|
break;
|
|
|
|
case PROGFN_EXP_PHASE:
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
p->phases[phase-1].exponential = true;
|
2001-09-22 20:52:21 +00:00
|
|
|
p->phases[phase-1].param = 0x10000 + progress;
|
|
|
|
p->phases[phase-1].current = p->phases[phase-1].total;
|
|
|
|
p->phases[phase-1].n = 0;
|
2001-05-06 14:35:20 +00:00
|
|
|
break;
|
2001-09-22 20:52:21 +00:00
|
|
|
case PROGFN_PHASE_EXTENT:
|
|
|
|
p->phases[phase-1].total = progress;
|
|
|
|
break;
|
|
|
|
case PROGFN_READY:
|
|
|
|
{
|
|
|
|
unsigned total = 0;
|
|
|
|
int i;
|
|
|
|
for (i = 0; i < p->nphases; i++) {
|
|
|
|
p->phases[i].startpoint = total;
|
|
|
|
total += p->phases[i].total;
|
|
|
|
}
|
|
|
|
p->total = total;
|
|
|
|
p->divisor = ((p->total + PROGRESSRANGE - 1) / PROGRESSRANGE);
|
|
|
|
p->range = p->total / p->divisor;
|
|
|
|
SendMessage(p->progbar, PBM_SETRANGE, 0, MAKELPARAM(0, p->range));
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
break;
|
2001-09-22 20:52:21 +00:00
|
|
|
case PROGFN_PROGRESS:
|
|
|
|
if (p->phases[phase-1].exponential) {
|
|
|
|
while (p->phases[phase-1].n < progress) {
|
|
|
|
p->phases[phase-1].n++;
|
|
|
|
p->phases[phase-1].current *= p->phases[phase-1].param;
|
|
|
|
p->phases[phase-1].current /= 0x10000;
|
|
|
|
}
|
|
|
|
position = (p->phases[phase-1].startpoint +
|
|
|
|
p->phases[phase-1].total - p->phases[phase-1].current);
|
|
|
|
} else {
|
|
|
|
position = (p->phases[phase-1].startpoint +
|
|
|
|
progress * p->phases[phase-1].mult);
|
|
|
|
}
|
|
|
|
SendMessage(p->progbar, PBM_SETPOS, position / p->divisor, 0);
|
2001-05-06 14:35:20 +00:00
|
|
|
break;
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2016-04-07 06:52:55 +00:00
|
|
|
extern const char ver[];
|
2000-10-19 15:43:08 +00:00
|
|
|
|
|
|
|
struct PassphraseProcStruct {
|
2011-10-02 14:14:21 +00:00
|
|
|
char **passphrase;
|
2000-10-19 15:43:08 +00:00
|
|
|
char *comment;
|
|
|
|
};
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Dialog-box function for the passphrase box.
|
|
|
|
*/
|
2015-08-11 12:22:09 +00:00
|
|
|
static INT_PTR CALLBACK PassphraseProc(HWND hwnd, UINT msg,
|
2001-05-06 14:35:20 +00:00
|
|
|
WPARAM wParam, LPARAM lParam)
|
|
|
|
{
|
2011-10-02 14:14:21 +00:00
|
|
|
static char **passphrase = NULL;
|
2000-10-19 15:43:08 +00:00
|
|
|
struct PassphraseProcStruct *p;
|
|
|
|
|
|
|
|
switch (msg) {
|
|
|
|
case WM_INITDIALOG:
|
2001-05-06 14:35:20 +00:00
|
|
|
SetForegroundWindow(hwnd);
|
|
|
|
SetWindowPos(hwnd, HWND_TOP, 0, 0, 0, 0,
|
|
|
|
SWP_NOMOVE | SWP_NOSIZE | SWP_SHOWWINDOW);
|
2001-03-03 11:54:34 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Centre the window.
|
|
|
|
*/
|
|
|
|
{ /* centre the window */
|
|
|
|
RECT rs, rd;
|
|
|
|
HWND hw;
|
|
|
|
|
|
|
|
hw = GetDesktopWindow();
|
2001-05-06 14:35:20 +00:00
|
|
|
if (GetWindowRect(hw, &rs) && GetWindowRect(hwnd, &rd))
|
|
|
|
MoveWindow(hwnd,
|
|
|
|
(rs.right + rs.left + rd.left - rd.right) / 2,
|
|
|
|
(rs.bottom + rs.top + rd.top - rd.bottom) / 2,
|
2018-10-29 19:50:29 +00:00
|
|
|
rd.right - rd.left, rd.bottom - rd.top, true);
|
2001-03-03 11:54:34 +00:00
|
|
|
}
|
|
|
|
|
2001-05-06 14:35:20 +00:00
|
|
|
p = (struct PassphraseProcStruct *) lParam;
|
|
|
|
passphrase = p->passphrase;
|
|
|
|
if (p->comment)
|
|
|
|
SetDlgItemText(hwnd, 101, p->comment);
|
2011-10-02 14:14:21 +00:00
|
|
|
burnstr(*passphrase);
|
|
|
|
*passphrase = dupstr("");
|
|
|
|
SetDlgItemText(hwnd, 102, *passphrase);
|
2001-05-06 14:35:20 +00:00
|
|
|
return 0;
|
2000-10-19 15:43:08 +00:00
|
|
|
case WM_COMMAND:
|
|
|
|
switch (LOWORD(wParam)) {
|
|
|
|
case IDOK:
|
|
|
|
if (*passphrase)
|
2001-05-06 14:35:20 +00:00
|
|
|
EndDialog(hwnd, 1);
|
2000-10-19 15:43:08 +00:00
|
|
|
else
|
2001-05-06 14:35:20 +00:00
|
|
|
MessageBeep(0);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
|
|
|
case IDCANCEL:
|
2001-05-06 14:35:20 +00:00
|
|
|
EndDialog(hwnd, 0);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
2001-05-06 14:35:20 +00:00
|
|
|
case 102: /* edit box */
|
2001-04-28 11:41:33 +00:00
|
|
|
if ((HIWORD(wParam) == EN_CHANGE) && passphrase) {
|
2011-10-02 14:14:21 +00:00
|
|
|
burnstr(*passphrase);
|
|
|
|
*passphrase = GetDlgItemText_alloc(hwnd, 102);
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
return 0;
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
case WM_CLOSE:
|
2001-05-06 14:35:20 +00:00
|
|
|
EndDialog(hwnd, 0);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Prompt for a key file. Assumes the filename buffer is of size
|
|
|
|
* FILENAME_MAX.
|
|
|
|
*/
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
static bool prompt_keyfile(HWND hwnd, char *dlgtitle,
|
|
|
|
char *filename, bool save, bool ppk)
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
2000-10-19 15:43:08 +00:00
|
|
|
OPENFILENAME of;
|
|
|
|
memset(&of, 0, sizeof(of));
|
|
|
|
of.hwndOwner = hwnd;
|
2002-08-06 17:35:34 +00:00
|
|
|
if (ppk) {
|
2003-01-29 16:39:18 +00:00
|
|
|
of.lpstrFilter = "PuTTY Private Key Files (*.ppk)\0*.ppk\0"
|
|
|
|
"All Files (*.*)\0*\0\0\0";
|
2002-08-06 17:35:34 +00:00
|
|
|
of.lpstrDefExt = ".ppk";
|
|
|
|
} else {
|
2003-01-29 16:39:18 +00:00
|
|
|
of.lpstrFilter = "All Files (*.*)\0*\0\0\0";
|
2002-08-06 17:35:34 +00:00
|
|
|
}
|
2000-10-19 15:43:08 +00:00
|
|
|
of.lpstrCustomFilter = NULL;
|
|
|
|
of.nFilterIndex = 1;
|
2001-05-06 14:35:20 +00:00
|
|
|
of.lpstrFile = filename;
|
|
|
|
*filename = '\0';
|
2000-10-19 15:43:08 +00:00
|
|
|
of.nMaxFile = FILENAME_MAX;
|
|
|
|
of.lpstrFileTitle = NULL;
|
|
|
|
of.lpstrTitle = dlgtitle;
|
|
|
|
of.Flags = 0;
|
2018-10-29 19:50:29 +00:00
|
|
|
return request_file(NULL, &of, false, save);
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Dialog-box function for the Licence box.
|
|
|
|
*/
|
2015-08-11 12:22:09 +00:00
|
|
|
static INT_PTR CALLBACK LicenceProc(HWND hwnd, UINT msg,
|
2001-05-06 14:35:20 +00:00
|
|
|
WPARAM wParam, LPARAM lParam)
|
|
|
|
{
|
2000-10-19 15:43:08 +00:00
|
|
|
switch (msg) {
|
|
|
|
case WM_INITDIALOG:
|
2001-03-03 11:54:34 +00:00
|
|
|
/*
|
|
|
|
* Centre the window.
|
|
|
|
*/
|
|
|
|
{ /* centre the window */
|
|
|
|
RECT rs, rd;
|
|
|
|
HWND hw;
|
|
|
|
|
|
|
|
hw = GetDesktopWindow();
|
2001-05-06 14:35:20 +00:00
|
|
|
if (GetWindowRect(hw, &rs) && GetWindowRect(hwnd, &rd))
|
|
|
|
MoveWindow(hwnd,
|
|
|
|
(rs.right + rs.left + rd.left - rd.right) / 2,
|
|
|
|
(rs.bottom + rs.top + rd.top - rd.bottom) / 2,
|
2018-10-29 19:50:29 +00:00
|
|
|
rd.right - rd.left, rd.bottom - rd.top, true);
|
2001-03-03 11:54:34 +00:00
|
|
|
}
|
|
|
|
|
2015-12-22 12:43:31 +00:00
|
|
|
SetDlgItemText(hwnd, 1000, LICENCE_TEXT("\r\n\r\n"));
|
2000-10-19 15:43:08 +00:00
|
|
|
return 1;
|
|
|
|
case WM_COMMAND:
|
|
|
|
switch (LOWORD(wParam)) {
|
|
|
|
case IDOK:
|
2004-10-27 15:50:52 +00:00
|
|
|
case IDCANCEL:
|
2001-05-06 14:35:20 +00:00
|
|
|
EndDialog(hwnd, 1);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
case WM_CLOSE:
|
|
|
|
EndDialog(hwnd, 1);
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Dialog-box function for the About box.
|
|
|
|
*/
|
2015-08-11 12:22:09 +00:00
|
|
|
static INT_PTR CALLBACK AboutProc(HWND hwnd, UINT msg,
|
2001-05-06 14:35:20 +00:00
|
|
|
WPARAM wParam, LPARAM lParam)
|
|
|
|
{
|
2000-10-19 15:43:08 +00:00
|
|
|
switch (msg) {
|
|
|
|
case WM_INITDIALOG:
|
2001-03-03 11:54:34 +00:00
|
|
|
/*
|
|
|
|
* Centre the window.
|
|
|
|
*/
|
|
|
|
{ /* centre the window */
|
|
|
|
RECT rs, rd;
|
|
|
|
HWND hw;
|
|
|
|
|
|
|
|
hw = GetDesktopWindow();
|
2001-05-06 14:35:20 +00:00
|
|
|
if (GetWindowRect(hw, &rs) && GetWindowRect(hwnd, &rd))
|
|
|
|
MoveWindow(hwnd,
|
|
|
|
(rs.right + rs.left + rd.left - rd.right) / 2,
|
|
|
|
(rs.bottom + rs.top + rd.top - rd.bottom) / 2,
|
2018-10-29 19:50:29 +00:00
|
|
|
rd.right - rd.left, rd.bottom - rd.top, true);
|
2001-03-03 11:54:34 +00:00
|
|
|
}
|
|
|
|
|
2015-12-22 10:18:48 +00:00
|
|
|
{
|
2017-01-21 14:55:53 +00:00
|
|
|
char *buildinfo_text = buildinfo("\r\n");
|
2015-12-22 10:18:48 +00:00
|
|
|
char *text = dupprintf
|
2017-01-21 14:55:53 +00:00
|
|
|
("PuTTYgen\r\n\r\n%s\r\n\r\n%s\r\n\r\n%s",
|
|
|
|
ver, buildinfo_text,
|
2015-12-22 12:43:31 +00:00
|
|
|
"\251 " SHORT_COPYRIGHT_DETAILS ". All rights reserved.");
|
2017-01-21 14:55:53 +00:00
|
|
|
sfree(buildinfo_text);
|
2015-12-22 10:18:48 +00:00
|
|
|
SetDlgItemText(hwnd, 1000, text);
|
|
|
|
sfree(text);
|
|
|
|
}
|
2000-10-19 15:43:08 +00:00
|
|
|
return 1;
|
|
|
|
case WM_COMMAND:
|
|
|
|
switch (LOWORD(wParam)) {
|
|
|
|
case IDOK:
|
2004-10-27 15:50:52 +00:00
|
|
|
case IDCANCEL:
|
2001-05-06 14:35:20 +00:00
|
|
|
EndDialog(hwnd, 1);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
|
|
|
case 101:
|
|
|
|
EnableWindow(hwnd, 0);
|
2003-02-07 14:22:19 +00:00
|
|
|
DialogBox(hinst, MAKEINTRESOURCE(214), hwnd, LicenceProc);
|
2000-10-19 15:43:08 +00:00
|
|
|
EnableWindow(hwnd, 1);
|
2001-05-06 14:35:20 +00:00
|
|
|
SetActiveWindow(hwnd);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
2017-02-22 06:56:43 +00:00
|
|
|
case 102:
|
|
|
|
/* Load web browser */
|
|
|
|
ShellExecute(hwnd, "open",
|
2017-05-07 15:29:01 +00:00
|
|
|
"https://www.chiark.greenend.org.uk/~sgtatham/putty/",
|
2017-02-22 06:56:43 +00:00
|
|
|
0, 0, SW_SHOWDEFAULT);
|
|
|
|
return 0;
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
case WM_CLOSE:
|
2001-05-06 14:35:20 +00:00
|
|
|
EndDialog(hwnd, 1);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2015-05-09 14:02:54 +00:00
|
|
|
typedef enum {RSA, DSA, ECDSA, ED25519} keytype;
|
2014-11-01 09:14:19 +00:00
|
|
|
|
2000-10-19 15:43:08 +00:00
|
|
|
/*
|
|
|
|
* Thread to generate a key.
|
|
|
|
*/
|
|
|
|
struct rsa_key_thread_params {
|
2001-05-06 14:35:20 +00:00
|
|
|
HWND progressbar; /* notify this with progress */
|
|
|
|
HWND dialog; /* notify this on completion */
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
int key_bits; /* bits in key modulus (RSA, DSA) */
|
|
|
|
int curve_bits; /* bits in elliptic curve (ECDSA) */
|
2014-11-01 09:14:19 +00:00
|
|
|
keytype keytype;
|
|
|
|
union {
|
|
|
|
struct RSAKey *key;
|
|
|
|
struct dss_key *dsskey;
|
2014-11-01 09:45:20 +00:00
|
|
|
struct ec_key *eckey;
|
2014-11-01 09:14:19 +00:00
|
|
|
};
|
2000-10-19 15:43:08 +00:00
|
|
|
};
|
2016-03-30 10:28:59 +00:00
|
|
|
static DWORD WINAPI generate_key_thread(void *param)
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
2000-10-19 15:43:08 +00:00
|
|
|
struct rsa_key_thread_params *params =
|
2001-05-06 14:35:20 +00:00
|
|
|
(struct rsa_key_thread_params *) param;
|
2000-10-19 15:43:08 +00:00
|
|
|
struct progress prog;
|
|
|
|
prog.progbar = params->progressbar;
|
|
|
|
|
2001-11-12 09:19:57 +00:00
|
|
|
progress_update(&prog, PROGFN_INITIALISE, 0, 0);
|
|
|
|
|
2014-11-01 09:14:19 +00:00
|
|
|
if (params->keytype == DSA)
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
dsa_generate(params->dsskey, params->key_bits, progress_update, &prog);
|
2014-11-01 09:45:20 +00:00
|
|
|
else if (params->keytype == ECDSA)
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
ec_generate(params->eckey, params->curve_bits, progress_update, &prog);
|
2015-05-09 14:02:54 +00:00
|
|
|
else if (params->keytype == ED25519)
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
ec_edgenerate(params->eckey, 256, progress_update, &prog);
|
2001-09-22 20:52:21 +00:00
|
|
|
else
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
rsa_generate(params->key, params->key_bits, progress_update, &prog);
|
2000-10-19 15:43:08 +00:00
|
|
|
|
|
|
|
PostMessage(params->dialog, WM_DONEKEY, 0, 0);
|
|
|
|
|
2000-12-12 10:33:13 +00:00
|
|
|
sfree(params);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
|
|
|
struct MainDlgState {
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
bool collecting_entropy;
|
|
|
|
bool generation_thread_exists;
|
|
|
|
bool key_exists;
|
2000-10-19 15:43:08 +00:00
|
|
|
int entropy_got, entropy_required, entropy_size;
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
int key_bits, curve_bits;
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
bool ssh2;
|
2014-11-01 09:14:19 +00:00
|
|
|
keytype keytype;
|
2001-03-03 11:54:34 +00:00
|
|
|
char **commentptr; /* points to key.comment or ssh2key.comment */
|
|
|
|
struct ssh2_userkey ssh2key;
|
2000-10-19 15:43:08 +00:00
|
|
|
unsigned *entropy;
|
2014-11-01 09:14:19 +00:00
|
|
|
union {
|
|
|
|
struct RSAKey key;
|
|
|
|
struct dss_key dsskey;
|
2014-11-01 09:45:20 +00:00
|
|
|
struct ec_key eckey;
|
2014-11-01 09:14:19 +00:00
|
|
|
};
|
2002-05-18 09:20:41 +00:00
|
|
|
HMENU filemenu, keymenu, cvtmenu;
|
2000-10-19 15:43:08 +00:00
|
|
|
};
|
|
|
|
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
static void hidemany(HWND hwnd, const int *ids, bool hideit)
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
2000-10-19 15:43:08 +00:00
|
|
|
while (*ids) {
|
2001-05-06 14:35:20 +00:00
|
|
|
ShowWindow(GetDlgItem(hwnd, *ids++), (hideit ? SW_HIDE : SW_SHOW));
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2001-08-27 17:40:03 +00:00
|
|
|
static void setupbigedit1(HWND hwnd, int id, int idstatic, struct RSAKey *key)
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
2015-05-12 12:42:26 +00:00
|
|
|
char *buffer = ssh1_pubkey_str(key);
|
2000-10-19 15:43:08 +00:00
|
|
|
SetDlgItemText(hwnd, id, buffer);
|
2001-08-27 17:40:03 +00:00
|
|
|
SetDlgItemText(hwnd, idstatic,
|
|
|
|
"&Public key for pasting into authorized_keys file:");
|
2000-12-12 10:33:13 +00:00
|
|
|
sfree(buffer);
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|
|
|
|
|
2001-08-27 17:40:03 +00:00
|
|
|
static void setupbigedit2(HWND hwnd, int id, int idstatic,
|
|
|
|
struct ssh2_userkey *key)
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
2015-05-12 12:42:26 +00:00
|
|
|
char *buffer = ssh2_pubkey_openssh_str(key);
|
2001-03-03 11:54:34 +00:00
|
|
|
SetDlgItemText(hwnd, id, buffer);
|
2001-08-27 17:40:03 +00:00
|
|
|
SetDlgItemText(hwnd, idstatic, "&Public key for pasting into "
|
2003-11-24 13:40:58 +00:00
|
|
|
"OpenSSH authorized_keys file:");
|
2001-05-06 14:35:20 +00:00
|
|
|
sfree(buffer);
|
2001-03-03 11:54:34 +00:00
|
|
|
}
|
|
|
|
|
2001-11-25 14:31:46 +00:00
|
|
|
/*
|
|
|
|
* Warn about the obsolescent key file format.
|
|
|
|
*/
|
|
|
|
void old_keyfile_warning(void)
|
|
|
|
{
|
|
|
|
static const char mbtitle[] = "PuTTY Key File Warning";
|
|
|
|
static const char message[] =
|
2005-03-10 16:36:05 +00:00
|
|
|
"You are loading an SSH-2 private key which has an\n"
|
2001-11-25 14:31:46 +00:00
|
|
|
"old version of the file format. This means your key\n"
|
|
|
|
"file is not fully tamperproof. Future versions of\n"
|
|
|
|
"PuTTY may stop supporting this private key format,\n"
|
|
|
|
"so we recommend you convert your key to the new\n"
|
|
|
|
"format.\n"
|
|
|
|
"\n"
|
|
|
|
"Once the key is loaded into PuTTYgen, you can perform\n"
|
|
|
|
"this conversion simply by saving it again.";
|
|
|
|
|
|
|
|
MessageBox(NULL, message, mbtitle, MB_OK);
|
|
|
|
}
|
|
|
|
|
2002-05-15 20:07:11 +00:00
|
|
|
enum {
|
|
|
|
controlidstart = 100,
|
|
|
|
IDC_QUIT,
|
|
|
|
IDC_TITLE,
|
|
|
|
IDC_BOX_KEY,
|
|
|
|
IDC_NOKEY,
|
|
|
|
IDC_GENERATING,
|
|
|
|
IDC_PROGRESS,
|
|
|
|
IDC_PKSTATIC, IDC_KEYDISPLAY,
|
|
|
|
IDC_FPSTATIC, IDC_FINGERPRINT,
|
|
|
|
IDC_COMMENTSTATIC, IDC_COMMENTEDIT,
|
|
|
|
IDC_PASSPHRASE1STATIC, IDC_PASSPHRASE1EDIT,
|
|
|
|
IDC_PASSPHRASE2STATIC, IDC_PASSPHRASE2EDIT,
|
|
|
|
IDC_BOX_ACTIONS,
|
|
|
|
IDC_GENSTATIC, IDC_GENERATE,
|
|
|
|
IDC_LOADSTATIC, IDC_LOAD,
|
|
|
|
IDC_SAVESTATIC, IDC_SAVE, IDC_SAVEPUB,
|
|
|
|
IDC_BOX_PARAMS,
|
|
|
|
IDC_TYPESTATIC, IDC_KEYSSH1, IDC_KEYSSH2RSA, IDC_KEYSSH2DSA,
|
2015-05-09 14:02:54 +00:00
|
|
|
IDC_KEYSSH2ECDSA, IDC_KEYSSH2ED25519,
|
2002-05-15 20:07:11 +00:00
|
|
|
IDC_BITSSTATIC, IDC_BITS,
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
IDC_CURVESTATIC, IDC_CURVE,
|
|
|
|
IDC_NOTHINGSTATIC,
|
2002-05-15 20:07:11 +00:00
|
|
|
IDC_ABOUT,
|
|
|
|
IDC_GIVEHELP,
|
2015-04-28 18:46:58 +00:00
|
|
|
IDC_IMPORT,
|
2015-05-10 06:42:48 +00:00
|
|
|
IDC_EXPORT_OPENSSH_AUTO, IDC_EXPORT_OPENSSH_NEW,
|
2015-04-28 18:46:58 +00:00
|
|
|
IDC_EXPORT_SSHCOM
|
2002-05-15 20:07:11 +00:00
|
|
|
};
|
|
|
|
|
|
|
|
static const int nokey_ids[] = { IDC_NOKEY, 0 };
|
|
|
|
static const int generating_ids[] = { IDC_GENERATING, IDC_PROGRESS, 0 };
|
|
|
|
static const int gotkey_ids[] = {
|
|
|
|
IDC_PKSTATIC, IDC_KEYDISPLAY,
|
|
|
|
IDC_FPSTATIC, IDC_FINGERPRINT,
|
|
|
|
IDC_COMMENTSTATIC, IDC_COMMENTEDIT,
|
|
|
|
IDC_PASSPHRASE1STATIC, IDC_PASSPHRASE1EDIT,
|
|
|
|
IDC_PASSPHRASE2STATIC, IDC_PASSPHRASE2EDIT, 0
|
|
|
|
};
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Small UI helper function to switch the state of the main dialog
|
|
|
|
* by enabling and disabling controls and menu items.
|
|
|
|
*/
|
|
|
|
void ui_set_state(HWND hwnd, struct MainDlgState *state, int status)
|
|
|
|
{
|
|
|
|
int type;
|
|
|
|
|
|
|
|
switch (status) {
|
|
|
|
case 0: /* no key */
|
2018-10-29 19:50:29 +00:00
|
|
|
hidemany(hwnd, nokey_ids, false);
|
|
|
|
hidemany(hwnd, generating_ids, true);
|
|
|
|
hidemany(hwnd, gotkey_ids, true);
|
2002-05-15 20:07:11 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_GENERATE), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_LOAD), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_SAVE), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_SAVEPUB), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH1), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2RSA), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2DSA), 1);
|
2014-11-01 09:45:20 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2ECDSA), 1);
|
2015-05-09 14:02:54 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2ED25519), 1);
|
2002-05-15 20:07:11 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_BITS), 1);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_LOAD, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_SAVE, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_SAVEPUB, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_GENERATE, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH1, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2RSA, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2DSA, MF_ENABLED|MF_BYCOMMAND);
|
2014-11-01 09:45:20 +00:00
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2ECDSA,
|
|
|
|
MF_ENABLED|MF_BYCOMMAND);
|
2015-05-09 14:02:54 +00:00
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2ED25519,
|
|
|
|
MF_ENABLED|MF_BYCOMMAND);
|
2002-05-18 09:20:41 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, IDC_IMPORT, MF_ENABLED|MF_BYCOMMAND);
|
2015-05-10 06:42:48 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, IDC_EXPORT_OPENSSH_AUTO,
|
2015-04-28 18:46:58 +00:00
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->cvtmenu, IDC_EXPORT_OPENSSH_NEW,
|
2002-05-15 20:07:11 +00:00
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
2002-05-18 09:20:41 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, IDC_EXPORT_SSHCOM,
|
2002-05-15 20:07:11 +00:00
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
break;
|
|
|
|
case 1: /* generating key */
|
2018-10-29 19:50:29 +00:00
|
|
|
hidemany(hwnd, nokey_ids, true);
|
|
|
|
hidemany(hwnd, generating_ids, false);
|
|
|
|
hidemany(hwnd, gotkey_ids, true);
|
2002-05-15 20:07:11 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_GENERATE), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_LOAD), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_SAVE), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_SAVEPUB), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH1), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2RSA), 0);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2DSA), 0);
|
2014-11-01 09:45:20 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2ECDSA), 0);
|
2015-05-09 14:02:54 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2ED25519), 0);
|
2002-05-15 20:07:11 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_BITS), 0);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_LOAD, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_SAVE, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_SAVEPUB, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_GENERATE, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH1, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2RSA, MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2DSA, MF_GRAYED|MF_BYCOMMAND);
|
2014-11-01 09:45:20 +00:00
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2ECDSA,
|
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
2015-05-09 14:02:54 +00:00
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2ED25519,
|
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
2002-05-18 09:20:41 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, IDC_IMPORT, MF_GRAYED|MF_BYCOMMAND);
|
2015-05-10 06:42:48 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, IDC_EXPORT_OPENSSH_AUTO,
|
2015-04-28 18:46:58 +00:00
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->cvtmenu, IDC_EXPORT_OPENSSH_NEW,
|
2002-05-15 20:07:11 +00:00
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
2002-05-18 09:20:41 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, IDC_EXPORT_SSHCOM,
|
2002-05-15 20:07:11 +00:00
|
|
|
MF_GRAYED|MF_BYCOMMAND);
|
|
|
|
break;
|
|
|
|
case 2:
|
2018-10-29 19:50:29 +00:00
|
|
|
hidemany(hwnd, nokey_ids, true);
|
|
|
|
hidemany(hwnd, generating_ids, true);
|
|
|
|
hidemany(hwnd, gotkey_ids, false);
|
2002-05-15 20:07:11 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_GENERATE), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_LOAD), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_SAVE), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_SAVEPUB), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH1), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2RSA), 1);
|
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2DSA), 1);
|
2014-11-01 09:45:20 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2ECDSA), 1);
|
2015-05-09 14:02:54 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_KEYSSH2ED25519), 1);
|
2002-05-15 20:07:11 +00:00
|
|
|
EnableWindow(GetDlgItem(hwnd, IDC_BITS), 1);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_LOAD, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_SAVE, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->filemenu, IDC_SAVEPUB, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_GENERATE, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH1, MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2RSA,MF_ENABLED|MF_BYCOMMAND);
|
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2DSA,MF_ENABLED|MF_BYCOMMAND);
|
2014-11-01 09:45:20 +00:00
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2ECDSA,
|
|
|
|
MF_ENABLED|MF_BYCOMMAND);
|
2015-05-09 14:02:54 +00:00
|
|
|
EnableMenuItem(state->keymenu, IDC_KEYSSH2ED25519,
|
|
|
|
MF_ENABLED|MF_BYCOMMAND);
|
2002-05-18 09:20:41 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, IDC_IMPORT, MF_ENABLED|MF_BYCOMMAND);
|
2002-05-15 20:07:11 +00:00
|
|
|
/*
|
|
|
|
* Enable export menu items if and only if the key type
|
|
|
|
* supports this kind of export.
|
|
|
|
*/
|
|
|
|
type = state->ssh2 ? SSH_KEYTYPE_SSH2 : SSH_KEYTYPE_SSH1;
|
|
|
|
#define do_export_menuitem(x,y) \
|
2002-05-18 09:20:41 +00:00
|
|
|
EnableMenuItem(state->cvtmenu, x, MF_BYCOMMAND | \
|
2002-05-15 20:07:11 +00:00
|
|
|
(import_target_type(y)==type?MF_ENABLED:MF_GRAYED))
|
2015-05-10 06:42:48 +00:00
|
|
|
do_export_menuitem(IDC_EXPORT_OPENSSH_AUTO, SSH_KEYTYPE_OPENSSH_AUTO);
|
2015-04-28 18:46:58 +00:00
|
|
|
do_export_menuitem(IDC_EXPORT_OPENSSH_NEW, SSH_KEYTYPE_OPENSSH_NEW);
|
2002-05-15 20:07:11 +00:00
|
|
|
do_export_menuitem(IDC_EXPORT_SSHCOM, SSH_KEYTYPE_SSHCOM);
|
|
|
|
#undef do_export_menuitem
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
/*
|
|
|
|
* Helper functions to set the key type, taking care of keeping the
|
|
|
|
* menu and radio button selections in sync and also showing/hiding
|
|
|
|
* the appropriate size/curve control for the current key type.
|
|
|
|
*/
|
|
|
|
void ui_update_key_type_ctrls(HWND hwnd)
|
|
|
|
{
|
|
|
|
enum { BITS, CURVE, NOTHING } which;
|
|
|
|
static const int bits_ids[] = {
|
|
|
|
IDC_BITSSTATIC, IDC_BITS, 0
|
|
|
|
};
|
|
|
|
static const int curve_ids[] = {
|
|
|
|
IDC_CURVESTATIC, IDC_CURVE, 0
|
|
|
|
};
|
|
|
|
static const int nothing_ids[] = {
|
|
|
|
IDC_NOTHINGSTATIC, 0
|
|
|
|
};
|
|
|
|
|
|
|
|
if (IsDlgButtonChecked(hwnd, IDC_KEYSSH1) ||
|
|
|
|
IsDlgButtonChecked(hwnd, IDC_KEYSSH2RSA) ||
|
|
|
|
IsDlgButtonChecked(hwnd, IDC_KEYSSH2DSA)) {
|
|
|
|
which = BITS;
|
|
|
|
} else if (IsDlgButtonChecked(hwnd, IDC_KEYSSH2ECDSA)) {
|
|
|
|
which = CURVE;
|
|
|
|
} else {
|
|
|
|
/* ED25519 implicitly only supports one curve */
|
|
|
|
which = NOTHING;
|
|
|
|
}
|
|
|
|
|
|
|
|
hidemany(hwnd, bits_ids, which != BITS);
|
|
|
|
hidemany(hwnd, curve_ids, which != CURVE);
|
|
|
|
hidemany(hwnd, nothing_ids, which != NOTHING);
|
|
|
|
}
|
|
|
|
void ui_set_key_type(HWND hwnd, struct MainDlgState *state, int button)
|
|
|
|
{
|
|
|
|
CheckRadioButton(hwnd, IDC_KEYSSH1, IDC_KEYSSH2ED25519, button);
|
|
|
|
CheckMenuRadioItem(state->keymenu, IDC_KEYSSH1, IDC_KEYSSH2ED25519,
|
|
|
|
button, MF_BYCOMMAND);
|
|
|
|
ui_update_key_type_ctrls(hwnd);
|
|
|
|
}
|
|
|
|
|
2002-08-06 17:48:14 +00:00
|
|
|
void load_key_file(HWND hwnd, struct MainDlgState *state,
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
Filename *filename, bool was_import_cmd)
|
2002-08-06 17:48:14 +00:00
|
|
|
{
|
2011-10-02 14:14:21 +00:00
|
|
|
char *passphrase;
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
bool needs_pass;
|
2002-08-06 17:48:14 +00:00
|
|
|
int type, realtype;
|
|
|
|
int ret;
|
2005-02-27 23:01:11 +00:00
|
|
|
const char *errmsg = NULL;
|
2002-08-06 17:48:14 +00:00
|
|
|
char *comment;
|
|
|
|
struct RSAKey newkey1;
|
|
|
|
struct ssh2_userkey *newkey2 = NULL;
|
|
|
|
|
2011-10-02 11:01:57 +00:00
|
|
|
type = realtype = key_type(filename);
|
2002-08-06 17:48:14 +00:00
|
|
|
if (type != SSH_KEYTYPE_SSH1 &&
|
|
|
|
type != SSH_KEYTYPE_SSH2 &&
|
|
|
|
!import_possible(type)) {
|
2005-02-27 23:01:11 +00:00
|
|
|
char *msg = dupprintf("Couldn't load private key (%s)",
|
|
|
|
key_type_to_str(type));
|
2005-03-01 01:16:57 +00:00
|
|
|
message_box(msg, "PuTTYgen Error", MB_OK | MB_ICONERROR,
|
|
|
|
HELPCTXID(errors_cantloadkey));
|
2005-02-27 23:01:11 +00:00
|
|
|
sfree(msg);
|
2002-08-06 17:48:14 +00:00
|
|
|
return;
|
|
|
|
}
|
|
|
|
|
|
|
|
if (type != SSH_KEYTYPE_SSH1 &&
|
|
|
|
type != SSH_KEYTYPE_SSH2) {
|
|
|
|
realtype = type;
|
|
|
|
type = import_target_type(type);
|
|
|
|
}
|
|
|
|
|
|
|
|
comment = NULL;
|
2011-10-02 14:14:21 +00:00
|
|
|
passphrase = NULL;
|
2002-08-06 17:48:14 +00:00
|
|
|
if (realtype == SSH_KEYTYPE_SSH1)
|
2018-05-24 07:22:44 +00:00
|
|
|
needs_pass = rsa_ssh1_encrypted(filename, &comment);
|
2002-08-06 17:48:14 +00:00
|
|
|
else if (realtype == SSH_KEYTYPE_SSH2)
|
2011-10-02 11:01:57 +00:00
|
|
|
needs_pass = ssh2_userkey_encrypted(filename, &comment);
|
2002-08-06 17:48:14 +00:00
|
|
|
else
|
2011-10-02 11:01:57 +00:00
|
|
|
needs_pass = import_encrypted(filename, realtype, &comment);
|
2002-08-06 17:48:14 +00:00
|
|
|
do {
|
2011-10-02 14:14:21 +00:00
|
|
|
burnstr(passphrase);
|
|
|
|
passphrase = NULL;
|
|
|
|
|
2002-08-06 17:48:14 +00:00
|
|
|
if (needs_pass) {
|
|
|
|
int dlgret;
|
2011-10-02 14:14:21 +00:00
|
|
|
struct PassphraseProcStruct pps;
|
|
|
|
pps.passphrase = &passphrase;
|
|
|
|
pps.comment = comment;
|
2002-08-06 17:48:14 +00:00
|
|
|
dlgret = DialogBoxParam(hinst,
|
|
|
|
MAKEINTRESOURCE(210),
|
|
|
|
NULL, PassphraseProc,
|
2005-03-02 15:53:50 +00:00
|
|
|
(LPARAM) &pps);
|
2002-08-06 17:48:14 +00:00
|
|
|
if (!dlgret) {
|
|
|
|
ret = -2;
|
|
|
|
break;
|
|
|
|
}
|
2011-10-02 14:14:21 +00:00
|
|
|
assert(passphrase != NULL);
|
2002-08-06 17:48:14 +00:00
|
|
|
} else
|
2011-10-02 14:14:21 +00:00
|
|
|
passphrase = dupstr("");
|
2002-08-06 17:48:14 +00:00
|
|
|
if (type == SSH_KEYTYPE_SSH1) {
|
|
|
|
if (realtype == type)
|
2018-05-24 07:22:44 +00:00
|
|
|
ret = rsa_ssh1_loadkey(
|
|
|
|
filename, &newkey1, passphrase, &errmsg);
|
2002-08-06 17:48:14 +00:00
|
|
|
else
|
2011-10-02 11:01:57 +00:00
|
|
|
ret = import_ssh1(filename, realtype, &newkey1,
|
|
|
|
passphrase, &errmsg);
|
2002-08-06 17:48:14 +00:00
|
|
|
} else {
|
|
|
|
if (realtype == type)
|
2011-10-02 11:01:57 +00:00
|
|
|
newkey2 = ssh2_load_userkey(filename, passphrase, &errmsg);
|
2002-08-06 17:48:14 +00:00
|
|
|
else
|
2011-10-02 11:01:57 +00:00
|
|
|
newkey2 = import_ssh2(filename, realtype, passphrase, &errmsg);
|
2002-08-06 17:48:14 +00:00
|
|
|
if (newkey2 == SSH2_WRONG_PASSPHRASE)
|
|
|
|
ret = -1;
|
|
|
|
else if (!newkey2)
|
|
|
|
ret = 0;
|
|
|
|
else
|
|
|
|
ret = 1;
|
|
|
|
}
|
|
|
|
} while (ret == -1);
|
|
|
|
if (comment)
|
|
|
|
sfree(comment);
|
|
|
|
if (ret == 0) {
|
2005-02-27 23:01:11 +00:00
|
|
|
char *msg = dupprintf("Couldn't load private key (%s)", errmsg);
|
2005-03-01 01:16:57 +00:00
|
|
|
message_box(msg, "PuTTYgen Error", MB_OK | MB_ICONERROR,
|
|
|
|
HELPCTXID(errors_cantloadkey));
|
2005-02-27 23:01:11 +00:00
|
|
|
sfree(msg);
|
2002-08-06 17:48:14 +00:00
|
|
|
} else if (ret == 1) {
|
|
|
|
/*
|
|
|
|
* Now update the key controls with all the
|
|
|
|
* key data.
|
|
|
|
*/
|
|
|
|
{
|
|
|
|
SetDlgItemText(hwnd, IDC_PASSPHRASE1EDIT,
|
|
|
|
passphrase);
|
|
|
|
SetDlgItemText(hwnd, IDC_PASSPHRASE2EDIT,
|
|
|
|
passphrase);
|
|
|
|
if (type == SSH_KEYTYPE_SSH1) {
|
2018-06-03 07:08:53 +00:00
|
|
|
char *fingerprint, *savecomment;
|
2002-08-06 17:48:14 +00:00
|
|
|
|
2018-10-29 19:50:29 +00:00
|
|
|
state->ssh2 = false;
|
2002-08-06 17:48:14 +00:00
|
|
|
state->commentptr = &state->key.comment;
|
|
|
|
state->key = newkey1;
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Set the key fingerprint.
|
|
|
|
*/
|
|
|
|
savecomment = state->key.comment;
|
|
|
|
state->key.comment = NULL;
|
2018-06-03 07:08:53 +00:00
|
|
|
fingerprint = rsa_ssh1_fingerprint(&state->key);
|
2002-08-06 17:48:14 +00:00
|
|
|
state->key.comment = savecomment;
|
2018-06-03 07:08:53 +00:00
|
|
|
SetDlgItemText(hwnd, IDC_FINGERPRINT, fingerprint);
|
|
|
|
sfree(fingerprint);
|
2002-08-06 17:48:14 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* Construct a decimal representation
|
|
|
|
* of the key, for pasting into
|
|
|
|
* .ssh/authorized_keys on a Unix box.
|
|
|
|
*/
|
|
|
|
setupbigedit1(hwnd, IDC_KEYDISPLAY,
|
|
|
|
IDC_PKSTATIC, &state->key);
|
|
|
|
} else {
|
|
|
|
char *fp;
|
|
|
|
char *savecomment;
|
|
|
|
|
2018-10-29 19:50:29 +00:00
|
|
|
state->ssh2 = true;
|
2002-08-06 17:48:14 +00:00
|
|
|
state->commentptr =
|
|
|
|
&state->ssh2key.comment;
|
|
|
|
state->ssh2key = *newkey2; /* structure copy */
|
|
|
|
sfree(newkey2);
|
|
|
|
|
|
|
|
savecomment = state->ssh2key.comment;
|
|
|
|
state->ssh2key.comment = NULL;
|
2018-06-03 11:58:05 +00:00
|
|
|
fp = ssh2_fingerprint(state->ssh2key.key);
|
2002-08-06 17:48:14 +00:00
|
|
|
state->ssh2key.comment = savecomment;
|
|
|
|
|
|
|
|
SetDlgItemText(hwnd, IDC_FINGERPRINT, fp);
|
|
|
|
sfree(fp);
|
|
|
|
|
|
|
|
setupbigedit2(hwnd, IDC_KEYDISPLAY,
|
|
|
|
IDC_PKSTATIC, &state->ssh2key);
|
|
|
|
}
|
|
|
|
SetDlgItemText(hwnd, IDC_COMMENTEDIT,
|
|
|
|
*state->commentptr);
|
|
|
|
}
|
|
|
|
/*
|
|
|
|
* Finally, hide the progress bar and show
|
|
|
|
* the key data.
|
|
|
|
*/
|
|
|
|
ui_set_state(hwnd, state, 2);
|
2018-10-29 19:50:29 +00:00
|
|
|
state->key_exists = true;
|
2002-08-06 17:48:14 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* If the user has imported a foreign key
|
|
|
|
* using the Load command, let them know.
|
|
|
|
* If they've used the Import command, be
|
|
|
|
* silent.
|
|
|
|
*/
|
|
|
|
if (realtype != type && !was_import_cmd) {
|
|
|
|
char msg[512];
|
|
|
|
sprintf(msg, "Successfully imported foreign key\n"
|
|
|
|
"(%s).\n"
|
|
|
|
"To use this key with PuTTY, you need to\n"
|
|
|
|
"use the \"Save private key\" command to\n"
|
|
|
|
"save it in PuTTY's own format.",
|
|
|
|
key_type_to_str(realtype));
|
|
|
|
MessageBox(NULL, msg, "PuTTYgen Notice",
|
|
|
|
MB_OK | MB_ICONINFORMATION);
|
|
|
|
}
|
|
|
|
}
|
2011-10-02 14:14:21 +00:00
|
|
|
burnstr(passphrase);
|
2002-08-06 17:48:14 +00:00
|
|
|
}
|
|
|
|
|
2018-06-03 13:41:31 +00:00
|
|
|
static void start_generating_key(HWND hwnd, struct MainDlgState *state)
|
|
|
|
{
|
|
|
|
static const char generating_msg[] =
|
|
|
|
"Please wait while a key is generated...";
|
|
|
|
|
|
|
|
struct rsa_key_thread_params *params;
|
|
|
|
DWORD threadid;
|
|
|
|
|
|
|
|
SetDlgItemText(hwnd, IDC_GENERATING, generating_msg);
|
|
|
|
SendDlgItemMessage(hwnd, IDC_PROGRESS, PBM_SETRANGE, 0,
|
|
|
|
MAKELPARAM(0, PROGRESSRANGE));
|
|
|
|
SendDlgItemMessage(hwnd, IDC_PROGRESS, PBM_SETPOS, 0, 0);
|
|
|
|
|
|
|
|
params = snew(struct rsa_key_thread_params);
|
|
|
|
params->progressbar = GetDlgItem(hwnd, IDC_PROGRESS);
|
|
|
|
params->dialog = hwnd;
|
|
|
|
params->key_bits = state->key_bits;
|
|
|
|
params->curve_bits = state->curve_bits;
|
|
|
|
params->keytype = state->keytype;
|
|
|
|
params->key = &state->key;
|
|
|
|
params->dsskey = &state->dsskey;
|
|
|
|
|
|
|
|
if (!CreateThread(NULL, 0, generate_key_thread,
|
|
|
|
params, 0, &threadid)) {
|
|
|
|
MessageBox(hwnd, "Out of thread resources",
|
|
|
|
"Key generation error",
|
|
|
|
MB_OK | MB_ICONERROR);
|
|
|
|
sfree(params);
|
|
|
|
} else {
|
2018-10-29 19:50:29 +00:00
|
|
|
state->generation_thread_exists = true;
|
2018-06-03 13:41:31 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2000-10-19 15:43:08 +00:00
|
|
|
/*
|
|
|
|
* Dialog-box function for the main PuTTYgen dialog box.
|
|
|
|
*/
|
2015-08-11 12:22:09 +00:00
|
|
|
static INT_PTR CALLBACK MainDlgProc(HWND hwnd, UINT msg,
|
2001-05-06 14:35:20 +00:00
|
|
|
WPARAM wParam, LPARAM lParam)
|
|
|
|
{
|
2000-10-19 15:43:08 +00:00
|
|
|
static const char entropy_msg[] =
|
2001-05-06 14:35:20 +00:00
|
|
|
"Please generate some randomness by moving the mouse over the blank area.";
|
2000-10-19 15:43:08 +00:00
|
|
|
struct MainDlgState *state;
|
|
|
|
|
|
|
|
switch (msg) {
|
|
|
|
case WM_INITDIALOG:
|
2006-12-17 11:16:07 +00:00
|
|
|
if (has_help())
|
2005-05-21 14:16:43 +00:00
|
|
|
SetWindowLongPtr(hwnd, GWL_EXSTYLE,
|
|
|
|
GetWindowLongPtr(hwnd, GWL_EXSTYLE) |
|
|
|
|
WS_EX_CONTEXTHELP);
|
2001-12-12 18:45:56 +00:00
|
|
|
else {
|
|
|
|
/*
|
|
|
|
* If we add a Help button, this is where we destroy it
|
|
|
|
* if the help file isn't present.
|
|
|
|
*/
|
|
|
|
}
|
2003-02-07 13:54:34 +00:00
|
|
|
SendMessage(hwnd, WM_SETICON, (WPARAM) ICON_BIG,
|
|
|
|
(LPARAM) LoadIcon(hinst, MAKEINTRESOURCE(200)));
|
2001-12-12 18:45:56 +00:00
|
|
|
|
2003-03-29 16:14:26 +00:00
|
|
|
state = snew(struct MainDlgState);
|
2018-10-29 19:50:29 +00:00
|
|
|
state->generation_thread_exists = false;
|
|
|
|
state->collecting_entropy = false;
|
2002-05-15 20:07:11 +00:00
|
|
|
state->entropy = NULL;
|
2018-10-29 19:50:29 +00:00
|
|
|
state->key_exists = false;
|
2005-05-21 14:16:43 +00:00
|
|
|
SetWindowLongPtr(hwnd, GWLP_USERDATA, (LONG_PTR) state);
|
2002-05-11 16:45:29 +00:00
|
|
|
{
|
|
|
|
HMENU menu, menu1;
|
|
|
|
|
|
|
|
menu = CreateMenu();
|
|
|
|
|
|
|
|
menu1 = CreateMenu();
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_LOAD, "&Load private key");
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_SAVEPUB, "Save p&ublic key");
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_SAVE, "&Save private key");
|
2002-05-15 20:07:11 +00:00
|
|
|
AppendMenu(menu1, MF_SEPARATOR, 0, 0);
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_QUIT, "E&xit");
|
2015-08-11 12:25:42 +00:00
|
|
|
AppendMenu(menu, MF_POPUP | MF_ENABLED, (UINT_PTR) menu1, "&File");
|
2002-05-15 20:07:11 +00:00
|
|
|
state->filemenu = menu1;
|
|
|
|
|
|
|
|
menu1 = CreateMenu();
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_GENERATE, "&Generate key pair");
|
|
|
|
AppendMenu(menu1, MF_SEPARATOR, 0, 0);
|
2005-03-10 16:36:05 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_KEYSSH1, "SSH-&1 key (RSA)");
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_KEYSSH2RSA, "SSH-2 &RSA key");
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_KEYSSH2DSA, "SSH-2 &DSA key");
|
2014-11-01 09:45:20 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_KEYSSH2ECDSA, "SSH-2 &ECDSA key");
|
2015-05-09 14:02:54 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_KEYSSH2ED25519, "SSH-2 ED&25519 key");
|
2015-08-11 12:25:42 +00:00
|
|
|
AppendMenu(menu, MF_POPUP | MF_ENABLED, (UINT_PTR) menu1, "&Key");
|
2002-05-15 20:07:11 +00:00
|
|
|
state->keymenu = menu1;
|
2002-05-11 16:45:29 +00:00
|
|
|
|
|
|
|
menu1 = CreateMenu();
|
2002-05-18 09:20:41 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_IMPORT, "&Import key");
|
|
|
|
AppendMenu(menu1, MF_SEPARATOR, 0, 0);
|
2015-05-10 06:42:48 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_EXPORT_OPENSSH_AUTO,
|
|
|
|
"Export &OpenSSH key");
|
2015-04-28 18:46:58 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_EXPORT_OPENSSH_NEW,
|
2015-05-10 06:42:48 +00:00
|
|
|
"Export &OpenSSH key (force new file format)");
|
2002-05-11 16:45:29 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_EXPORT_SSHCOM,
|
|
|
|
"Export &ssh.com key");
|
2015-08-11 12:25:42 +00:00
|
|
|
AppendMenu(menu, MF_POPUP | MF_ENABLED, (UINT_PTR) menu1,
|
2003-05-24 18:02:49 +00:00
|
|
|
"Con&versions");
|
2002-05-18 09:20:41 +00:00
|
|
|
state->cvtmenu = menu1;
|
2002-05-11 16:45:29 +00:00
|
|
|
|
|
|
|
menu1 = CreateMenu();
|
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_ABOUT, "&About");
|
2006-12-17 11:16:07 +00:00
|
|
|
if (has_help())
|
2002-05-11 16:45:29 +00:00
|
|
|
AppendMenu(menu1, MF_ENABLED, IDC_GIVEHELP, "&Help");
|
2015-08-11 12:25:42 +00:00
|
|
|
AppendMenu(menu, MF_POPUP | MF_ENABLED, (UINT_PTR) menu1, "&Help");
|
2002-05-11 16:45:29 +00:00
|
|
|
|
|
|
|
SetMenu(hwnd, menu);
|
|
|
|
}
|
|
|
|
|
2001-03-03 11:54:34 +00:00
|
|
|
/*
|
|
|
|
* Centre the window.
|
|
|
|
*/
|
|
|
|
{ /* centre the window */
|
|
|
|
RECT rs, rd;
|
|
|
|
HWND hw;
|
|
|
|
|
|
|
|
hw = GetDesktopWindow();
|
2001-05-06 14:35:20 +00:00
|
|
|
if (GetWindowRect(hw, &rs) && GetWindowRect(hwnd, &rd))
|
|
|
|
MoveWindow(hwnd,
|
|
|
|
(rs.right + rs.left + rd.left - rd.right) / 2,
|
|
|
|
(rs.bottom + rs.top + rd.top - rd.bottom) / 2,
|
2018-10-29 19:50:29 +00:00
|
|
|
rd.right - rd.left, rd.bottom - rd.top, true);
|
2001-03-03 11:54:34 +00:00
|
|
|
}
|
|
|
|
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
|
|
|
struct ctlpos cp, cp2;
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
int ymax;
|
2000-10-19 15:43:08 +00:00
|
|
|
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
/* Accelerators used: acglops1rbvde */
|
2000-10-20 09:31:16 +00:00
|
|
|
|
2001-10-30 22:12:49 +00:00
|
|
|
ctlposinit(&cp, hwnd, 4, 4, 4);
|
2001-05-06 14:35:20 +00:00
|
|
|
beginbox(&cp, "Key", IDC_BOX_KEY);
|
|
|
|
cp2 = cp;
|
2001-09-09 10:35:56 +00:00
|
|
|
statictext(&cp2, "No key.", 1, IDC_NOKEY);
|
2001-05-06 14:35:20 +00:00
|
|
|
cp2 = cp;
|
2001-09-09 10:35:56 +00:00
|
|
|
statictext(&cp2, "", 1, IDC_GENERATING);
|
2001-05-06 14:35:20 +00:00
|
|
|
progressbar(&cp2, IDC_PROGRESS);
|
|
|
|
bigeditctrl(&cp,
|
|
|
|
"&Public key for pasting into authorized_keys file:",
|
2001-10-30 22:12:49 +00:00
|
|
|
IDC_PKSTATIC, IDC_KEYDISPLAY, 5);
|
2001-05-06 14:35:20 +00:00
|
|
|
SendDlgItemMessage(hwnd, IDC_KEYDISPLAY, EM_SETREADONLY, 1, 0);
|
2003-05-24 18:02:49 +00:00
|
|
|
staticedit(&cp, "Key f&ingerprint:", IDC_FPSTATIC,
|
2001-05-06 14:35:20 +00:00
|
|
|
IDC_FINGERPRINT, 75);
|
|
|
|
SendDlgItemMessage(hwnd, IDC_FINGERPRINT, EM_SETREADONLY, 1,
|
|
|
|
0);
|
|
|
|
staticedit(&cp, "Key &comment:", IDC_COMMENTSTATIC,
|
|
|
|
IDC_COMMENTEDIT, 75);
|
|
|
|
staticpassedit(&cp, "Key p&assphrase:", IDC_PASSPHRASE1STATIC,
|
|
|
|
IDC_PASSPHRASE1EDIT, 75);
|
|
|
|
staticpassedit(&cp, "C&onfirm passphrase:",
|
|
|
|
IDC_PASSPHRASE2STATIC, IDC_PASSPHRASE2EDIT, 75);
|
|
|
|
endbox(&cp);
|
|
|
|
beginbox(&cp, "Actions", IDC_BOX_ACTIONS);
|
|
|
|
staticbtn(&cp, "Generate a public/private key pair",
|
|
|
|
IDC_GENSTATIC, "&Generate", IDC_GENERATE);
|
|
|
|
staticbtn(&cp, "Load an existing private key file",
|
|
|
|
IDC_LOADSTATIC, "&Load", IDC_LOAD);
|
2001-08-27 17:40:03 +00:00
|
|
|
static2btn(&cp, "Save the generated key", IDC_SAVESTATIC,
|
|
|
|
"Save p&ublic key", IDC_SAVEPUB,
|
|
|
|
"&Save private key", IDC_SAVE);
|
2001-05-06 14:35:20 +00:00
|
|
|
endbox(&cp);
|
|
|
|
beginbox(&cp, "Parameters", IDC_BOX_PARAMS);
|
2015-05-14 12:19:15 +00:00
|
|
|
radioline(&cp, "Type of key to generate:", IDC_TYPESTATIC, 5,
|
|
|
|
"&RSA", IDC_KEYSSH2RSA,
|
|
|
|
"&DSA", IDC_KEYSSH2DSA,
|
|
|
|
"&ECDSA", IDC_KEYSSH2ECDSA,
|
|
|
|
"ED&25519", IDC_KEYSSH2ED25519,
|
2005-03-10 16:36:05 +00:00
|
|
|
"SSH-&1 (RSA)", IDC_KEYSSH1,
|
2015-05-14 12:19:15 +00:00
|
|
|
NULL);
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
cp2 = cp;
|
|
|
|
staticedit(&cp2, "Number of &bits in a generated key:",
|
2000-10-20 10:07:53 +00:00
|
|
|
IDC_BITSSTATIC, IDC_BITS, 20);
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
ymax = cp2.ypos;
|
|
|
|
cp2 = cp;
|
|
|
|
staticddl(&cp2, "Cur&ve to use for generating this key:",
|
|
|
|
IDC_CURVESTATIC, IDC_CURVE, 20);
|
|
|
|
SendDlgItemMessage(hwnd, IDC_CURVE, CB_RESETCONTENT, 0, 0);
|
|
|
|
{
|
|
|
|
int i, bits;
|
|
|
|
const struct ec_curve *curve;
|
Invent a struct type for polymorphic SSH key data.
During last week's work, I made a mistake in which I got the arguments
backwards in one of the key-blob-generating functions - mistakenly
swapped the 'void *' key instance with the 'BinarySink *' output
destination - and I didn't spot the mistake until run time, because in
C you can implicitly convert both to and from void * and so there was
no compile-time failure of type checking.
Now that I've introduced the FROMFIELD macro that downcasts a pointer
to one field of a structure to retrieve a pointer to the whole
structure, I think I might start using that more widely to indicate
this kind of polymorphic subtyping. So now all the public-key
functions in the struct ssh_signkey vtable handle their data instance
in the form of a pointer to a subfield of a new zero-sized structure
type 'ssh_key', which outside the key implementations indicates 'this
is some kind of key instance but it could be of any type'; they
downcast that pointer internally using FROMFIELD in place of the
previous ordinary C cast, and return one by returning &foo->sshk for
whatever foo they've just made up.
The sshk member is not at the beginning of the structure, which means
all those FROMFIELDs and &key->sshk are actually adding and
subtracting an offset. Of course I could have put the member at the
start anyway, but I had the idea that it's actually a feature _not_ to
have the two types start at the same address, because it means you
should notice earlier rather than later if you absentmindedly cast
from one to the other directly rather than by the approved method (in
particular, if you accidentally assign one through a void * and back
without even _noticing_ you perpetrated a cast). In particular, this
enforces that you can't sfree() the thing even once without realising
you should instead of called the right freekey function. (I found
several bugs by this method during initial testing, so I think it's
already proved its worth!)
While I'm here, I've also renamed the vtable structure ssh_signkey to
ssh_keyalg, because it was a confusing name anyway - it describes the
_algorithm_ for handling all keys of that type, not a specific key. So
ssh_keyalg is the collection of code, and ssh_key is one instance of
the data it handles.
2018-05-27 07:32:21 +00:00
|
|
|
const ssh_keyalg *alg;
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
|
|
|
|
for (i = 0; i < n_ec_nist_curve_lengths; i++) {
|
|
|
|
bits = ec_nist_curve_lengths[i];
|
|
|
|
ec_nist_alg_and_curve_by_bits(bits, &curve, &alg);
|
|
|
|
SendDlgItemMessage(hwnd, IDC_CURVE, CB_ADDSTRING, 0,
|
|
|
|
(LPARAM)curve->textname);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
ymax = ymax > cp2.ypos ? ymax : cp2.ypos;
|
|
|
|
cp2 = cp;
|
|
|
|
statictext(&cp2, "(nothing to configure for this key type)",
|
|
|
|
1, IDC_NOTHINGSTATIC);
|
|
|
|
ymax = ymax > cp2.ypos ? ymax : cp2.ypos;
|
|
|
|
cp.ypos = ymax;
|
2001-05-06 14:35:20 +00:00
|
|
|
endbox(&cp);
|
|
|
|
}
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
ui_set_key_type(hwnd, state, IDC_KEYSSH2RSA);
|
2018-10-29 19:50:29 +00:00
|
|
|
SetDlgItemInt(hwnd, IDC_BITS, DEFAULT_KEY_BITS, false);
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
SendDlgItemMessage(hwnd, IDC_CURVE, CB_SETCURSEL,
|
|
|
|
DEFAULT_CURVE_INDEX, 0);
|
2000-10-20 10:07:53 +00:00
|
|
|
|
2001-05-06 14:35:20 +00:00
|
|
|
/*
|
|
|
|
* Initially, hide the progress bar and the key display,
|
|
|
|
* and show the no-key display. Also disable the Save
|
2001-08-27 17:40:03 +00:00
|
|
|
* buttons, because with no key we obviously can't save
|
2001-05-06 14:35:20 +00:00
|
|
|
* anything.
|
|
|
|
*/
|
2002-05-15 20:07:11 +00:00
|
|
|
ui_set_state(hwnd, state, 0);
|
2000-10-19 15:43:08 +00:00
|
|
|
|
2002-08-06 17:48:14 +00:00
|
|
|
/*
|
|
|
|
* Load a key file if one was provided on the command line.
|
|
|
|
*/
|
2013-07-22 19:55:55 +00:00
|
|
|
if (cmdline_keyfile) {
|
|
|
|
Filename *fn = filename_from_str(cmdline_keyfile);
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
load_key_file(hwnd, state, fn, false);
|
2013-07-22 19:55:55 +00:00
|
|
|
filename_free(fn);
|
|
|
|
}
|
2002-08-06 17:48:14 +00:00
|
|
|
|
2000-10-19 15:43:08 +00:00
|
|
|
return 1;
|
|
|
|
case WM_MOUSEMOVE:
|
2005-05-21 14:16:43 +00:00
|
|
|
state = (struct MainDlgState *) GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (state->collecting_entropy &&
|
|
|
|
state->entropy && state->entropy_got < state->entropy_required) {
|
|
|
|
state->entropy[state->entropy_got++] = lParam;
|
|
|
|
state->entropy[state->entropy_got++] = GetMessageTime();
|
|
|
|
SendDlgItemMessage(hwnd, IDC_PROGRESS, PBM_SETPOS,
|
|
|
|
state->entropy_got, 0);
|
|
|
|
if (state->entropy_got >= state->entropy_required) {
|
|
|
|
/*
|
|
|
|
* Seed the entropy pool
|
|
|
|
*/
|
|
|
|
random_add_heavynoise(state->entropy, state->entropy_size);
|
2012-07-22 19:51:50 +00:00
|
|
|
smemclr(state->entropy, state->entropy_size);
|
2001-05-06 14:35:20 +00:00
|
|
|
sfree(state->entropy);
|
2018-10-29 19:50:29 +00:00
|
|
|
state->collecting_entropy = false;
|
2001-05-06 14:35:20 +00:00
|
|
|
|
2018-06-03 13:41:31 +00:00
|
|
|
start_generating_key(hwnd, state);
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
break;
|
2000-10-19 15:43:08 +00:00
|
|
|
case WM_COMMAND:
|
|
|
|
switch (LOWORD(wParam)) {
|
2002-05-15 20:07:11 +00:00
|
|
|
case IDC_KEYSSH1:
|
|
|
|
case IDC_KEYSSH2RSA:
|
|
|
|
case IDC_KEYSSH2DSA:
|
2014-11-01 09:45:20 +00:00
|
|
|
case IDC_KEYSSH2ECDSA:
|
2015-05-09 14:02:54 +00:00
|
|
|
case IDC_KEYSSH2ED25519:
|
2002-05-15 20:07:11 +00:00
|
|
|
{
|
|
|
|
state = (struct MainDlgState *)
|
2005-05-21 14:16:43 +00:00
|
|
|
GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
ui_set_key_type(hwnd, state, LOWORD(wParam));
|
2002-05-15 20:07:11 +00:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case IDC_QUIT:
|
|
|
|
PostMessage(hwnd, WM_CLOSE, 0, 0);
|
|
|
|
break;
|
2000-10-19 15:43:08 +00:00
|
|
|
case IDC_COMMENTEDIT:
|
|
|
|
if (HIWORD(wParam) == EN_CHANGE) {
|
2001-05-06 14:35:20 +00:00
|
|
|
state = (struct MainDlgState *)
|
2005-05-21 14:16:43 +00:00
|
|
|
GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (state->key_exists) {
|
|
|
|
HWND editctl = GetDlgItem(hwnd, IDC_COMMENTEDIT);
|
|
|
|
int len = GetWindowTextLength(editctl);
|
|
|
|
if (*state->commentptr)
|
|
|
|
sfree(*state->commentptr);
|
2003-03-29 16:14:26 +00:00
|
|
|
*state->commentptr = snewn(len + 1, char);
|
2001-05-06 14:35:20 +00:00
|
|
|
GetWindowText(editctl, *state->commentptr, len + 1);
|
2001-03-10 10:22:18 +00:00
|
|
|
if (state->ssh2) {
|
2001-08-27 17:40:03 +00:00
|
|
|
setupbigedit2(hwnd, IDC_KEYDISPLAY, IDC_PKSTATIC,
|
2001-05-06 14:35:20 +00:00
|
|
|
&state->ssh2key);
|
2001-03-10 10:22:18 +00:00
|
|
|
} else {
|
2001-08-27 17:40:03 +00:00
|
|
|
setupbigedit1(hwnd, IDC_KEYDISPLAY, IDC_PKSTATIC,
|
|
|
|
&state->key);
|
2001-03-10 10:22:18 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2000-10-19 15:43:08 +00:00
|
|
|
break;
|
|
|
|
case IDC_ABOUT:
|
|
|
|
EnableWindow(hwnd, 0);
|
2003-02-07 14:22:19 +00:00
|
|
|
DialogBox(hinst, MAKEINTRESOURCE(213), hwnd, AboutProc);
|
2000-10-19 15:43:08 +00:00
|
|
|
EnableWindow(hwnd, 1);
|
2001-05-06 14:35:20 +00:00
|
|
|
SetActiveWindow(hwnd);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
2002-05-11 16:45:29 +00:00
|
|
|
case IDC_GIVEHELP:
|
|
|
|
if (HIWORD(wParam) == BN_CLICKED ||
|
|
|
|
HIWORD(wParam) == BN_DOUBLECLICKED) {
|
2006-12-17 11:16:07 +00:00
|
|
|
launch_help(hwnd, WINHELP_CTX_puttygen_general);
|
2002-05-11 16:45:29 +00:00
|
|
|
}
|
|
|
|
return 0;
|
2001-05-06 14:35:20 +00:00
|
|
|
case IDC_GENERATE:
|
2003-03-22 09:22:52 +00:00
|
|
|
if (HIWORD(wParam) != BN_CLICKED &&
|
|
|
|
HIWORD(wParam) != BN_DOUBLECLICKED)
|
|
|
|
break;
|
2001-05-06 14:35:20 +00:00
|
|
|
state =
|
2005-05-21 14:16:43 +00:00
|
|
|
(struct MainDlgState *) GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (!state->generation_thread_exists) {
|
2018-06-03 13:41:31 +00:00
|
|
|
unsigned raw_entropy_required;
|
|
|
|
unsigned char *raw_entropy_buf;
|
2001-05-06 14:35:20 +00:00
|
|
|
BOOL ok;
|
2018-10-29 19:50:29 +00:00
|
|
|
state->key_bits = GetDlgItemInt(hwnd, IDC_BITS, &ok, false);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (!ok)
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
state->key_bits = DEFAULT_KEY_BITS;
|
|
|
|
{
|
|
|
|
int curveindex = SendDlgItemMessage(hwnd, IDC_CURVE,
|
|
|
|
CB_GETCURSEL, 0, 0);
|
|
|
|
assert(curveindex >= 0);
|
|
|
|
assert(curveindex < n_ec_nist_curve_lengths);
|
|
|
|
state->curve_bits = ec_nist_curve_lengths[curveindex];
|
|
|
|
}
|
2001-03-03 11:54:34 +00:00
|
|
|
/* If we ever introduce a new key type, check it here! */
|
|
|
|
state->ssh2 = !IsDlgButtonChecked(hwnd, IDC_KEYSSH1);
|
2014-11-01 09:14:19 +00:00
|
|
|
state->keytype = RSA;
|
|
|
|
if (IsDlgButtonChecked(hwnd, IDC_KEYSSH2DSA)) {
|
|
|
|
state->keytype = DSA;
|
2014-11-01 09:45:20 +00:00
|
|
|
} else if (IsDlgButtonChecked(hwnd, IDC_KEYSSH2ECDSA)) {
|
|
|
|
state->keytype = ECDSA;
|
2015-05-09 14:02:54 +00:00
|
|
|
} else if (IsDlgButtonChecked(hwnd, IDC_KEYSSH2ED25519)) {
|
|
|
|
state->keytype = ED25519;
|
2014-11-01 09:14:19 +00:00
|
|
|
}
|
2016-04-02 07:00:37 +00:00
|
|
|
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
if ((state->keytype == RSA || state->keytype == DSA) &&
|
|
|
|
state->key_bits < 256) {
|
|
|
|
char *message = dupprintf
|
|
|
|
("PuTTYgen will not generate a key smaller than 256"
|
|
|
|
" bits.\nKey length reset to default %d. Continue?",
|
|
|
|
DEFAULT_KEY_BITS);
|
|
|
|
int ret = MessageBox(hwnd, message, "PuTTYgen Warning",
|
2001-05-06 14:35:20 +00:00
|
|
|
MB_ICONWARNING | MB_OKCANCEL);
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
sfree(message);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (ret != IDOK)
|
|
|
|
break;
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
state->key_bits = DEFAULT_KEY_BITS;
|
2018-10-29 19:50:29 +00:00
|
|
|
SetDlgItemInt(hwnd, IDC_BITS, DEFAULT_KEY_BITS, false);
|
2016-04-02 07:00:37 +00:00
|
|
|
} else if ((state->keytype == RSA || state->keytype == DSA) &&
|
|
|
|
state->key_bits < DEFAULT_KEY_BITS) {
|
|
|
|
char *message = dupprintf
|
|
|
|
("Keys shorter than %d bits are not recommended. "
|
|
|
|
"Really generate this key?", DEFAULT_KEY_BITS);
|
|
|
|
int ret = MessageBox(hwnd, message, "PuTTYgen Warning",
|
|
|
|
MB_ICONWARNING | MB_OKCANCEL);
|
|
|
|
sfree(message);
|
|
|
|
if (ret != IDOK)
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
if (state->keytype == RSA || state->keytype == DSA)
|
2018-06-03 13:41:31 +00:00
|
|
|
raw_entropy_required = (state->key_bits / 2) * 2;
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
else if (state->keytype == ECDSA)
|
2018-06-03 13:41:31 +00:00
|
|
|
raw_entropy_required = (state->curve_bits / 2) * 2;
|
Polish up the PuTTYgen user interface for ECC key types.
Jacob pointed out that a free-text field for entering a key size in
bits is all very well for key types where we actually _can_ generate a
key to a size of your choice, but less useful for key types where
there are only three (or one) legal values for the field, especially
if we don't _say_ what they are.
So I've revamped the UI a bit: now, in ECDSA mode, you get a dropdown
list selector showing the available elliptic curves (and they're even
named, rather than just given by bit count), and in ED25519 mode even
that disappears. The curve selector for ECDSA and the bits selector
for RSA/DSA are independent controls, so each one remembers its last
known value even while temporarily hidden in favour of the other.
The actual generation function still expects a bit count rather than
an actual curve or algorithm ID, so the easiest way to actually
arrange to populate the drop-down list was to have an array of bit
counts exposed by sshecc.c. That's a bit ugly, but there we go.
One small functional change: if you enter an absurdly low value into
the RSA/DSA bit count box (under 256), PuTTYgen used to give a warning
and reset it to 256. Now it resets it to the default key length of
2048, basically because I was touching that code anyway to change a
variable name and just couldn't bring myself to leave it in a state
where it intentionally chose such an utterly useless key size. Of
course this doesn't prevent generation of 256-bit keys if someone
still really wants one - it just means they don't get one selected as
the result of a typo.
2016-03-25 07:53:06 +00:00
|
|
|
else
|
2018-06-03 13:41:31 +00:00
|
|
|
raw_entropy_required = 256;
|
|
|
|
|
|
|
|
raw_entropy_buf = snewn(raw_entropy_required, unsigned char);
|
|
|
|
if (win_read_random(raw_entropy_buf, raw_entropy_required)) {
|
|
|
|
/*
|
|
|
|
* If we can get the entropy we need from
|
|
|
|
* CryptGenRandom, just do that, and go straight
|
|
|
|
* to the key-generation phase.
|
|
|
|
*/
|
|
|
|
random_add_heavynoise(raw_entropy_buf,
|
|
|
|
raw_entropy_required);
|
|
|
|
start_generating_key(hwnd, state);
|
|
|
|
} else {
|
|
|
|
/*
|
|
|
|
* Manual entropy input, by making the user wave
|
|
|
|
* the mouse over the window a lot.
|
|
|
|
*
|
|
|
|
* My brief statistical tests on mouse movements
|
|
|
|
* suggest that there are about 2.5 bits of
|
|
|
|
* randomness in the x position, 2.5 in the y
|
|
|
|
* position, and 1.7 in the message time, making
|
|
|
|
* 5.7 bits of unpredictability per mouse
|
|
|
|
* movement. However, other people have told me
|
|
|
|
* it's far less than that, so I'm going to be
|
|
|
|
* stupidly cautious and knock that down to a nice
|
|
|
|
* round 2. With this method, we require two words
|
|
|
|
* per mouse movement, so with 2 bits per mouse
|
|
|
|
* movement we expect 2 bits every 2 words, i.e.
|
|
|
|
* the number of _words_ of mouse data we want to
|
|
|
|
* collect is just the same as the number of
|
|
|
|
* _bits_ of entropy we want.
|
|
|
|
*/
|
|
|
|
state->entropy_required = raw_entropy_required;
|
|
|
|
|
|
|
|
ui_set_state(hwnd, state, 1);
|
|
|
|
SetDlgItemText(hwnd, IDC_GENERATING, entropy_msg);
|
2018-10-29 19:50:29 +00:00
|
|
|
state->key_exists = false;
|
|
|
|
state->collecting_entropy = true;
|
2018-06-03 13:41:31 +00:00
|
|
|
|
|
|
|
state->entropy_got = 0;
|
|
|
|
state->entropy_size = (state->entropy_required *
|
|
|
|
sizeof(unsigned));
|
|
|
|
state->entropy = snewn(state->entropy_required, unsigned);
|
|
|
|
|
|
|
|
SendDlgItemMessage(hwnd, IDC_PROGRESS, PBM_SETRANGE, 0,
|
|
|
|
MAKELPARAM(0, state->entropy_required));
|
|
|
|
SendDlgItemMessage(hwnd, IDC_PROGRESS, PBM_SETPOS, 0, 0);
|
|
|
|
}
|
2001-05-06 14:35:20 +00:00
|
|
|
|
2018-06-03 13:41:31 +00:00
|
|
|
smemclr(raw_entropy_buf, raw_entropy_required);
|
|
|
|
sfree(raw_entropy_buf);
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
break;
|
|
|
|
case IDC_SAVE:
|
2015-05-10 06:42:48 +00:00
|
|
|
case IDC_EXPORT_OPENSSH_AUTO:
|
2015-04-28 18:46:58 +00:00
|
|
|
case IDC_EXPORT_OPENSSH_NEW:
|
2002-05-13 16:56:11 +00:00
|
|
|
case IDC_EXPORT_SSHCOM:
|
2003-05-14 18:53:28 +00:00
|
|
|
if (HIWORD(wParam) != BN_CLICKED)
|
|
|
|
break;
|
2001-05-06 14:35:20 +00:00
|
|
|
state =
|
2005-05-21 14:16:43 +00:00
|
|
|
(struct MainDlgState *) GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (state->key_exists) {
|
|
|
|
char filename[FILENAME_MAX];
|
2011-10-02 14:14:21 +00:00
|
|
|
char *passphrase, *passphrase2;
|
2002-05-13 16:56:11 +00:00
|
|
|
int type, realtype;
|
|
|
|
|
|
|
|
if (state->ssh2)
|
|
|
|
realtype = SSH_KEYTYPE_SSH2;
|
|
|
|
else
|
|
|
|
realtype = SSH_KEYTYPE_SSH1;
|
|
|
|
|
2015-05-10 06:42:48 +00:00
|
|
|
if (LOWORD(wParam) == IDC_EXPORT_OPENSSH_AUTO)
|
|
|
|
type = SSH_KEYTYPE_OPENSSH_AUTO;
|
2015-04-28 18:46:58 +00:00
|
|
|
else if (LOWORD(wParam) == IDC_EXPORT_OPENSSH_NEW)
|
|
|
|
type = SSH_KEYTYPE_OPENSSH_NEW;
|
2002-05-13 16:56:11 +00:00
|
|
|
else if (LOWORD(wParam) == IDC_EXPORT_SSHCOM)
|
|
|
|
type = SSH_KEYTYPE_SSHCOM;
|
|
|
|
else
|
|
|
|
type = realtype;
|
|
|
|
|
|
|
|
if (type != realtype &&
|
|
|
|
import_target_type(type) != realtype) {
|
|
|
|
char msg[256];
|
2005-03-10 16:36:05 +00:00
|
|
|
sprintf(msg, "Cannot export an SSH-%d key in an SSH-%d"
|
2002-05-13 16:56:11 +00:00
|
|
|
" format", (state->ssh2 ? 2 : 1),
|
|
|
|
(state->ssh2 ? 1 : 2));
|
|
|
|
MessageBox(hwnd, msg,
|
|
|
|
"PuTTYgen Error", MB_OK | MB_ICONERROR);
|
|
|
|
break;
|
|
|
|
}
|
|
|
|
|
2011-10-02 14:14:21 +00:00
|
|
|
passphrase = GetDlgItemText_alloc(hwnd, IDC_PASSPHRASE1EDIT);
|
|
|
|
passphrase2 = GetDlgItemText_alloc(hwnd, IDC_PASSPHRASE2EDIT);
|
2000-10-20 09:31:16 +00:00
|
|
|
if (strcmp(passphrase, passphrase2)) {
|
2001-05-06 14:35:20 +00:00
|
|
|
MessageBox(hwnd,
|
2000-10-20 09:31:16 +00:00
|
|
|
"The two passphrases given do not match.",
|
2001-05-06 14:35:20 +00:00
|
|
|
"PuTTYgen Error", MB_OK | MB_ICONERROR);
|
2011-10-02 14:14:21 +00:00
|
|
|
burnstr(passphrase);
|
|
|
|
burnstr(passphrase2);
|
2000-10-20 09:31:16 +00:00
|
|
|
break;
|
|
|
|
}
|
2011-10-02 14:14:21 +00:00
|
|
|
burnstr(passphrase2);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (!*passphrase) {
|
|
|
|
int ret;
|
|
|
|
ret = MessageBox(hwnd,
|
|
|
|
"Are you sure you want to save this key\n"
|
|
|
|
"without a passphrase to protect it?",
|
|
|
|
"PuTTYgen Warning",
|
|
|
|
MB_YESNO | MB_ICONWARNING);
|
2011-10-02 14:14:21 +00:00
|
|
|
if (ret != IDYES) {
|
|
|
|
burnstr(passphrase);
|
|
|
|
break;
|
|
|
|
}
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
if (prompt_keyfile(hwnd, "Save private key as:",
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
filename, true, (type == realtype))) {
|
2000-10-20 09:43:58 +00:00
|
|
|
int ret;
|
2000-10-20 09:41:13 +00:00
|
|
|
FILE *fp = fopen(filename, "r");
|
|
|
|
if (fp) {
|
2002-11-07 19:49:03 +00:00
|
|
|
char *buffer;
|
2000-10-20 09:41:13 +00:00
|
|
|
fclose(fp);
|
2002-11-07 19:49:03 +00:00
|
|
|
buffer = dupprintf("Overwrite existing file\n%s?",
|
|
|
|
filename);
|
2000-10-20 09:41:13 +00:00
|
|
|
ret = MessageBox(hwnd, buffer, "PuTTYgen Warning",
|
|
|
|
MB_YESNO | MB_ICONWARNING);
|
2002-11-07 19:49:03 +00:00
|
|
|
sfree(buffer);
|
2011-10-02 14:14:21 +00:00
|
|
|
if (ret != IDYES) {
|
|
|
|
burnstr(passphrase);
|
2000-10-20 09:41:13 +00:00
|
|
|
break;
|
2011-10-02 14:14:21 +00:00
|
|
|
}
|
2000-10-20 09:41:13 +00:00
|
|
|
}
|
2002-05-13 16:56:11 +00:00
|
|
|
|
2001-03-03 11:54:34 +00:00
|
|
|
if (state->ssh2) {
|
2011-10-02 11:01:57 +00:00
|
|
|
Filename *fn = filename_from_str(filename);
|
2002-05-13 16:56:11 +00:00
|
|
|
if (type != realtype)
|
2011-10-02 11:01:57 +00:00
|
|
|
ret = export_ssh2(fn, type, &state->ssh2key,
|
2002-05-13 16:56:11 +00:00
|
|
|
*passphrase ? passphrase : NULL);
|
|
|
|
else
|
2011-10-02 11:01:57 +00:00
|
|
|
ret = ssh2_save_userkey(fn, &state->ssh2key,
|
2002-05-13 16:56:11 +00:00
|
|
|
*passphrase ? passphrase :
|
|
|
|
NULL);
|
2011-10-02 11:01:57 +00:00
|
|
|
filename_free(fn);
|
2001-03-03 11:54:34 +00:00
|
|
|
} else {
|
2011-10-02 11:01:57 +00:00
|
|
|
Filename *fn = filename_from_str(filename);
|
2002-05-13 16:56:11 +00:00
|
|
|
if (type != realtype)
|
2011-10-02 11:01:57 +00:00
|
|
|
ret = export_ssh1(fn, type, &state->key,
|
2002-05-13 16:56:11 +00:00
|
|
|
*passphrase ? passphrase : NULL);
|
|
|
|
else
|
2018-05-24 07:22:44 +00:00
|
|
|
ret = rsa_ssh1_savekey(
|
|
|
|
fn, &state->key,
|
|
|
|
*passphrase ? passphrase : NULL);
|
2011-10-02 11:01:57 +00:00
|
|
|
filename_free(fn);
|
2001-03-03 11:54:34 +00:00
|
|
|
}
|
2000-10-20 09:43:58 +00:00
|
|
|
if (ret <= 0) {
|
|
|
|
MessageBox(hwnd, "Unable to save key file",
|
2001-05-06 14:35:20 +00:00
|
|
|
"PuTTYgen Error", MB_OK | MB_ICONERROR);
|
2000-10-20 09:43:58 +00:00
|
|
|
}
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
2011-10-02 14:14:21 +00:00
|
|
|
burnstr(passphrase);
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
break;
|
2001-08-27 17:40:03 +00:00
|
|
|
case IDC_SAVEPUB:
|
2003-05-14 18:53:28 +00:00
|
|
|
if (HIWORD(wParam) != BN_CLICKED)
|
|
|
|
break;
|
2001-08-27 17:40:03 +00:00
|
|
|
state =
|
2005-05-21 14:16:43 +00:00
|
|
|
(struct MainDlgState *) GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2001-08-27 17:40:03 +00:00
|
|
|
if (state->key_exists) {
|
|
|
|
char filename[FILENAME_MAX];
|
|
|
|
if (prompt_keyfile(hwnd, "Save public key as:",
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
filename, true, false)) {
|
2001-08-27 17:40:03 +00:00
|
|
|
int ret;
|
|
|
|
FILE *fp = fopen(filename, "r");
|
|
|
|
if (fp) {
|
2002-11-07 19:49:03 +00:00
|
|
|
char *buffer;
|
2001-08-27 17:40:03 +00:00
|
|
|
fclose(fp);
|
2002-11-07 19:49:03 +00:00
|
|
|
buffer = dupprintf("Overwrite existing file\n%s?",
|
|
|
|
filename);
|
2001-08-27 17:40:03 +00:00
|
|
|
ret = MessageBox(hwnd, buffer, "PuTTYgen Warning",
|
|
|
|
MB_YESNO | MB_ICONWARNING);
|
2002-11-07 19:49:03 +00:00
|
|
|
sfree(buffer);
|
2001-08-27 17:40:03 +00:00
|
|
|
if (ret != IDYES)
|
|
|
|
break;
|
|
|
|
}
|
2015-05-12 12:42:26 +00:00
|
|
|
fp = fopen(filename, "w");
|
|
|
|
if (!fp) {
|
|
|
|
MessageBox(hwnd, "Unable to open key file",
|
|
|
|
"PuTTYgen Error", MB_OK | MB_ICONERROR);
|
|
|
|
} else {
|
|
|
|
if (state->ssh2) {
|
2018-05-24 09:59:39 +00:00
|
|
|
strbuf *blob = strbuf_new();
|
2018-06-03 11:58:05 +00:00
|
|
|
ssh_key_public_blob(
|
|
|
|
state->ssh2key.key, BinarySink_UPCAST(blob));
|
2015-05-12 12:42:26 +00:00
|
|
|
ssh2_write_pubkey(fp, state->ssh2key.comment,
|
2018-05-24 09:59:39 +00:00
|
|
|
blob->u, blob->len,
|
2015-05-12 12:42:26 +00:00
|
|
|
SSH_KEYTYPE_SSH2_PUBLIC_RFC4716);
|
2018-05-24 09:59:39 +00:00
|
|
|
strbuf_free(blob);
|
2015-05-12 12:42:26 +00:00
|
|
|
} else {
|
|
|
|
ssh1_write_pubkey(fp, &state->key);
|
|
|
|
}
|
|
|
|
if (fclose(fp) < 0) {
|
|
|
|
MessageBox(hwnd, "Unable to save key file",
|
|
|
|
"PuTTYgen Error", MB_OK | MB_ICONERROR);
|
|
|
|
}
|
|
|
|
}
|
2001-08-27 17:40:03 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
break;
|
2001-05-06 14:35:20 +00:00
|
|
|
case IDC_LOAD:
|
2002-05-18 09:20:41 +00:00
|
|
|
case IDC_IMPORT:
|
2003-05-14 18:53:28 +00:00
|
|
|
if (HIWORD(wParam) != BN_CLICKED)
|
|
|
|
break;
|
2001-05-06 14:35:20 +00:00
|
|
|
state =
|
2005-05-21 14:16:43 +00:00
|
|
|
(struct MainDlgState *) GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2001-05-06 14:35:20 +00:00
|
|
|
if (!state->generation_thread_exists) {
|
|
|
|
char filename[FILENAME_MAX];
|
Convert a lot of 'int' variables to 'bool'.
My normal habit these days, in new code, is to treat int and bool as
_almost_ completely separate types. I'm still willing to use C's
implicit test for zero on an integer (e.g. 'if (!blob.len)' is fine,
no need to spell it out as blob.len != 0), but generally, if a
variable is going to be conceptually a boolean, I like to declare it
bool and assign to it using 'true' or 'false' rather than 0 or 1.
PuTTY is an exception, because it predates the C99 bool, and I've
stuck to its existing coding style even when adding new code to it.
But it's been annoying me more and more, so now that I've decided C99
bool is an acceptable thing to require from our toolchain in the first
place, here's a quite thorough trawl through the source doing
'boolification'. Many variables and function parameters are now typed
as bool rather than int; many assignments of 0 or 1 to those variables
are now spelled 'true' or 'false'.
I managed this thorough conversion with the help of a custom clang
plugin that I wrote to trawl the AST and apply heuristics to point out
where things might want changing. So I've even managed to do a decent
job on parts of the code I haven't looked at in years!
To make the plugin's work easier, I pushed platform front ends
generally in the direction of using standard 'bool' in preference to
platform-specific boolean types like Windows BOOL or GTK's gboolean;
I've left the platform booleans in places they _have_ to be for the
platform APIs to work right, but variables only used by my own code
have been converted wherever I found them.
In a few places there are int values that look very like booleans in
_most_ of the places they're used, but have a rarely-used third value,
or a distinction between different nonzero values that most users
don't care about. In these cases, I've _removed_ uses of 'true' and
'false' for the return values, to emphasise that there's something
more subtle going on than a simple boolean answer:
- the 'multisel' field in dialog.h's list box structure, for which
the GTK front end in particular recognises a difference between 1
and 2 but nearly everything else treats as boolean
- the 'urgent' parameter to plug_receive, where 1 vs 2 tells you
something about the specific location of the urgent pointer, but
most clients only care about 0 vs 'something nonzero'
- the return value of wc_match, where -1 indicates a syntax error in
the wildcard.
- the return values from SSH-1 RSA-key loading functions, which use
-1 for 'wrong passphrase' and 0 for all other failures (so any
caller which already knows it's not loading an _encrypted private_
key can treat them as boolean)
- term->esc_query, and the 'query' parameter in toggle_mode in
terminal.c, which _usually_ hold 0 for ESC[123h or 1 for ESC[?123h,
but can also hold -1 for some other intervening character that we
don't support.
In a few places there's an integer that I haven't turned into a bool
even though it really _can_ only take values 0 or 1 (and, as above,
tried to make the call sites consistent in not calling those values
true and false), on the grounds that I thought it would make it more
confusing to imply that the 0 value was in some sense 'negative' or
bad and the 1 positive or good:
- the return value of plug_accepting uses the POSIXish convention of
0=success and nonzero=error; I think if I made it bool then I'd
also want to reverse its sense, and that's a job for a separate
piece of work.
- the 'screen' parameter to lineptr() in terminal.c, where 0 and 1
represent the default and alternate screens. There's no obvious
reason why one of those should be considered 'true' or 'positive'
or 'success' - they're just indices - so I've left it as int.
ssh_scp_recv had particularly confusing semantics for its previous int
return value: its call sites used '<= 0' to check for error, but it
never actually returned a negative number, just 0 or 1. Now the
function and its call sites agree that it's a bool.
In a couple of places I've renamed variables called 'ret', because I
don't like that name any more - it's unclear whether it means the
return value (in preparation) for the _containing_ function or the
return value received from a subroutine call, and occasionally I've
accidentally used the same variable for both and introduced a bug. So
where one of those got in my way, I've renamed it to 'toret' or 'retd'
(the latter short for 'returned') in line with my usual modern
practice, but I haven't done a thorough job of finding all of them.
Finally, one amusing side effect of doing this is that I've had to
separate quite a few chained assignments. It used to be perfectly fine
to write 'a = b = c = TRUE' when a,b,c were int and TRUE was just a
the 'true' defined by stdbool.h, that idiom provokes a warning from
gcc: 'suggest parentheses around assignment used as truth value'!
2018-11-02 19:23:19 +00:00
|
|
|
if (prompt_keyfile(hwnd, "Load private key:", filename, false,
|
|
|
|
LOWORD(wParam) == IDC_LOAD)) {
|
2013-07-22 07:11:54 +00:00
|
|
|
Filename *fn = filename_from_str(filename);
|
|
|
|
load_key_file(hwnd, state, fn, LOWORD(wParam) != IDC_LOAD);
|
|
|
|
filename_free(fn);
|
|
|
|
}
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
break;
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
case WM_DONEKEY:
|
2005-05-21 14:16:43 +00:00
|
|
|
state = (struct MainDlgState *) GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2018-10-29 19:50:29 +00:00
|
|
|
state->generation_thread_exists = false;
|
|
|
|
state->key_exists = true;
|
2001-09-22 20:52:21 +00:00
|
|
|
SendDlgItemMessage(hwnd, IDC_PROGRESS, PBM_SETRANGE, 0,
|
|
|
|
MAKELPARAM(0, PROGRESSRANGE));
|
|
|
|
SendDlgItemMessage(hwnd, IDC_PROGRESS, PBM_SETPOS, PROGRESSRANGE, 0);
|
2001-03-03 12:05:36 +00:00
|
|
|
if (state->ssh2) {
|
2014-11-01 09:14:19 +00:00
|
|
|
if (state->keytype == DSA) {
|
2018-06-03 11:58:05 +00:00
|
|
|
state->ssh2key.key = &state->dsskey.sshk;
|
2014-11-01 09:45:20 +00:00
|
|
|
} else if (state->keytype == ECDSA) {
|
2018-06-03 11:58:05 +00:00
|
|
|
state->ssh2key.key = &state->eckey.sshk;
|
2015-05-09 14:02:54 +00:00
|
|
|
} else if (state->keytype == ED25519) {
|
2018-06-03 11:58:05 +00:00
|
|
|
state->ssh2key.key = &state->eckey.sshk;
|
2001-09-22 20:52:21 +00:00
|
|
|
} else {
|
2018-06-03 11:58:05 +00:00
|
|
|
state->ssh2key.key = &state->key.sshk;
|
2001-09-22 20:52:21 +00:00
|
|
|
}
|
2001-03-03 11:54:34 +00:00
|
|
|
state->commentptr = &state->ssh2key.comment;
|
2001-03-03 12:05:36 +00:00
|
|
|
} else {
|
2001-03-03 11:54:34 +00:00
|
|
|
state->commentptr = &state->key.comment;
|
2001-03-03 12:05:36 +00:00
|
|
|
}
|
2001-05-06 14:35:20 +00:00
|
|
|
/*
|
|
|
|
* Invent a comment for the key. We'll do this by including
|
|
|
|
* the date in it. This will be so horrifyingly ugly that
|
|
|
|
* the user will immediately want to change it, which is
|
|
|
|
* what we want :-)
|
|
|
|
*/
|
2003-03-29 16:14:26 +00:00
|
|
|
*state->commentptr = snewn(30, char);
|
2001-05-06 14:35:20 +00:00
|
|
|
{
|
2005-01-09 14:27:48 +00:00
|
|
|
struct tm tm;
|
|
|
|
tm = ltime();
|
2014-11-01 09:14:19 +00:00
|
|
|
if (state->keytype == DSA)
|
2005-01-09 14:27:48 +00:00
|
|
|
strftime(*state->commentptr, 30, "dsa-key-%Y%m%d", &tm);
|
2014-11-01 09:45:20 +00:00
|
|
|
else if (state->keytype == ECDSA)
|
|
|
|
strftime(*state->commentptr, 30, "ecdsa-key-%Y%m%d", &tm);
|
2015-05-09 14:02:54 +00:00
|
|
|
else if (state->keytype == ED25519)
|
|
|
|
strftime(*state->commentptr, 30, "ed25519-key-%Y%m%d", &tm);
|
2001-09-22 20:52:21 +00:00
|
|
|
else
|
2005-01-09 14:27:48 +00:00
|
|
|
strftime(*state->commentptr, 30, "rsa-key-%Y%m%d", &tm);
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
/*
|
|
|
|
* Now update the key controls with all the key data.
|
|
|
|
*/
|
|
|
|
{
|
2018-06-03 07:08:53 +00:00
|
|
|
char *fp, *savecomment;
|
2001-05-06 14:35:20 +00:00
|
|
|
/*
|
|
|
|
* Blank passphrase, initially. This isn't dangerous,
|
|
|
|
* because we will warn (Are You Sure?) before allowing
|
|
|
|
* the user to save an unprotected private key.
|
|
|
|
*/
|
|
|
|
SetDlgItemText(hwnd, IDC_PASSPHRASE1EDIT, "");
|
|
|
|
SetDlgItemText(hwnd, IDC_PASSPHRASE2EDIT, "");
|
|
|
|
/*
|
|
|
|
* Set the comment.
|
|
|
|
*/
|
|
|
|
SetDlgItemText(hwnd, IDC_COMMENTEDIT, *state->commentptr);
|
|
|
|
/*
|
|
|
|
* Set the key fingerprint.
|
|
|
|
*/
|
2001-03-03 11:54:34 +00:00
|
|
|
savecomment = *state->commentptr;
|
|
|
|
*state->commentptr = NULL;
|
2018-06-03 07:08:53 +00:00
|
|
|
if (state->ssh2)
|
2018-06-03 11:58:05 +00:00
|
|
|
fp = ssh2_fingerprint(state->ssh2key.key);
|
2018-06-03 07:08:53 +00:00
|
|
|
else
|
|
|
|
fp = rsa_ssh1_fingerprint(&state->key);
|
|
|
|
SetDlgItemText(hwnd, IDC_FINGERPRINT, fp);
|
|
|
|
sfree(fp);
|
2001-03-03 11:54:34 +00:00
|
|
|
*state->commentptr = savecomment;
|
2001-05-06 14:35:20 +00:00
|
|
|
/*
|
|
|
|
* Construct a decimal representation of the key, for
|
2001-08-27 17:40:03 +00:00
|
|
|
* pasting into .ssh/authorized_keys or
|
|
|
|
* .ssh/authorized_keys2 on a Unix box.
|
2001-05-06 14:35:20 +00:00
|
|
|
*/
|
2001-03-03 11:54:34 +00:00
|
|
|
if (state->ssh2) {
|
2001-08-27 17:40:03 +00:00
|
|
|
setupbigedit2(hwnd, IDC_KEYDISPLAY,
|
|
|
|
IDC_PKSTATIC, &state->ssh2key);
|
2001-03-03 11:54:34 +00:00
|
|
|
} else {
|
2001-08-27 17:40:03 +00:00
|
|
|
setupbigedit1(hwnd, IDC_KEYDISPLAY,
|
|
|
|
IDC_PKSTATIC, &state->key);
|
2001-03-03 11:54:34 +00:00
|
|
|
}
|
2001-05-06 14:35:20 +00:00
|
|
|
}
|
|
|
|
/*
|
|
|
|
* Finally, hide the progress bar and show the key data.
|
|
|
|
*/
|
2002-05-15 20:07:11 +00:00
|
|
|
ui_set_state(hwnd, state, 2);
|
2001-05-06 14:35:20 +00:00
|
|
|
break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case WM_HELP:
|
2006-12-17 11:16:07 +00:00
|
|
|
{
|
2001-12-12 18:45:56 +00:00
|
|
|
int id = ((LPHELPINFO)lParam)->iCtrlId;
|
2015-05-15 10:15:42 +00:00
|
|
|
const char *topic = NULL;
|
2001-12-12 18:45:56 +00:00
|
|
|
switch (id) {
|
|
|
|
case IDC_GENERATING:
|
|
|
|
case IDC_PROGRESS:
|
|
|
|
case IDC_GENSTATIC:
|
|
|
|
case IDC_GENERATE:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_generate; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_PKSTATIC:
|
|
|
|
case IDC_KEYDISPLAY:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_pastekey; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_FPSTATIC:
|
|
|
|
case IDC_FINGERPRINT:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_fingerprint; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_COMMENTSTATIC:
|
|
|
|
case IDC_COMMENTEDIT:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_comment; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_PASSPHRASE1STATIC:
|
|
|
|
case IDC_PASSPHRASE1EDIT:
|
|
|
|
case IDC_PASSPHRASE2STATIC:
|
|
|
|
case IDC_PASSPHRASE2EDIT:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_passphrase; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_LOADSTATIC:
|
|
|
|
case IDC_LOAD:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_load; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_SAVESTATIC:
|
|
|
|
case IDC_SAVE:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_savepriv; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_SAVEPUB:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_savepub; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_TYPESTATIC:
|
|
|
|
case IDC_KEYSSH1:
|
|
|
|
case IDC_KEYSSH2RSA:
|
|
|
|
case IDC_KEYSSH2DSA:
|
2014-11-01 09:45:20 +00:00
|
|
|
case IDC_KEYSSH2ECDSA:
|
2015-05-09 14:02:54 +00:00
|
|
|
case IDC_KEYSSH2ED25519:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_keytype; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
case IDC_BITSSTATIC:
|
|
|
|
case IDC_BITS:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_bits; break;
|
2002-05-18 09:20:41 +00:00
|
|
|
case IDC_IMPORT:
|
2015-05-10 06:42:48 +00:00
|
|
|
case IDC_EXPORT_OPENSSH_AUTO:
|
2015-04-28 18:46:58 +00:00
|
|
|
case IDC_EXPORT_OPENSSH_NEW:
|
2002-05-15 20:07:11 +00:00
|
|
|
case IDC_EXPORT_SSHCOM:
|
2006-12-17 11:16:07 +00:00
|
|
|
topic = WINHELP_CTX_puttygen_conversions; break;
|
2001-12-12 18:45:56 +00:00
|
|
|
}
|
2005-02-16 01:47:10 +00:00
|
|
|
if (topic) {
|
2006-12-17 11:16:07 +00:00
|
|
|
launch_help(hwnd, topic);
|
2001-12-12 18:45:56 +00:00
|
|
|
} else {
|
|
|
|
MessageBeep(0);
|
|
|
|
}
|
|
|
|
}
|
|
|
|
break;
|
2000-10-19 15:43:08 +00:00
|
|
|
case WM_CLOSE:
|
2005-05-21 14:16:43 +00:00
|
|
|
state = (struct MainDlgState *) GetWindowLongPtr(hwnd, GWLP_USERDATA);
|
2001-05-06 14:35:20 +00:00
|
|
|
sfree(state);
|
2006-12-17 11:16:07 +00:00
|
|
|
quit_help(hwnd);
|
2001-05-06 14:35:20 +00:00
|
|
|
EndDialog(hwnd, 1);
|
2000-10-19 15:43:08 +00:00
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
return 0;
|
|
|
|
}
|
|
|
|
|
2006-12-17 11:16:07 +00:00
|
|
|
void cleanup_exit(int code)
|
|
|
|
{
|
|
|
|
shutdown_help();
|
|
|
|
exit(code);
|
|
|
|
}
|
2002-03-06 20:13:22 +00:00
|
|
|
|
2001-05-06 14:35:20 +00:00
|
|
|
int WINAPI WinMain(HINSTANCE inst, HINSTANCE prev, LPSTR cmdline, int show)
|
|
|
|
{
|
2017-01-28 21:56:28 +00:00
|
|
|
int argc, i;
|
2002-08-06 17:48:14 +00:00
|
|
|
char **argv;
|
2006-12-17 11:16:07 +00:00
|
|
|
int ret;
|
2002-08-06 17:48:14 +00:00
|
|
|
|
2016-07-18 19:02:32 +00:00
|
|
|
dll_hijacking_protection();
|
|
|
|
|
2017-03-13 21:42:44 +00:00
|
|
|
init_common_controls();
|
2000-10-19 15:43:08 +00:00
|
|
|
hinst = inst;
|
2005-03-01 01:16:57 +00:00
|
|
|
hwnd = NULL;
|
2001-12-12 18:45:56 +00:00
|
|
|
|
|
|
|
/*
|
|
|
|
* See if we can find our Help file.
|
|
|
|
*/
|
2006-12-17 11:16:07 +00:00
|
|
|
init_help();
|
2001-12-12 18:45:56 +00:00
|
|
|
|
2005-03-19 02:26:58 +00:00
|
|
|
split_into_argv(cmdline, &argc, &argv, NULL);
|
|
|
|
|
2017-01-28 21:56:28 +00:00
|
|
|
for (i = 0; i < argc; i++) {
|
|
|
|
if (!strcmp(argv[i], "-pgpfp")) {
|
2005-03-19 02:26:58 +00:00
|
|
|
pgp_fingerprints();
|
2017-01-28 21:56:28 +00:00
|
|
|
return 1;
|
|
|
|
} else if (!strcmp(argv[i], "-restrict-acl") ||
|
|
|
|
!strcmp(argv[i], "-restrict_acl") ||
|
|
|
|
!strcmp(argv[i], "-restrictacl")) {
|
|
|
|
restrict_process_acl();
|
2005-03-19 02:26:58 +00:00
|
|
|
} else {
|
|
|
|
/*
|
|
|
|
* Assume the first argument to be a private key file, and
|
|
|
|
* attempt to load it.
|
|
|
|
*/
|
2017-01-28 21:56:28 +00:00
|
|
|
cmdline_keyfile = argv[i];
|
|
|
|
break;
|
2005-03-19 02:26:58 +00:00
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2004-11-27 19:56:38 +00:00
|
|
|
random_ref();
|
2006-12-17 11:16:07 +00:00
|
|
|
ret = DialogBox(hinst, MAKEINTRESOURCE(201), NULL, MainDlgProc) != IDOK;
|
|
|
|
|
|
|
|
cleanup_exit(ret);
|
|
|
|
return ret; /* just in case optimiser complains */
|
2000-10-19 15:43:08 +00:00
|
|
|
}
|