Instead of manually expanding the req_dist_name_dict, create a helper function for creating a config section from any dict. That will also automatically allow other fields to be emitted.
We can allow a field with multiple values, e.g. "OU" -> ["First OU", "Second OU"], and encode that in the config file using 1.OU = First OU 2.OU = Second OU as documented in 'man 5 config'. Reviewed-by: Simon Glass <[email protected]> Signed-off-by: Rasmus Villemoes <[email protected]> --- tools/binman/btool/openssl.py | 58 +++++++++++++++++------------------ 1 file changed, 28 insertions(+), 30 deletions(-) diff --git a/tools/binman/btool/openssl.py b/tools/binman/btool/openssl.py index b26f087c447..84413428e1e 100644 --- a/tools/binman/btool/openssl.py +++ b/tools/binman/btool/openssl.py @@ -36,6 +36,28 @@ class Bintoolopenssl(bintool.Bintool): name, 'openssl cryptography toolkit', version_regex=r'OpenSSL (.*) \(', version_args='version') + @staticmethod + def dict_to_config_section(section_name, data): + """Generate a section for an openssl config file from key-value pairs + + Args: + section_name: The name of the section + data: dict containing key-value pairs + + Returns: + A multi-line string containing the section definition. + + Each key must be a string, each value can be a string or a list of strings. + """ + sec = f'[ {section_name} ]\n' + for field, value in data.items(): + if isinstance(value, str): + sec += f'{field:22s} = {value}\n' + elif isinstance(value, list): + for i, s in enumerate(value): + sec += f'{i+1}.{field:20s} = {s}\n' + return sec + def x509_cert(self, cert_fname, input_fname, key_fname, cn, revision, config_fname): """Create a certificate @@ -92,8 +114,7 @@ imageSize = INTEGER:{len(indata)} sw_rev (int): Software revision config_fname (str): Filename to write fconfig into req_dist_name_dict (dict): Dictionary containing key-value pairs of - req_distinguished_name section extensions, must contain extensions for - C, ST, L, O, OU, CN and emailAddress + req_distinguished_name section extensions firewall_cert_data (dict): - auth_in_place (int): The Priv ID for copying as the specific host in firewall protected region @@ -114,14 +135,7 @@ x509_extensions = v3_ca prompt = no dirstring_type = nobmp -[ req_distinguished_name ] -C = {req_dist_name_dict['C']} -ST = {req_dist_name_dict['ST']} -L = {req_dist_name_dict['L']} -O = {req_dist_name_dict['O']} -OU = {req_dist_name_dict['OU']} -CN = {req_dist_name_dict['CN']} -emailAddress = {req_dist_name_dict['emailAddress']} +{self.dict_to_config_section('req_distinguished_name', req_dist_name_dict)} [ v3_ca ] basicConstraints = CA:true @@ -163,8 +177,7 @@ numFirewallRegions = INTEGER:{firewall_cert_data['num_firewalls']} sw_rev (int): Software revision config_fname (str): Filename to write fconfig into req_dist_name_dict (dict): Dictionary containing key-value pairs of - req_distinguished_name section extensions, must contain extensions for - C, ST, L, O, OU, CN and emailAddress + req_distinguished_name section extensions cert_type (int): Certification type bootcore (int): Booting core bootcore_opts(int): Booting core option, lockstep (0) or split (2) mode @@ -184,14 +197,7 @@ numFirewallRegions = INTEGER:{firewall_cert_data['num_firewalls']} prompt = no dirstring_type = nobmp - [ req_distinguished_name ] -C = {req_dist_name_dict['C']} -ST = {req_dist_name_dict['ST']} -L = {req_dist_name_dict['L']} -O = {req_dist_name_dict['O']} -OU = {req_dist_name_dict['OU']} -CN = {req_dist_name_dict['CN']} -emailAddress = {req_dist_name_dict['emailAddress']} +{self.dict_to_config_section('req_distinguished_name', req_dist_name_dict)} [ v3_ca ] basicConstraints = CA:true @@ -252,8 +258,7 @@ emailAddress = {req_dist_name_dict['emailAddress']} sw_rev (int): Software revision config_fname (str): Filename to write fconfig into req_dist_name_dict (dict): Dictionary containing key-value pairs of - req_distinguished_name section extensions, must contain extensions for - C, ST, L, O, OU, CN and emailAddress + req_distinguished_name section extensions cert_type (int): Certification type bootcore (int): Booting core load_addr (int): Load address of image @@ -274,14 +279,7 @@ x509_extensions = v3_ca prompt = no dirstring_type = nobmp -[ req_distinguished_name ] -C = {req_dist_name_dict['C']} -ST = {req_dist_name_dict['ST']} -L = {req_dist_name_dict['L']} -O = {req_dist_name_dict['O']} -OU = {req_dist_name_dict['OU']} -CN = {req_dist_name_dict['CN']} -emailAddress = {req_dist_name_dict['emailAddress']} +{self.dict_to_config_section('req_distinguished_name', req_dist_name_dict)} [ v3_ca ] basicConstraints = CA:true -- 2.55.0
